Trust
What Agent Console holds, where it runs, and where data goes.
The data boundary of a customer installation, as the product implements it today.
Where it runs
- Your environment
- One deployment for one organization, in your own environment, signed in through your identity provider (a configured OpenID Connect provider, with a documented SCIM provisioning interface), on PostgreSQL 15 or newer with row-level security on every organization’s rows. Nothing it does needs a connection to LockedIn Labs. The design partnership plan names the install path for your estate.
- Install paths
- Documented Azure Container Apps/Bicep and Kubernetes/Helm paths. Configuration validation is separate from a successful installation in your environment. Connector credentials are held as references (
env://andvault://) and resolved from the environment or HashiCorp Vault at the moment of use. - Outside the request path
- The console collects evidence beside the request path. Callers use configured gateways or native provider connections; the optional Agent Console Gateway is a separate runtime. Approved controls reach supported gateway and hook targets. Readback compares configuration; decision records provide separate enforcement evidence.
- Support access
- Support access and any data transfer require your authorized scope, and troubleshooting grants no standing access. If a deployment adds remote support or vendor-operated processing, that access and its agreement are documented first.
What it holds
The usage reporter collects counts and supported metadata without prompts, responses, source code or local paths. Optional Ask sends the question and authorized evidence excerpts to your configured model provider. Agent Console makes no coverage or clinical decisions.
An installation holds directory and device inventory, usage and cost snapshots from approved sources, registered work and ownership, business cases, baselines, outcome measurements and reconciliations, and policy decisions with their audit evidence. Ask, if you switch it on, sends the question and authorized evidence excerpts to the provider you connect (see Where data goes). Your privacy team evaluates those data flows and the actual fields in each connected source.
- Attributable records
- Directory identity, work ownership and financial records identify people and teams. Opaque identifiers and digests are not anonymization, so access and retention controls apply to the data as it is.
- Health information
- Agent Console is designed to hold no protected health information. Your privacy and legal team evaluates the actual data flow of each connected source before it is switched on.
- Calibration and evaluation
- Tenant-local calibration and retained comparison evidence use the organization’s records. An operator enables the scheduled work; acceptance depends on the available cohort, labels and review. Optional Ask and approved exports follow the outbound boundaries below.
Where data goes
For a self-hosted installation, your configuration decides. These are the optional destinations.
| Destination | What leaves |
|---|---|
| Ask Agent Console (optional) | Ask Agent Console runs once your deployment connects a model provider (Anthropic, Azure-hosted Foundry or Amazon Bedrock). The question and the evidence excerpts the asker is allowed to read go to that provider. The model only picks evidence, and the server writes every sentence and figure. The provider's own retention and training terms apply. |
| Notifications, tickets, SIEM and metrics | The Slack, Teams, ticketing or observability destinations you configure receive their documented metadata, or an export you approve. Messages carry closed codes and a link, never people, devices or content. |
| Audit anchoring (optional) | A retention-locked storage bucket you approve receives the signed head of the audit chain and the public verification key. |
| Identity and secrets | Your identity provider and secret store handle sign-in and credential resolution, within the scopes you approve. |
Retention by dataset
Retention is set per dataset.
| Dataset | Retention |
|---|---|
| Device usage | A retention window of 400 days by default, adjustable from 1 to 3,660. Records outside it are refused on arrival. |
| Tool-call metadata | Reads cover seven days. Older rows are pruned as new ones are recorded, up to 400,000 rows per organization. |
| Ask Agent Console | The signed audit chain keeps the question's length and digests of the question, inputs, results and answer. The provider's retention is set by your agreement with it. |
| Identity, work and finance | Kept in your database. Removing a person revokes their access and keeps the history. Erasure per dataset is agreed with you. |
| Audit receipts | The application cannot modify or delete them. Retention and custody of anchors are your decision. |
| Backups and exports | Controlled by your deployment and the export destinations you approve. |
Agreements and diligence
The current assurance status, the architecture and data-flow documentation are provided under NDA on request from security@lockedinlabs.ai. Any required business associate agreement, data-processing terms and service commitments are reviewed and set in the signed agreement.
The demonstration on this site is a fictional health plan with synthetic data on a hosted reference deployment. For controls and the vulnerability process, see Security.
Take the boundary to your security team.
A design partnership runs in your own environment, at a fixed fee quoted on scope. Bring your security reviewer to the walkthrough.