“Can another team see our data?”
One missing filter in one query, and a workspace leaks. Application checks alone are one bug away from it.
ConvOps security fails closed. No context, no data. No verified person, no write. No approval, no step. Every layer a request crosses is built to refuse first.
row-level security with force · server-stamped identity · gates that refuse
It is built to fail closed: no workspace context, no data; no verified person, no write; no approval, no step. Each claim below names its limit.
ConvOps is the operations layer for AI agents: an MCP server that holds your team's process as workflows, with approval gates, a shared memory and an audit trail. It runs no AI models.
updated
Before a team lets AI touch real work, someone has to answer these. Plainly, and with evidence.
“Can another team see our data?”
One missing filter in one query, and a workspace leaks. Application checks alone are one bug away from it.
“Was that the AI or a person?”
If the log trusts whatever name the caller sends, the log proves nothing.
“What stops an agent going too far?”
A rule written in a prompt is a request. The model can skip it, and nobody sees it happen.
Every request from an AI client crosses the same layers, in the same order. Pick one and watch where it stops.
A query reads only the workspace its context points to. The wall is in the database itself, so an app bug cannot open it.
Every claim comes with how far it goes and how it works. Read the middle row first.
A security review should not find surprises. These are the limits, stated before you ask.
Scoped or expiring API keys
Keys have neither. A key acts as its user until you revoke it.
Granular permissions
Three roles: owner, admin, member. Nothing finer.
An audit trail of everything
Before and after diffs cover tasks and workflow instances only.
A recorded approver on every gate
A gate records that approval was given. Who approved is not stored separately.
Policies that block
Policies are guidance delivered to the agent. Gates are what refuse.
A verified agent name
The agent label is self-declared. Only the person is verified.
Compliance certifications
This page lists none. Ask us what your review needs.
Self-hosting
This page describes the hosted service only. Ask us before assuming more.
Missing context, a missing identity or an unmet gate all end the same way: nothing happens.
the default state
Isolation lives in the database itself. A bug in the app still cannot read across.
row-level security
Who you are comes from your sign-in, never from what a caller says.
server-stamped
Owner, admin, member. Simple to review, real refusals.
real 403s
Before and after, field by field, on tasks and workflow runs.
scoped, honestly
For the engineer on the review. The real policy, the real audit fields, and the scope of each.
Every tenant-scoped table carries this RLS policy, applied with FORCE. Rows with no owner are the shared global catalog.
USING (
org_id = current_setting(
'app.current_tenant_id', TRUE)
OR org_id IS NULL
)The agent label is self-declared. The user fields are stamped server-side from the verified credential.
{
"actor": "implementer",
"actor_user_id": "usr_…",
"actor_user_name": "David Marsa"
}The MCP surface uses OAuth 2.1 with JWKS verification. A static key path exists for automation. Keys are bcrypt-hashed, shown once, scoped to the user across their workspaces.
Field-level before and after diffs on tasks and workflow instances. Per-step history with decision context. The audit endpoints are REST and web app only; there is no MCP tool for them.
Bring your questions. We go through each control on this page with you, including where it stops.
It reads nothing. The row-level security policy keys on the request's tenant setting, and with FORCE applied even the table owner cannot step around it. Fail closed is the default state, not an error path.
No, by design. Keys are bcrypt-hashed at rest and displayed exactly once at creation; if one is lost, you revoke it and mint another.
From the verified credential, stamped server-side. There is no request field, header, or tool parameter that carries it, so it cannot be spoofed by an agent or a caller.
SSO and SCIM are part of the Enterprise plan. Standard sign-in is OAuth; the MCP surface authenticates with OAuth 2.1 and JWKS verification, with a static key path for automation.
There are three: owner, admin and member. They are enforced with real 403s at the route and service layer, with last-owner protection. There are no custom roles or per-item permissions.
No to both. A key acts as its user, across that user's workspaces, until it is revoked. People sign in with OAuth; keys are for automation, and should be handled like passwords.
Field-level before and after diffs for tasks and workflow instances, the places where agents act. It does not cover every table. The audit log is read in the web app and the REST API, not from inside the chat client.
Only the workspaces you are a member of. Recall searches across your own memberships in one query; each memory stays owned by its workspace, and every write lands in exactly one.