ColleagueOne documentation

Security model

Understand isolation, credentials, model access, data controls, approvals and identity in ColleagueOne.

ColleagueOne’s security model places controls around the full work lifecycle: who can define a colleague, what it can access, where it runs, what models it can use and which actions require a person.

Runtime isolation

Every colleague runs in its own Firecracker microVM sandbox. This separates the work runtime from other colleague runs and from the control services that mediate credentials and policy.

Credential boundary

Vendor connection credentials remain in the gateway and are never handed to the colleague. Do not bypass this boundary by putting secrets in goals, files, conversations or custom instructions.

Model gateway

Model access is mediated through a model gateway. Per-run scoped keys and budgets can be governed per colleague and per organisation. ColleagueOne is model-agnostic and can use OpenAI, Anthropic and other configured providers through that gateway.

Human approval

Sensitive actions can require approval. The proposed action and context appear in Needs You so an authorised person can approve, decline or redirect the work.

Data policy

Data classification labels and DLP policy help organisations define how content should be handled. Workspace content can be processed by third-party model providers as required to provide the service; organisations should choose models and inputs consistent with their policy.

Identity and roles

Owner, admin and member roles combine with Google, Microsoft Entra, SAML or OIDC sign-in. SCIM supports lifecycle management. Organisations remain responsible for role assignment and access review.

Audit and reviewability

Audit logging supports investigation and accountability. Results, approvals and reviewed memory make important outcomes and persistence decisions visible in the product.

Compliance position

ColleagueOne is built for UAE organisations and designed with UAE PDPL considerations in mind. PDPL-aware does not mean certified compliance. ColleagueOne does not currently claim SOC 2, ISO or other certifications on this site, and does not claim UAE data residency.

Report a security issue

Follow the responsible disclosure policy and use the listed private contact. Do not include live secrets or unnecessary personal data in an initial report.