Security and data handling

Understand the data path before you run work.

An agent task can involve AgentSky, a model provider and connected applications. Review each boundary and your account settings against the published privacy policy and terms.

Data boundaries

Follow the information through the task.

Use the privacy policy for the current definitions, controls and retention windows. This overview helps you identify the questions to resolve for a particular workflow.

  • Task inputs and runtime

    Identify the prompts, files and workspace state the task requires. Review processing storage and deletion behavior before using sensitive information.

  • Model providers

    Check the selected provider and the account controls governing provider training and retention. Do not treat every model route as having identical data terms.

  • Connected applications

    Review the scopes and account authorized for each connector. A messaging channel and an application-data connector serve different purposes.

  • Trace history and contribution

    Review history and contribution as separate settings. The privacy policy explains their purposes and retention; confirm the settings in the account used for the evaluation.

Before a pilot

Test with the access the task actually needs.

Begin with non-sensitive representative material while your organization completes its data review.

01

Inventory data and authority

Record the systems the task reads and changes, the authorized accounts, and the human owner of any consequential action.

02

Review policies and settings

Read the privacy policy and terms, verify provider and trace settings, and confirm any contractual requirements directly with the team.

03

Verify revocation and cleanup

Include connection removal, agent deletion and the relevant retention windows in your evaluation. Keep the evidence with the pilot decision.

Common questions

Data review questions

Where are the retention periods documented?

The privacy policy’s retention section describes the windows for runtime state, traces, logs, account data and billing records. Review the current policy and the settings that apply to your account.

Can we assume every provider has the same training policy?

No. Review the selected model provider and the routing settings described in the privacy policy. Obtain confirmation of any provider restriction required by your organization.

Where do we request a security or procurement review?

Use the enterprise evaluation contact to discuss your requirements. Request the specific evidence or contractual terms you need before treating a requirement as satisfied.

Sources and setup references

Resolve your evaluation requirements.

Discuss your pilot