AigenzeyDocs
Home/Docs/Admin, Governance & Security

Admin, Governance & Security

Aigenzey Cowork is built from the ground up for modern enterprise governance, strict tenant isolation, auditable execution, and comprehensive data protection.

Organizations, Users & Roles

Cowork provides a clear multi-tenant organizational structure with granular permission tiers:

RoleAccess ScopeCapabilities
MemberPersonal & Assigned DepartmentsExecute chat tasks, create personal skills, connect personal productivity tools, and run department playbooks.
Department AdminDepartment WideManage department members, curate department playbooks, and approve shared team skills.
Organization AdminOrganization WideInvite and manage team members, configure enterprise SSO, create departments, set organizational usage budgets, manage custom connector credentials, and inspect company audit logs.

Departments & Access Boundaries

Organizations can segment users into logical departments (e.g. Sales, Engineering, People/HR, Finance, Legal):

  • Skill Boundary Enforcement: Skills authored for specific departments are only visible to and executable by authorized members of those departments.
  • Department Connector Restrictions: High-impact enterprise connectors (such as Salesforce, NetSuite, Workday, or Stripe) can be restricted to relevant departments (e.g. restricting CRM tools exclusively to Sales & RevOps).

Enterprise Single Sign-On (SSO)

For Business & Enterprise workspaces, Aigenzey Cowork provides native Single Sign-On (SSO) integration supporting OpenID Connect (OIDC) and SAML-compatible identity federation with industry-leading Identity Providers.

SSO Architecture & Overview

Configuring enterprise SSO enables streamlined, secure employee access through your organization's centralized identity management platform:

  • Authorized SSO Callback URI: Register the standard callback endpoint in your IdP console:
    https://cowork.aigenzey.com/auth/sso/callback
  • Zero Password Handling: Corporate credentials are verified directly by your Identity Provider, eliminating the risk of stored passwords.
  • Cryptographic Session Verification: SSO handshakes use signed, expiring state verification to prevent session interception.

Supported Identity Providers

Organization Administrators can configure SSO from Admin Panel → Settings → Single Sign-On:

Identity ProviderRequired Setup FieldsConfiguration Summary
Microsoft Entra ID (Azure AD)Tenant ID, Client ID, Client SecretRegister a Web Application in Microsoft Entra ID with Microsoft Graph User.Read delegated permissions.
Google Workspace SSOClient ID, Client Secret, Allowed DomainsCreate an OAuth 2.0 Web Client in Google Cloud Console and specify your corporate Google Workspace domain.
OktaIssuer URL, Client ID, Client SecretCreate an OIDC Web App Integration in Okta and assign it to your employee groups.
Generic OIDC (Auth0, Ping, OneLogin, Keycloak)Issuer URL, Client ID, Client SecretConnect any standard OpenID Connect 1.0 compliant enterprise authentication server.

JIT Provisioning & Domain Enforcement

Tailor your organization's authentication policy to match your IT security standards:

  • Just-In-Time (JIT) Auto-Provisioning: Automatically provision active accounts for verified corporate employees on their first login, avoiding manual invite backlogs.
  • Default Department & Role Assignment: Pre-assign default roles and department groups so new team members instantly access the playbooks and tools they need.
  • Corporate Domain Whitelisting: Restrict workspace entry exclusively to verified email domain addresses (e.g. acme.com).
  • Mandatory SSO Enforcement: Disable unmanaged password and personal sign-ins for users with corporate email domains once configuration is validated.
  • Pre-Flight Test Verification: Use the built-in Test SSO Configuration feature to safely verify authentication handshakes and claim mappings before enforcing company-wide rules.

Usage Quotas & Budget Governance

To maintain cost predictability and allocate resources fairly across teams, Cowork provides real-time budget controls:

  • Pre-Execution Budget Guardrails: Real-time checks verify organizational allowance before starting tasks, preventing unexpected usage overages.
  • Transparent Usage Tracking: Prompt processing, reasoning, and output metrics are precisely tracked and viewable in the Admin Panel.
  • High Reliability: Critical workflows are safeguarded with resilient failover systems to prevent disruptions during routine operations.

Audit Logging & Observability

Every agent interaction is recorded in a centralized, immutable audit log (Admin Console → Audit Logs):

Audit ParameterDescription
User & Identity ContextUser name, email, department, organization, and timestamp.
Skills & Tools InvokedExact list of playbooks and external tools queried during task execution.
Execution MetricsExecution duration, milestone timeline, and resource usage metrics.
Task OutcomeSuccessful completion status, deliverable types, and sanitized diagnostic summaries.

Enterprise Security & Encryption

Aigenzey Cowork implements robust protection across all data and credentials:

  • Military-Grade Encryption at Rest: All stored OAuth tokens, integration credentials, API secrets, and database access keys are secured with advanced authenticated encryption.
  • Zero Frontend Exposure: Sensitive API keys and secret values never travel to the client browser. Admin consoles display only masked indicators for verification.
  • Cryptographic Request Integrity: Authorization workflows utilize cryptographically signed, timestamped parameters to defend against forgery and unauthorized redirects.

Multi-Tier Agent Safety & Defenses

Because autonomous agents interact with diverse external data (emails, tickets, websites, and file attachments), Cowork incorporates multi-layer safety protections:

  1. Contextual Data Boundaries: External document content and messages are isolated within secure data envelopes, ensuring external text is treated as data rather than executable instructions.
  2. Tool Sandboxing & Action Confirmations: High-impact operations (such as sending external emails, updating CRM records, or publishing content) require explicit user confirmation before final execution.
  3. Autonomous Loop Prevention: The orchestrator actively monitors execution depth, safely stopping tasks if an agent encounters repetitive circular tool patterns.

Data Retention & Privacy Sovereignty

Cowork provides comprehensive data sovereignty and privacy controls:

  • Strict Zero-Training Guarantee: Customer inputs, conversation history, and connected business documents are never used to train public foundation models.
  • Right-to-be-Forgotten: Users and administrators can permanently purge conversations, memory entries, or entire organization accounts at any time.
  • Flexible Deployment Options: Enterprise organizations can deploy Cowork within dedicated cloud environments (Google Cloud, AWS, Azure) to comply with regional data residency and governance requirements.