Skip to content

Security & Data

How AgentHub protects access to your work.

Workspace access and purpose-specific sharing links help you control who can see your work. The sections below explain how each type of access works.

Access stays tied to the record and the decision.

The product uses workspace access controls for operators and purpose-built links for clients.

Workspace access

Signed-in users work inside workspace-scoped records. Database policies and ownership checks restrict access to the active workspace.

Secure approval links

Approval links expire after 14 days, can be revoked or replaced, and accept one client response. AgentHub creates the link. It does not send it automatically.

Human control

AgentHub does not automatically approve, implement, verify, publish, send, or edit a client automation. Those decisions remain with the people responsible for the work.

No-account approval

A secure link is a credential, not an identity claim.

The link lets its holder review one frozen request and respond once. AgentHub records the named response, but the link itself is not an electronic signature or proof of the viewer's identity.

Credential handling

The secret stays in the URL fragment. AgentHub stores only its SHA-256 hash, not the raw token.

Opening the link

The record can show when the approval page was first opened successfully. It does not identify who opened it and does not store an IP address, user agent, or open count for that event.

Approval-page privacy

The approval page is configured as no-index, no-store, and no-referrer, and it does not load third-party analytics.

Invalid links

Expired, revoked, replaced, and invalid links do not disclose the client, workspace, or requested scope.

Record enough to support the decision.

AgentHub is built to hold the operating record around client work, not the secrets that make the automation run.

  • Workflow snapshots exclude credentials, node parameters, field values, and execution payloads.
  • Implementation evidence stores a link and reference. AgentHub does not ingest the linked source code.
  • Approval records preserve the decision while keeping missing identity evidence visible.

Forwarded email

Only what you forward, only from you.

Each workspace has a private forwarding address. A forwarded email becomes a draft only when it comes from the email address of an active workspace member; anything else is dropped without a reply.

AgentHub stores the forwarded text, capped at 12,000 characters, the member who forwarded it, the sender named in the forwarded header, and the subject. It does not connect to your mailbox and reads nothing you do not forward.

A dismissed draft keeps only that it was dismissed and by whom. Its text is removed.

Private skills and sharing

You choose when a skill leaves your private drafts.

A skill share link gives anyone holding it access to preview and download that saved version, including its instructions and creator details. No recipient account is required, and the link can be forwarded.

Later draft edits do not change that shared version. Revoking the link stops future access through it; it cannot recall copies already downloaded. Skill links are separate from client approval links and do not use their 14-day expiration.

Review the complete skill before sharing. Client workflow references are excluded, but any confidential information you write into the skill must be removed by you.

Security status

These are product boundaries, not a certification.

This page is not a SOC 2, ISO, privacy-law, or industry-compliance attestation. It describes current AgentHub behavior and will be updated as the product changes.

Workspace controls reviewedAugust 15, 2026Report a concern