Organisation IDs and database policies separate your records from every other customer.
Keep Alex useful, accountable and recoverable.
One place to review the workspace memory, set retention expectations and export the evidence Alex has built before anything is removed.
Recorded in the last 30 days.
Delete attempts Alex stopped safely.
Recent outbox events needing review.
Recent workspace or record exports.
Keep the memory useful and recoverable
These are the workspace defaults Alex will use when retention automation is enabled. Nothing is silently deleted by saving this policy.
Your Public Affairs work belongs to your organisation.
Workspace membership—not ownership of the Alex platform—controls access to documents, positions, Issues, stakeholders, conversations and outputs.
Owners control users and roles. Consultancy colleagues see only explicitly assigned client accounts.
Alex can recommend and draft positions; people approve positions and consequential external action.
Retention, archive, recovery and export controls preserve an accountable evidence trail.
Owners can keep originals in approved Drive or SharePoint folders and let Alex retain only structured, reviewable evidence.
Alex platform operators cannot browse this workspace. Any future content support session must be customer-approved, purpose-limited, audited and automatically expire.
Controls Alex can evidence today
- Database-enforced tenant and role boundaries
- Private, organisation-scoped records and file access
- Human approval for positions and external action
- Retention, export, recovery and audit controls
- Platform operations separated from customer PA content
Independent certifications, penetration-test results and formal assurance should only be advertised after they have been completed.
Can Alex be trusted to keep going?
A bounded check of the foundations around Alex’s colleague loop. It does not expose secrets, record contents or pretend that an external backup test has happened.
Alex has the server configuration needed for research, Brain access and organisation-scoped writes.
Next: No action neededThe app is using its prototype fallback, so signed-in organisation boundaries are not enforced.
Next: Set ALEX_REQUIRE_AUTH=true before inviting a design partnerLifecycle history, export ledger and source-linked Policy File change assessment are available.
Next: No action neededA recent cycle exists, but it recorded a warning or did not complete cleanly.
Next: Open Monitoring and inspect the latest run2 deliveries failed in the last seven days: Generic email delivery needs RESEND_API_KEY and ALEX_EMAIL_FROM.
Next: Open Integrations and retry or review the ledgerAlex records recovery and export evidence, but database backup/restore must be confirmed in the production Supabase project.
Next: Run and record a production restore test before wider rollout