Multi-tenant isolation
Strict tenant boundaries across sessions, configuration, retrieval, and data execution.
Security & Governance
Security is architectural — fail-closed defaults, deterministic execution, and complete traceability across tenants, agents, and data access.
Strict tenant boundaries across sessions, configuration, retrieval, and data execution.
Role-based access for admin, agent management, and conversation inspection.
Live agent versions are immutable; changes flow through draft and candidate with audit events.
Enterprise identity via OIDC; MFA enforced through your identity provider.
Link executes read-only, allow-listed queries with tenant isolation. No ad-hoc SQL, no write paths, and no model-driven data access decisions.
Lifecycle logging, LLM call audit records, context expansion payloads, and admin visibility into assembled context per assistant message.