Security and data
What happens to your data and your customers', the controls you hold, and how to audit what was sent.
What you control
| Control | Where |
|---|---|
| Who sees what | Team roles limit access by function. Only the Owner sees billing — see Team and roles. |
| What the agent must never say | The Never do list in Agent behaviour — never make a medical claim, never guarantee a delivery date. |
| When a human takes over | The escalation rules: disputes, refunds, high-value orders. |
| Traceability of what was sent | Settings, then Message logs — the delivery history of every outgoing message, across all channels. |
| External system access | API keys are read-only and can be revoked individually. |
Audit what was sent
Filter by agent and by period to audit what went out and to check for delivery failures. This is the record to reach for when a customer says they never received something.
FAQ and troubleshooting
Do you use my customers' information?
Your information stays confidential and is used only to provide the service. It is not used for other purposes and not shared with unauthorised third parties.
A customer says they never received a message
Open Message logs, filter to that period and channel, and check the delivery status. A failure there tells you whether the message left at all.
How do I stop the agent saying something specific?
Add it to Never do in Agent behaviour, as one short sentence. That is the most reliable guardrail available.
What's next?
Give external systems controlled, read-only access to your data.