Choose the audience.
Choose private, shared or centralised access.Decide who can use a connected accountinside The925.
Understand connection access
Know who can use a connection, what OrgAI can do, and when a change needs your confirmation.

Your connected workspace
Connected account access



Granted provider permissions



Workspace permissions
Intelligence within boundaries
Defined actions
Proposed change
Confirmation required
ExploreBuilt into the interaction
Access, action permissions and confirmation are different controls. The925 keeps them separate.
Choose private, shared or centralised access.Decide who can use a connected accountinside The925.
Understand connection accessCatalogued write actions need confirmation.Reading still requires access, even whenno write confirmation is needed.
See an exampleConnector tokens use backend encryption.Public records show account, status andscope metadata, never the tokens.
Controls described from the integration implementation. Availability depends on the connected account, permissions and provider setup.
Connection access
Decide how a connection is used in your organisation. Keep personal connections private or make selected connections available to the people who need them.
Who can use this connection?
Only Rachel can use this connection. Joining the workspace does not give other members access.
Provider permissions still control what Rachel’s connected account can access.
Connection settings

Rachel’s connection

Connection creator

Workspace member
Review the content a shared account can reach before making it available to others. No blanket source-permission mirroring is claimed here.
Human confirmation
Creating a draft and sending an email are separate operations. Each has its own permission requirements and confirmation step.






OrgAI can make mistakes. Double check important info.The framework behind the assistant
OrgAI works through defined operations, not unrestricted access. The connection, the action and the confirmation each matter.
01 / Access
Provider permissions, granted scopes,organisation policy and The925 accesssettings constrain what is available.
02 / Operation
Supported actions use specified input fieldsand limits. A capability label does not makean unsupported operation executable.
03 / Change
Catalogued write actions require confirmation.Reading, editing, sharing and sending arenot interchangeable permissions.
A URL or credential pasted into a prompt does not create an executable custom integration.
Explore the frameworkTransparency by connection
Explore the actions, declared permissions and confirmation requirements for each integration in our Resources library.
Privacy & data handling
Before rollout, review what is processed, who receives it and how it is retained. The details should match your deployment, not a generic badge.
Review hosting locations, model providers, subprocessors and the treatment of information sent for processing.
Clarify what happens to source copies, indexes, conversations, records and backups when data is removed or a connection is revoked.
Agree the processing purpose, contractual responsibilities and how privacy requests and incidents will be handled.
Compliance depends on the actual processing and the measures that support it. This page describes product controls; it does not claim independent GDPR certification or establish compliance on its own.
A closer look
Understand the boundaries before connecting company information.
Discuss your requirementsNo. Private connections are limited to their creator. Shared connections target selected users or roles. Centralised connections are available across the organisation subject to product permissions.
These settings control who can use the connection. The connected account’s permissions and provider grant determine its reach, so shared-source access still needs careful review.
All catalogued connector write actions require confirmation, including saving a draft, sending a message and changing file sharing. Read actions do not use the same write-confirmation step, but they still require access.
Confirmation does not override a provider restriction or substitute for a required company approval.
The integration documentation describes connector tokens encrypted on the backend. Public connection records expose account, status and scope metadata rather than the tokens.
For infrastructure-wide encryption coverage, backup protection and key-management details, discuss the specific deployment with our team.
Connection management includes revocation and changes to the connection audience. Disconnection and deletion of previously processed information are different operations.
Before rollout, agree how copies, indexes, conversations, work records and backups are retained or removed. No instant or universal deletion guarantee is stated here.
Review the model providers and data-use terms for your deployment before connecting sensitive information. Retention and model training are separate questions. This page does not make a blanket no-training or zero-retention promise.
Include those requirements in your security review before connecting sensitive information.
Product controls and independent assurance are different things. No ISO 27001 certification or SOC 2 report is claimed on this page.
GDPR compliance and voluntary certification are different things. Evaluate the actual processing, contract and supporting measures with your organisation’s advisers.
Yes. Start the conversation with your use case, tools, data categories and any assurance requirements. The review questions on this page help structure the discussion about access, processing, retention, incidents and evidence.
Do not put credentials, personal records or exploit details into a general booking form.
Let’s work through the details
Start with the use case, the connected tools and the controls your organisation needs.