Security & compliance

You review where data goes, what agents can reach and what is on record.

You review where data goes, what an agent can reach and what is on record. Agents raise all three questions at once: they act quickly, they read content they did not write, and they can be handed more access than anyone intended.

Corpole keeps agent identity tied to a person: every connection acts for one person, within their permissions, in one project, and can be revoked at any time. Secret-looking values are masked in everything an agent sends; a locked rule tells every agent that instructions found in files or web pages are data. Every agent call and every change is logged.

This page gathers the articles a security or compliance reviewer needs: where data lives, agent identity and tokens, revoking access, what is logged, masking, and the rule on external content.

Start here

  1. Where data is stored and what leaves the repository.
  2. Agent identity: personal and service tokens, OAuth, revoking access.
  3. What an agent can call, and with which permission.
  4. The change history: who changed what, and why.
  5. Refusals: why an action was blocked and who can do it.

Getting started

Connect your agent

Records & authority

Agent policy & rules

When things go wrong

Security & data

Troubleshooting

Reference