Workspace access
Signed-in users work inside workspace-scoped records. Database policies and ownership checks restrict access to the active workspace.
Security & Data
AgentHub keeps client change records inside a workspace and gives clients narrow, time-limited links for specific decisions. This page explains what those controls do and what they do not prove.
Control boundaries
The product uses workspace access controls for operators and purpose-built links for clients.
Signed-in users work inside workspace-scoped records. Database policies and ownership checks restrict access to the active workspace.
Approval links expire after 14 days, can be revoked or replaced, and accept one client response. AgentHub creates the link. It does not send it automatically.
AgentHub does not automatically approve, implement, verify, publish, send, or edit a client automation. Those decisions remain with the people responsible for the work.
No-account approval
The link lets its holder review one frozen request and respond once. AgentHub records the named response, but the link itself is not an electronic signature or proof of the viewer's identity.
The secret stays in the URL fragment. AgentHub stores only its SHA-256 hash, not the raw token.
The record can show when the approval page was first opened successfully. It does not identify who opened it and does not store an IP address, user agent, or open count for that event.
The approval page is configured as no-index, no-store, and no-referrer, and it does not load third-party analytics.
Expired, revoked, replaced, and invalid links do not disclose the client, workspace, or requested scope.
Data boundaries
AgentHub is built to hold the operating record around client work, not the secrets that make the automation run.
Claim discipline
This page is not a SOC 2, ISO, privacy-law, or industry-compliance attestation. It describes current AgentHub behavior and will be updated as the product changes.