Least privilege
LiveRiley asks for the narrowest access that gets the job done. If a workflow only needs to read, that is all it gets.
Security
audit the outcome · verify activation · prove it every Friday
AI is only useful for real work if it can touch your real tools, and that should never mean handing out blank checks. Every surface that works through Riley gets scoped access, approval-gated writes, and a record of what happened. No vendor can honestly promise perfect security; what we promise is narrow access, a human gate on writes, and proof you can check.
How the gateway works
AI asks through Riley. Your dashboard, Slack, and any connected AI client (Claude, ChatGPT, Cursor, your own agents) all reach your business tools through the same door: Riley. No surface gets a side door.
Riley enforces the rules. Scoped permissions, read / draft / write modes, and workspace isolation apply to every request. Anything that would change something outside your workspace stops in your approvals queue first.
Every action leaves a record. Completed work lands in the outcome ledger as it happens, and finished jobs can carry a signed receipt you can verify. The record is written at action time, not reconstructed later.
Security principles
Live means enforced in the product today. Partial means real but not complete, and the description says what is missing. Planned means a commitment, not a feature.
Riley asks for the narrowest access that gets the job done. If a workflow only needs to read, that is all it gets.
Each connection is scoped to what you grant during connect. Riley cannot reach past the scopes you approved.
Every integration works at one of three levels: read only, drafts for your approval, or writes that always pass through approval first.
Actions that change something outside your workspace wait in your approvals queue. You see what will happen before it happens.
Your workspace's data, connections, and keys are scoped to your workspace. Requests are pinned to the signed-in workspace on every call.
Disconnect an integration or revoke an access key at any time from Settings, and it stops working immediately.
You can mint a new key and revoke the old one whenever you want. Automatic scheduled rotation is not built yet, so rotation is a manual step today.
Connection credentials stay in the connection layer and sensitive fields are redacted from logs. Models work with results, not your raw secrets.
Completed actions land in the outcome ledger as they happen, and security-relevant events are recorded separately. The record is written at action time, not reconstructed.
Work done through Riley is recorded wherever it came from. A per-surface usage breakdown is only partly built, so today you see the work but not yet a full per-surface report.
What Riley remembers about your business is yours to read and edit from the dashboard, including brand voice and preferences.
Export your workspace data or delete your account from Settings. Deletion uses a grace period, then your data is removed.
Your data is not used to train models behind your back. Any cross-customer learning is opt-in and off by default.
Requests arriving through connected AI clients pass through the same approval gate as everything else. No surface gets a side door.
Role-based access for teams exists but is not yet fully surfaced across every page, so treat per-role boundaries as partial today.
AI access safety
AI access keys are minted per workspace in Settings and displayed exactly once. We store a hash, not the key, so nobody at Riley can read it back. Revoke any key at any time and it stops working immediately.
A request from Claude, ChatGPT, Cursor, or any other connected client passes through the same approval gate as work you start in the dashboard. External writes wait in your queue no matter which surface asked.
Connection credentials stay in the connection layer, and sensitive fields are redacted from logs. Models work with results, not your stored tokens or passwords.
See every surface Riley works from at Riley anywhere, or the technical details at developers.
Your controls
Anything that writes outside your workspace waits for a named approval. You choose the posture: approve everything, or approve external writes only.
What Riley remembers about your business, including brand voice and preferences, is yours to read and edit from the dashboard.
Disconnect any integration or revoke any access key from Settings whenever you want. Access ends immediately.
Export your workspace data or delete your account from Settings. Deletion uses a grace period, then your data is removed.
Riley's playbooks and recommendations are updated as models, clients, and platforms change.
Compliance status
Live today
In progress
Data protection documents (DPA, subprocessor list) are available on request via support@hireriley.com or the contact form. Current posture always lives on /trust.
Ask us anything about permissions, data handling, or access controls. And see what the record looks like on the proof side.