Security & governance

Company
intelligence.
Under your
control.

Know who can use a connection, what OrgAI can do, and when a change needs your confirmation.

PayPal Inc.

Your connected workspace

Company files

Connected account access

Google DriveBoxOneDrive

Email & conversations

Granted provider permissions

GmailOutlookWhatsApp

Processes & work

Workspace permissions

Checkered shieldStar of life shieldKey shield

Intelligence within boundaries

Defined actions
Rachel Green

Rachel Green

Proposed change

Send the client update

To
Maya · Acme
Action
Send an email

Confirmation required

Explore

Built into the interaction

Clear boundaries.
Useful intelligence.

Access, action permissions and confirmation are different controls. The925 keeps them separate.

Choose the audience.

Choose private, shared or centralised access.Decide who can use a connected accountinside The925.

Understand connection access

Review the change.

Catalogued write actions need confirmation.Reading still requires access, even whenno write confirmation is needed.

See an example

Keep credentials out of view.

Connector tokens use backend encryption.Public records show account, status andscope metadata, never the tokens.

Controls described from the integration implementation. Availability depends on the connected account, permissions and provider setup.

Connection access

The right connection.
For the right people.

Decide how a connection is used in your organisation. Keep personal connections private or make selected connections available to the people who need them.

Who can use this connection?

Only the connection creator.

Only Rachel can use this connection. Joining the workspace does not give other members access.

Provider permissions still control what Rachel’s connected account can access.

Connection settings

Google Drive

Rachel’s connection

Private
Rachel

Connection creator

Can use
Monica

Workspace member

Not included

Connection audience is not the same as source-file permission.

Review the content a shared account can reach before making it available to others. No blanket source-permission mirroring is claimed here.

Human confirmation

AI prepares. You review.

Creating a draft and sending an email are separate operations. Each has its own permission requirements and confirmation step.

Welcome Chandler, let’s get some work done!

Ask OrgAI what you would like to do…
Flow EngineSourcesGoogle DriveGoogle DocsGoogle SlidesGoogle SheetsGoogle CalendarGoogle MeetGmailOrgAI can make mistakes. Double check important info.

The framework behind the assistant

A request is not
a permission.

OrgAI works through defined operations, not unrestricted access. The connection, the action and the confirmation each matter.

01 / Access

The connected account.

Provider permissions, granted scopes,organisation policy and The925 accesssettings constrain what is available.

02 / Operation

A defined action.

Supported actions use specified input fieldsand limits. A capability label does not makean unsupported operation executable.

03 / Change

A deliberate change.

Catalogued write actions require confirmation.Reading, editing, sharing and sending arenot interchangeable permissions.

Defined adapters. Not arbitrary commands.

A URL or credential pasted into a prompt does not create an executable custom integration.

Explore the framework

Transparency by connection

Understand the access.
Then connect.

Explore the actions, declared permissions and confirmation requirements for each integration in our Resources library.

  • Google Drive

    Example operationRead who can access a file

    Declared accessdrive.readonly

    Before a changeRead access required

  • Gmail

    Example operationSend a message

    Declared accessgmail.send

    Before a changeConfirmation required

  • Outlook Email

    Example operationSave a draft

    Declared accessMail.ReadWrite

    Before a changeConfirmation required

  • Slack

    Example operationSend a message

    Declared accesschat:write

    Before a changeConfirmation required

Illustrative selection from the action inventory. Full provider authorisation can be broader than the scope shown for a single action.

Explore integrations

Privacy & data handling

Your data deserves
clear answers.

Before rollout, review what is processed, who receives it and how it is retained. The details should match your deployment, not a generic badge.

Processing & providers

Review hosting locations, model providers, subprocessors and the treatment of information sent for processing.

Retention & deletion

Clarify what happens to source copies, indexes, conversations, records and backups when data is removed or a connection is revoked.

Roles & responsibilities

Agree the processing purpose, contractual responsibilities and how privacy requests and incidents will be handled.

Privacy is more than a permission setting.

Compliance depends on the actual processing and the measures that support it. This page describes product controls; it does not claim independent GDPR certification or establish compliance on its own.

A closer look

Good questions.
Clear answers.

Understand the boundaries before connecting company information.

Discuss your requirements
Does connecting a tool give everyone access?

No. Private connections are limited to their creator. Shared connections target selected users or roles. Centralised connections are available across the organisation subject to product permissions.

These settings control who can use the connection. The connected account’s permissions and provider grant determine its reach, so shared-source access still needs careful review.

Can OrgAI send or change something without confirmation?

All catalogued connector write actions require confirmation, including saving a draft, sending a message and changing file sharing. Read actions do not use the same write-confirmation step, but they still require access.

Confirmation does not override a provider restriction or substitute for a required company approval.

How are connector credentials handled?

The integration documentation describes connector tokens encrypted on the backend. Public connection records expose account, status and scope metadata rather than the tokens.

For infrastructure-wide encryption coverage, backup protection and key-management details, discuss the specific deployment with our team.

Can we revoke a connection?

Connection management includes revocation and changes to the connection audience. Disconnection and deletion of previously processed information are different operations.

Before rollout, agree how copies, indexes, conversations, work records and backups are retained or removed. No instant or universal deletion guarantee is stated here.

Is our information used to train AI models?

Review the model providers and data-use terms for your deployment before connecting sensitive information. Retention and model training are separate questions. This page does not make a blanket no-training or zero-retention promise.

Include those requirements in your security review before connecting sensitive information.

What about GDPR, ISO 27001 and SOC 2?

Product controls and independent assurance are different things. No ISO 27001 certification or SOC 2 report is claimed on this page.

GDPR compliance and voluntary certification are different things. Evaluate the actual processing, contract and supporting measures with your organisation’s advisers.

Can we review security before a rollout?

Yes. Start the conversation with your use case, tools, data categories and any assurance requirements. The review questions on this page help structure the discussion about access, processing, retention, incidents and evidence.

Do not put credentials, personal records or exploit details into a general booking form.

Let’s work through the details

Bring your team.
Bring your requirements.

Start with the use case, the connected tools and the controls your organisation needs.