# What Mindset enforces for you

> The security rules Mindset holds for every agent without any setup, and the controls you can switch on when you need more.

After this page you know which security rules hold for every agent without anyone setting them up, and which extra controls you can switch on. This is the security side of Optimize. If you're writing your own agent policy, you can list the rules in the first part as controls the platform already enforces. The rest of your policy is covered in [Roll out Mindset in your company](https://docs4.mindset.ai/docs/ams/roll-out-mindset-in-your-company).

## What holds by default

### A named operation is the only way out

An agent, script or function reaches an outside system only through an [operation](https://docs4.mindset.ai/docs/ams/glossary) on a [connection](https://docs4.mindset.ai/docs/ams/connect-a-system). There's no general web or HTTP tool for an agent to use. Even a public website is reached through a connection with an operation on it.

The unit of permission is the operation (*get the purchase order for this invoice number*), not the whole system. A list of operations is something a person can read and sign off. Even an agent that's been hijacked by text injected into a document it read can reach only those operations.

### Credentials never reach the agent or the model

A connection's credentials are kept in a secret store. Mindset's database holds only a reference to them, and they're never put into an agent's context or sent to a model. Agents are told never to ask anyone to paste a credential, and a person enters one on a separate secure page.

Mindset's record names the agent that made each call. The outside system sees the connection's shared credential (or, for a StackOne connection, the end user's own). It can't tell which agent made the call.

### An agent can never approve an operation

Approving a write operation is a person's act. Approve and revoke aren't on any agent's tools, and the server refuses an approval that doesn't come from a person signed in with admin rights. That holds when agents call other agents, which is where a chain of approvals could otherwise close on itself.

### Every action is recorded against its run

Each operation call and model call is written to the audit record against the run it belonged to. Mindset writes the record, not the agent, so an agent can't skip it. The record is append only: the database refuses deletes.

If writing the record fails after a call has already gone out, the call still happened and the failure is logged.

### Environments can't see each other

Agents, connections, triggers and schedules each live in one [environment](https://docs4.mindset.ai/docs/ams/environments). An agent in your test environment can't reach a connection in production. An API key is issued into one environment and works only there. The org's people, settings and audit sit above the environments and are shared by all of them.

## What you can switch on

| Control | Where | Default | What it does |
| --- | --- | --- | --- |
| A person approves each new write | **Settings → Systems → Connections that change other systems** | Off: writes are enabled automatically | Turn off **Turn on connections that change other systems automatically**. Each new write operation then waits until a person approves it once |
| Approval of one action during a run | A script phase with an `$ask` step | None | Posts the decision to Slack with buttons and parks the run until people answer |
| Personal data protection | **Settings → Governance → Personal data** | Off | Detects personal data and replaces it before it reaches the model provider |
| OpenTelemetry export | **Settings → Governance → Telemetry export (OpenTelemetry)** | Not set up | Sends traces, metrics, agent behavior and costs to your own collector |
| Audit retention | **Settings → Governance → Audit & data residency** | 6 months | How long the audit record keeps identifying details |
| Conversation retention | **Settings → Governance → Conversation retention** | Kept indefinitely, except test runs | When conversations expire after inactivity |

### A person approves each new write

With the setting on (the default), a new write operation is enabled as soon as it's added, and the record names the org setting as what enabled it. With it off, a person signed in with admin rights approves each new write operation once, on the connection's **Operations** tab. Approval is per operation, not per call. See [Making it run, and approving what it does](https://docs4.mindset.ai/docs/ams/making-it-run-and-approving-what-it-does).

### Approval of one action during a run

To have a person decide on each specific action (approve this supplier query, reject that one), the script author adds an `$ask` step to a phase. Slack is the only place it can post today. See [Write a script](https://docs4.mindset.ai/docs/ams/write-a-script).

### Personal data protection

Under **What happens to personal data in transit**, pick one:

| Option | What happens |
| --- | --- |
| **Off: personal data is not substituted** | Messages reach the model provider as written. The default |
| **Redact permanently: the real value never comes back** | The agent and every tool it calls see placeholders. Anything that needs the real value fails |
| **Redact, with audited access to the real value** | Replaced before the provider sees it, restored on the way back. Each restore is recorded in the audit trail |
| **Redact in transit only** | Replaced before the provider sees it and restored straight away on the way back |

You can add your own detection rules in the same card.

### OpenTelemetry export

Enter your **OTLP endpoint**, and an **Auth header name** and **Auth token** if your collector needs them. Then choose what to send: **Send traces**, **Send metrics**, **Send agent behavior (script phases and gate outcomes)**, **Include end-user identifiers** and **Send costs**. Costs are off until you turn them on.

### Retention

**Audit retention (months)** is at least 6 and at most 120. When records pass it, their identifying details are removed. The records themselves aren't deleted.

**Conversation retention** is set separately for end-user conversations and unattended runs, rehearsals, authoring conversations and test runs. Each is **Kept indefinitely** or expires after a number of days without activity.

## What Mindset doesn't enforce

Mindset doesn't run your [acceptance tests](https://docs4.mindset.ai/docs/ams/test-an-agents-behavior) before a version goes live, and it doesn't block activation when one fails. Run them yourself before you activate. Owners, backups and archiving unused agents are conventions your team holds. See [Roll out Mindset in your company](https://docs4.mindset.ai/docs/ams/roll-out-mindset-in-your-company).
