[{"data":1,"prerenderedAt":38},["ShallowReactive",2],{"$f2rgzds82a9mm6":3},{"href":4,"title":5,"description":6,"kind":7,"mark":7,"planned":8,"contributors":9,"provenance":7,"html":10,"headings":11},"\u002Fdocs\u002Fcontrol\u002Fisolation","Isolation and retention","What stays inside your enterprise, what a model is and is not shown, and how long run history is kept.",null,false,[],"\u003Ch2 id=\"one-enterprise-one-tenant\">One enterprise, one tenant\u003C\u002Fh2>\n\u003Cp>Each enterprise is its own tenant. What it holds is visible only inside it:\u003C\u002Fp>\n\u003Cdiv class=\"prose__table\">\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>What\u003C\u002Fth>\n\u003Cth>Stays inside the enterprise\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>Memory\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>A run and the API read only their own enterprise's memory. Another enterprise's notes are never loaded, whatever a request asks for.\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>Runs and executions\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>Their inputs, logs, results, events and costs.\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>Credentials\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>Model connections, tool connections, the webhook secret and API tokens. None can be read back once saved, in the portal or over the API: a new webhook secret or API token is shown once, when it is made.\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>Mail\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>Each member's inbox. A run reads only its own member's mailbox.\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003C\u002Fdiv>\n\u003Cp>Inside an enterprise, memory is shared. Teams, roles and tasks are labels on one memory, not private stores, so\nnever train a secret into it. See \u003Ca href=\"\u002Fdocs\u002Fcontrol\u002Fmemory\">Memory\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>A task you clone or copy from \u003Cstrong>Catalog\u003C\u002Fstrong> brings its definition and nothing else: no credentials, no memory, no run\nhistory. See \u003Ca href=\"\u002Fdocs\u002Fwork\u002Ftasks#clone-and-copy\">Tasks\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2 id=\"throwaway-run-environments\">Throwaway run environments\u003C\u002Fh2>\n\u003Cp>A run that works on files (a clone of a repository, tests, a build) does it in a\n\u003Ca href=\"\u002Fdocs\u002Ftools\u002Fworkspaces\">workspace\u003C\u002Fa> made for that run alone. It is not shared with any other run or enterprise,\nand it is destroyed when the run finishes; a run waiting at a gate keeps its workspace until it carries on. Anything\nthe run did not push or publish goes with it.\u003C\u002Fp>\n\u003Ch2 id=\"what-the-model-sees\">What the model sees\u003C\u002Fh2>\n\u003Cp>The model a run uses is given the job: the task's goal, success metric, guardrails and skill, the run's input, and\nthe tools it may call, each as a name, a description and the arguments it takes. What a tool returns during the run\n(a file, an issue, an answer from memory) is read by the model too.\u003C\u002Fp>\n\u003Cp>It is never given where a tool lives or how it signs in. Server addresses, tokens and other credentials stay with\nthe OS, which makes each call on the model's behalf, after the task's checks and any \u003Ca href=\"\u002Fdocs\u002Fcontrol\u002Fgates\">gate\u003C\u002Fa>.\nAn argument a connection fixes (an organisation, a workspace) is taken out of what the model is shown, so it\ncannot ask for another.\u003C\u002Fp>\n\u003Cp>The model provider sees what a run sends it, on the \u003Ca href=\"\u002Fdocs\u002Fcontrol\u002Fspend#model-connections\">model connection\u003C\u002Fa> you\nchose.\u003C\u002Fp>\n\u003Ch2 id=\"how-long-run-history-is-kept\">How long run history is kept\u003C\u002Fh2>\n\u003Cp>Executions and their runs are kept for your plan's period, counted from when the whole\n\u003Ca href=\"\u002Fdocs\u002Fwork\u002Fexecutions\">execution\u003C\u002Fa> finished:\u003C\u002Fp>\n\u003Cdiv class=\"prose__table\">\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Plan\u003C\u002Fth>\n\u003Cth>Executions and runs kept for\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\n\u003Ctd>Free\u003C\u002Ftd>\n\u003Ctd>7 days\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Starter\u003C\u002Ftd>\n\u003Ctd>7 days\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Company\u003C\u002Ftd>\n\u003Ctd>30 days\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Scale\u003C\u002Ftd>\n\u003Ctd>30 days\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Enterprise\u003C\u002Ftd>\n\u003Ctd>365 days\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003C\u002Fdiv>\n\u003Cp>After that, the execution is deleted whole: every run in it, with its logs, events and results. An execution is\nnever split, and one with a run still open is never deleted, however old its first run is. A clean-up runs every\nhour.\u003C\u002Fp>\n\u003Cp>Memory is kept until someone removes it. Removing a note hides it from every run at once; the record of it stays for\naudit.\u003C\u002Fp>\n\u003Cdiv class=\"prose__planned\">\n\u003Cp class=\"prose__flag\">Planned\u003C\u002Fp>\n\u003Ch2 id=\"mail-retention-by-plan\">Mail retention by plan\u003C\u002Fh2>\n\u003Cp>Each plan lists how long member mail is kept (7 days on Free and Starter, 30 on Company and Scale, 365 on\nEnterprise). Deleting mail at the end of that period is not built yet: today received mail stays in the member's\ninbox.\u003C\u002Fp>\n\u003C\u002Fdiv>\n\u003Cdiv class=\"prose__planned\">\n\u003Cp class=\"prose__flag\">Planned\u003C\u002Fp>\n\u003Ch2 id=\"retention-you-set\">Retention you set\u003C\u002Fh2>\n\u003Cp>You will set how long your enterprise keeps run logs, memory and \u003Ca href=\"\u002Fdocs\u002Fcontrol\u002Fassets\">assets\u003C\u002Fa>, within what your\nplan allows. Custom retention is part of the Enterprise plan.\u003C\u002Fp>\n\u003C\u002Fdiv>\n\u003Cdiv class=\"prose__planned\">\n\u003Cp class=\"prose__flag\">Planned\u003C\u002Fp>\n\u003Ch2 id=\"support-access\">Support access\u003C\u002Fh2>\n\u003Cp>Zero Human staff will not read your memory, logs, assets or secrets by default. When you need help, you will grant\nsupport access yourself: for a limited time, and recorded, so you can see who looked and when.\u003C\u002Fp>\n\u003C\u002Fdiv>\n\u003Cdiv class=\"prose__planned\">\n\u003Cp class=\"prose__flag\">Planned\u003C\u002Fp>\n\u003Ch2 id=\"closing-an-enterprise\">Closing an enterprise\u003C\u002Fh2>\n\u003Cp>Closing an enterprise will delete its data. It cannot be undone.\u003C\u002Fp>\n\u003C\u002Fdiv>\n",[12,16,19,22,25,29,32,35],{"id":13,"text":14,"level":15,"planned":8},"one-enterprise-one-tenant","One enterprise, one tenant",2,{"id":17,"text":18,"level":15,"planned":8},"throwaway-run-environments","Throwaway run environments",{"id":20,"text":21,"level":15,"planned":8},"what-the-model-sees","What the model sees",{"id":23,"text":24,"level":15,"planned":8},"how-long-run-history-is-kept","How long run history is kept",{"id":26,"text":27,"level":15,"planned":28},"mail-retention-by-plan","Mail retention by plan",true,{"id":30,"text":31,"level":15,"planned":28},"retention-you-set","Retention you set",{"id":33,"text":34,"level":15,"planned":28},"support-access","Support access",{"id":36,"text":37,"level":15,"planned":28},"closing-an-enterprise","Closing an enterprise",1791124519595]