文档首页

Governance

Roles, API keys, models, and data handling

Security-minded overview of access control, credential rotation, retention, and what to document for enterprise reviews.

securityapi keysrolesretention

Governance is how you keep FlexyAgents aligned with SOC-style questionnaires: who can change prompts, who sees PII-heavy transcripts, and how long data persists.

Specific controls may be plan-gated—validate against your subscription and DPAs.

For step-by-step provider keys (OpenAI, Anthropic, Google Gemini, etc.), see Documentation → Governance → LLM API keys (BYOK).

Roles and least privilege

Separate knowledge editors, people who manage billing and subscriptions, and people who can view transcripts. Break-glass procedures should disable risky automations without deleting historical audit data when policy allows.

Review membership quarterly, especially for contractors.

  • Typical split: admins (org settings, billing), builders (agents, knowledge), analysts (read-only analytics), support leads (transcript review where permitted).
  • Avoid shared “utility” accounts; named users improve audit trails.

API keys and model keys

Server-side keys must never ship to browsers. Rotate on schedule and after employee departures.

Document which agents use BYOK endpoints for incident response drills.

Chat/embed API keys identify your app to FlexyAgents; LLM provider keys in Settings → LLM API Keys are sent to OpenAI, Anthropic, Google, or other vendors you enable—under your contract with them.

  • Chat/API keys: used for HTTP API and widget authentication—scope to the minimum agents and environments.
  • LLM keys: optional per provider; when present, inference for that provider can use your key instead of hosted pooled keys (depending on plan and agent settings).

Data retention and export

Align retention with customer contracts and GDPR/CCPA expectations. Know how to export or delete records for DSARs before you need it in production.

Redact or minimize PII sent to third-party LLM providers per your agreements.

在你的技术栈上构建

准备上线有依据的助手了吗?

开始试用,或与我们沟通上线、治理和企业级要求。