Workspace access
Signed-in users work inside workspace-scoped records. Database policies and ownership checks restrict access to the active workspace.
Security & Data
Workspace access and purpose-specific sharing links help you control who can see your work. The sections below explain how each type of access works.
Control boundaries
The product uses workspace access controls for operators and purpose-built links for clients.
Signed-in users work inside workspace-scoped records. Database policies and ownership checks restrict access to the active workspace.
Approval links expire after 14 days, can be revoked or replaced, and accept one client response. AgentHub creates the link. It does not send it automatically.
AgentHub does not automatically approve, implement, verify, publish, send, or edit a client automation. Those decisions remain with the people responsible for the work.
No-account approval
The link lets its holder review one frozen request and respond once. AgentHub records the named response, but the link itself is not an electronic signature or proof of the viewer's identity.
The secret stays in the URL fragment. AgentHub stores only its SHA-256 hash, not the raw token.
The record can show when the approval page was first opened successfully. It does not identify who opened it and does not store an IP address, user agent, or open count for that event.
The approval page is configured as no-index, no-store, and no-referrer, and it does not load third-party analytics.
Expired, revoked, replaced, and invalid links do not disclose the client, workspace, or requested scope.
Data boundaries
AgentHub is built to hold the operating record around client work, not the secrets that make the automation run.
Forwarded email
Each workspace has a private forwarding address. A forwarded email becomes a draft only when it comes from the email address of an active workspace member; anything else is dropped without a reply.
AgentHub stores the forwarded text, capped at 12,000 characters, the member who forwarded it, the sender named in the forwarded header, and the subject. It does not connect to your mailbox and reads nothing you do not forward.
A dismissed draft keeps only that it was dismissed and by whom. Its text is removed.
Private skills and sharing
A skill share link gives anyone holding it access to preview and download that saved version, including its instructions and creator details. No recipient account is required, and the link can be forwarded.
Later draft edits do not change that shared version. Revoking the link stops future access through it; it cannot recall copies already downloaded. Skill links are separate from client approval links and do not use their 14-day expiration.
Review the complete skill before sharing. Client workflow references are excluded, but any confidential information you write into the skill must be removed by you.
Security status
This page is not a SOC 2, ISO, privacy-law, or industry-compliance attestation. It describes current AgentHub behavior and will be updated as the product changes.