AgentOS

Trust center

Separate task-review, Ads-mutation and publishing controls.

Review proposals. Configure eligible task categories. Inspect the available change records.

The approval architecture

Inbox review is one gate. Eligible task categories can complete without final review under a setting you choose. Ads and publishing are separate.

Approval architectureOAuth-connected data feeds proposals. Inbox review, task-category settings, Ads mutations, and publishing are separate controls. Inspect available change records, then the client portal.OAuthGSC / GA4 / AdsProposalsin InboxInbox Approvethis itemTask settingno final reviewAds ladderstill this ApprovePublishingdraft / opt-inChange recordsthen portal

Read the behavior table

Inspect the available change records

This record shows id, tenant_id, entity_type, entity_id, action, actor_id, actor_type, diff, created_at. There is no policy_id column. Actor labels are not by themselves proof a human approved.

audit_log.columns

id
tenant_id
entity_type
entity_id
action
actor_id
actor_type
diff
created_at

{
  "entity_type": "implementation_task",
  "action": "approve",
  "actor_type": "agent",
  "actor_id": "system:autonomy:<originating-agent>",
  "diff": {
    "autonomyLevel": "autonomous",
    "category": "<tuple category>",
    "reason": "plan_steps_delivered"
  }
}

Data handling

Data handling
TopicWhat the source supports
What we accessReviewed source requests webmasters.readonly for GSC, analytics.readonly for GA4, and adwords for Ads. Ads writes and publishing exist; integrations are not all read-only.
What we storeWorkspace configuration, recommendation history, approval decisions, and the change-record fields shown below. Completeness is not guaranteed: audit inserts can fail without rolling back the action.
What we do not claimA human does not approve every change. Separate scoped-agent APIs exist. Training, retention, and subprocessors remain unverified as marketing facts.

Permissions and tenancy

Selected routes compare tenant and client ownership. That is not a proof of row-level security, separate databases, or owner-only approvals. Viewer write-guards exist; per-assigned-client analyst enforcement is not established here.

Subprocessors and model providers

Source includes Anthropic-direct and AWS Bedrock selection. That is not a production vendor inventory, a training opt-out, or a data residency guarantee.

Read the Privacy Policy

Roadmap honesty

  • SOC 2: Not completed. Stated intent; no badge until held.
  • Penetration test: Not published. No fake report links.
  • DPA: Available when the first Partner conversation requires it (/dpa).
  • Review proposals. Configure eligible task categories. Inspect the available change records.
  • Questions about trust? Talk to us.