TRUST & RECOVERY

Keep Alex useful, accountable and recoverable.

One place to review the workspace memory, set retention expectations and export the evidence Alex has built before anything is removed.

WORKSPACENorthstar Group plcv0.89 safeguards are available
LIFECYCLE EVENTS0

Recorded in the last 30 days.

SAFEGUARDED DELETES0

Delete attempts Alex stopped safely.

DELIVERY FAILURES2

Recent outbox events needing review.

EXPORTS12

Recent workspace or record exports.

RETENTION POLICY

Keep the memory useful and recoverable

These are the workspace defaults Alex will use when retention automation is enabled. Nothing is silently deleted by saving this policy.

Download workspace audit

Export files contain safe workspace metadata, lifecycle history and delivery status; connector credentials are never included.

SECURITY & DATA

Your Public Affairs work belongs to your organisation.

Workspace membership—not ownership of the Alex platform—controls access to documents, positions, Issues, stakeholders, conversations and outputs.

Platform access blocked
Tenant isolation

Organisation IDs and database policies separate your records from every other customer.

Named access

Owners control users and roles. Consultancy colleagues see only explicitly assigned client accounts.

Human authority

Alex can recommend and draft positions; people approve positions and consequential external action.

Data lifecycle

Retention, archive, recovery and export controls preserve an accountable evidence trail.

Customer-controlled knowledge

Owners can keep originals in approved Drive or SharePoint folders and let Alex retain only structured, reviewable evidence.

SUPPORT ACCESSDisabled by default

Alex platform operators cannot browse this workspace. Any future content support session must be customer-approved, purpose-limited, audited and automatically expire.

0 support access records
Controls Alex can evidence today
  • Database-enforced tenant and role boundaries
  • Private, organisation-scoped records and file access
  • Human approval for positions and external action
  • Retention, export, recovery and audit controls
  • Platform operations separated from customer PA content

Independent certifications, penetration-test results and formal assurance should only be advertised after they have been completed.

PRODUCTION READINESS

Can Alex be trusted to keep going?

Checked 20 Sept, 21:39Download support snapshot

A bounded check of the foundations around Alex’s colleague loop. It does not expose secrets, record contents or pretend that an external backup test has happened.

2healthy
2needs attention
2review before rollout
Core server configurationHealthy
Configured

Alex has the server configuration needed for research, Brain access and organisation-scoped writes.

Next: No action needed
Workspace access boundaryNeeds attention
Prototype mode

The app is using its prototype fallback, so signed-in organisation boundaries are not enforced.

Next: Set ALEX_REQUIRE_AUTH=true before inviting a design partner
Governed recovery and Policy File schemaHealthy
Ready

Lifecycle history, export ledger and source-linked Policy File change assessment are available.

Next: No action needed
Live UK monitoringReview before rollout
completed with errors

A recent cycle exists, but it recorded a warning or did not complete cleanly.

Next: Open Monitoring and inspect the latest run
Colleague delivery pathNeeds attention
2 failed

2 deliveries failed in the last seven days: Generic email delivery needs RESEND_API_KEY and ALEX_EMAIL_FROM.

Next: Open Integrations and retry or review the ledger
Backup and restore readinessReview before rollout
External verification

Alex records recovery and export evidence, but database backup/restore must be confirmed in the production Supabase project.

Next: Run and record a production restore test before wider rollout
ACCOUNTABILITY

Recent record decisions

Archive, restore and guarded delete attempts remain visible.
No lifecycle events have been recorded in the last 30 days.
EXPORT HISTORY

What has been taken out

Exports expire from the ledger after 30 days; the downloaded file remains with the team.
Work export1 objects · completed
Work export1 objects · completed
Stakeholder export1 objects · completed
Stakeholder export1 objects · completed
Stakeholder export1 objects · completed
Work export1 objects · completed
Work export1 objects · completed
Workspace audit export354 objects · completed
Issue export1 objects · completed
Work export1 objects · completed
Issue export1 objects · completed
Work export1 objects · completed
Alex’s rule: ordinary records can be archived and restored; signals, evidence, approved outputs, Policy File history and audit events are never hard-deleted through the normal product UI.