Does Agentra train public models on our data?
Agentra does not require your private workflow data to train public models. Model/data boundaries are reviewed during the diagnostic and documented before deployment.
Can we keep humans in every approval loop?
Yes. Many first deployments should keep humans in every material action until quality, confidence, and exception handling are proven.
Can Agentra work with our security team?
Yes. Security review is expected for production workflows. The diagnostic is designed to surface access, retention, and control questions early.
What happens to exceptions?
Exceptions are not hidden. They are categorized, routed, reviewed, and used to improve the workflow after launch.
Who owns the workflow after launch?
Ownership is assigned before go-live. AgentOps can monitor and improve the workflow, but the client needs a business owner for rules and outcomes.
Do you need write access to our systems?
Not always during diagnostic. A production workflow may need controlled writeback, but the scope should distinguish read, draft, route, update, and blocked actions before access is granted.
Who owns credentials?
Client-owned accounts or approved service credentials are preferred where the client's security policy requires them. Credential ownership and rotation expectations should be documented before build.
Can we start with read-only access?
Often yes. Discovery and early testing can use exports, screenshots, sandbox data, or read-only access. Live writeback requires explicit approval and logging.
What data is needed for a diagnostic?
The minimum useful set is process walkthroughs, redacted samples, system screenshots or exports, approval rules, exception examples, and KPI baseline data.
How are permissions scoped?
Permissions should be scoped to the first workflow slice, required fields, required users, and approved actions instead of broad account-wide access.
What actions should be blocked by default?
Payment release, legal commitments, regulated advice, policy decisions, unsupervised client messages, and destructive record changes should be blocked unless the client explicitly approves a controlled path.
Can logs be exported?
The log format depends on the workflow and systems involved, but a launch-ready workflow should preserve run history, approver identity, reason codes, source references, and system updates.
How is PII handled?
PII handling is scoped during diagnostic. Sensitive fields should be minimized, access-controlled, routed through approved systems, and excluded from casual testing or public proof assets.
Can client data be deleted?
Deletion, retention, and export requirements should be defined in the client agreement and implementation plan before production access is granted.
Which model providers are used?
Provider choice depends on client requirements, system architecture, and security review. Model and data boundaries should be documented before deployment.
Do you support SSO or RBAC?
SSO, RBAC, and permission behavior depend on the client systems and deployment design. The diagnostic should identify what the first workflow requires.
How long does security review take?
It depends on the client's procurement and IT process. The safest path is to start review during diagnostic so access blockers do not delay the pod.
What should we send to IT before the fit call?
Send the target workflow, systems involved, desired actions, blocked actions, likely data categories, approval owners, and any security questionnaire requirements.
What will Agentra refuse to automate?
Agentra should refuse workflows where there is no owner, no approval path for material actions, no access control, no measurable KPI, or unacceptable risk.