m4Mindset docs

Docs / AMS / Optimize / What Mindset enforces for you

View as Markdown

What Mindset enforces for you

The security rules Mindset holds for every agent without any setup, and the controls you can switch on when you need more.

After this page you know which security rules hold for every agent without anyone setting them up, and which extra controls you can switch on. This is the security side of Optimize. If you're writing your own agent policy, you can list the rules in the first part as controls the platform already enforces. The rest of your policy is covered in Roll out Mindset in your company.

What holds by default

A named operation is the only way out

An agent, script or function reaches an outside system only through an operation on a connection. There's no general web or HTTP tool for an agent to use. Even a public website is reached through a connection with an operation on it.

The unit of permission is the operation (get the purchase order for this invoice number), not the whole system. A list of operations is something a person can read and sign off. Even an agent that's been hijacked by text injected into a document it read can reach only those operations.

Credentials never reach the agent or the model

A connection's credentials are kept in a secret store. Mindset's database holds only a reference to them, and they're never put into an agent's context or sent to a model. Agents are told never to ask anyone to paste a credential, and a person enters one on a separate secure page.

Mindset's record names the agent that made each call. The outside system sees the connection's shared credential (or, for a StackOne connection, the end user's own). It can't tell which agent made the call.

An agent can never approve an operation

Approving a write operation is a person's act. Approve and revoke aren't on any agent's tools, and the server refuses an approval that doesn't come from a person signed in with admin rights. That holds when agents call other agents, which is where a chain of approvals could otherwise close on itself.

Every action is recorded against its run

Each operation call and model call is written to the audit record against the run it belonged to. Mindset writes the record, not the agent, so an agent can't skip it. The record is append only: the database refuses deletes.

If writing the record fails after a call has already gone out, the call still happened and the failure is logged.

Environments can't see each other

Agents, connections, triggers and schedules each live in one environment. An agent in your test environment can't reach a connection in production. An API key is issued into one environment and works only there. The org's people, settings and audit sit above the environments and are shared by all of them.

What you can switch on

ControlWhereDefaultWhat it does
A person approves each new writeSettings → Systems → Connections that change other systemsOff: writes are enabled automaticallyTurn off Turn on connections that change other systems automatically. Each new write operation then waits until a person approves it once
Approval of one action during a runA script phase with an $ask stepNonePosts the decision to Slack with buttons and parks the run until people answer
Personal data protectionSettings → Governance → Personal dataOffDetects personal data and replaces it before it reaches the model provider
OpenTelemetry exportSettings → Governance → Telemetry export (OpenTelemetry)Not set upSends traces, metrics, agent behavior and costs to your own collector
Audit retentionSettings → Governance → Audit & data residency6 monthsHow long the audit record keeps identifying details
Conversation retentionSettings → Governance → Conversation retentionKept indefinitely, except test runsWhen conversations expire after inactivity

A person approves each new write

With the setting on (the default), a new write operation is enabled as soon as it's added, and the record names the org setting as what enabled it. With it off, a person signed in with admin rights approves each new write operation once, on the connection's Operations tab. Approval is per operation, not per call. See Making it run, and approving what it does.

Approval of one action during a run

To have a person decide on each specific action (approve this supplier query, reject that one), the script author adds an $ask step to a phase. Slack is the only place it can post today. See Write a script.

Personal data protection

Under What happens to personal data in transit, pick one:

OptionWhat happens
Off: personal data is not substitutedMessages reach the model provider as written. The default
Redact permanently: the real value never comes backThe agent and every tool it calls see placeholders. Anything that needs the real value fails
Redact, with audited access to the real valueReplaced before the provider sees it, restored on the way back. Each restore is recorded in the audit trail
Redact in transit onlyReplaced before the provider sees it and restored straight away on the way back

You can add your own detection rules in the same card.

OpenTelemetry export

Enter your OTLP endpoint, and an Auth header name and Auth token if your collector needs them. Then choose what to send: Send traces, Send metrics, Send agent behavior (script phases and gate outcomes), Include end-user identifiers and Send costs. Costs are off until you turn them on.

Retention

Audit retention (months) is at least 6 and at most 120. When records pass it, their identifying details are removed. The records themselves aren't deleted.

Conversation retention is set separately for end-user conversations and unattended runs, rehearsals, authoring conversations and test runs. Each is Kept indefinitely or expires after a number of days without activity.

What Mindset doesn't enforce

Mindset doesn't run your acceptance tests before a version goes live, and it doesn't block activation when one fails. Run them yourself before you activate. Owners, backups and archiving unused agents are conventions your team holds. See Roll out Mindset in your company.