Enterprise design-partner program

Govern the service while preserving private meeting content.

Autopen’s enterprise control plane is designed to govern identity, lifecycle, policy, devices, usage, and investigations without giving ordinary administrators permission to read member transcripts or notes. That is a product boundary. On a protected account it is also a cryptographic one: the saved content is encrypted to a key the member's device holds. Where an organization manages the account, the organization may hold a recovery copy of that key, and the member cannot turn it off from the app.

!
Design-partner status: the production service and managed data plane are live, and application controls are implemented for review. Real-tenant acceptance, operating evidence, contracts, independent testing, and assurance remain gates before enterprise customer use. This page is not a certification claim.
Control model

Four questions IT teams need answered.

Autopen’s enterprise direction starts with the information procurement, security, privacy, and identity teams need for a structured evaluation.

IdentityWho can sign in?

Managed domains, SSO policy, directory lifecycle, roles, and session revocation define access.

DataWhere does content go?

The audio, transcript, notes, metadata, provider, storage, and deletion path is documented explicitly.

PolicyWhat can users do?

Retention, export, sharing, app lock, offline access, and participant notice can be restricted.

EvidenceCan the claims be proven?

Operational, real-tenant, endpoint, deletion, and independent assurance evidence remain required.

Identity and lifecycle

Access follows organizational policy and lifecycle.

Production identity is delegated to WorkOS. The design supports organization SAML or OIDC SSO, verified-domain policy, directory-driven joiner/mover/leaver events, bounded roles, and revocable Autopen sessions.

  • Require organization SSO and prevent managed-domain bypass through social or password login.
  • Provision, suspend, reactivate, and deprovision members through durable directory events.
  • Revoke all Autopen sessions when a member is contained or deprovisioned.
  • Keep provider tokens out of native callback URLs through PKCE and one-time Autopen codes.
01

Workforce identity

SAML/OIDC, MFA and Conditional Access at the IdP, verified domains, and discovery from a work email.

02

Directory source

Signed directory events with timestamp checks and duplicate-event handling, with durable processing and reconciliation.

03

Autopen authorization

Active membership, Enterprise entitlement, role, tenant ownership, and restrictive policy are rechecked by the API.

Policy and administration

Security controls that do not require content surveillance.

Autopen separates governance metadata from meeting content. Administrators can investigate, contain, and delete without an ordinary route for opening private member transcripts or notes. On a protected account, the member's saved transcript and notes are encrypted to the member's key.

Organization policy

Set restrictive defaults

Independent transcript, notes, and Trash retention; export and sharing controls; app lock; offline grace; participant-notice requirement; SSO and MFA intent.

Member lifecycle

Contain access immediately

Suspend or deprovision members, revoke normal sessions, preserve role hierarchy, and guard against removing the final organization owner.

Device inventory

Know what is enrolled

Platform, app version, enrollment, last-seen, and wipe-command status without collecting a stream of meeting activity.

Usage and audit

Investigate without meeting text

Aggregate consumption, append-only security events, CSV export, and signed security-event feeds for your SIEM, built to carry no meeting content.

Remote containment

A wipe request remains pending until the endpoint acknowledges completion.

Autopen’s application-level containment path revokes normal sessions immediately and leaves a narrow, device-scoped credential able only to receive and acknowledge its own deletion command.

  • The app removes cached content and destroys its local cache-encryption key before acknowledging.
  • The administrator sees pending, acknowledged, or expired—not a misleading binary “success.”
  • An offline, powered-off, modified, or hostile unmanaged endpoint cannot be represented as erased.
  • Managed-app removal and Intune MDM/MAM selective wipe remain the stronger endpoint controls.
01 · Revoke

Sessions close

Normal access and refresh sessions are invalidated immediately.

02 · Deliver

Command waits

The narrow credential can receive only its own expiring control command.

03 · Delete

Local key destroyed

Content, cache keys, preferences, and normal credentials are removed.

04 · Acknowledge

Status becomes evidence

Only a returned acknowledgement changes the command from pending.

Permission model

Least privilege with a visible privacy boundary.

The final-owner guard and privilege hierarchy prevent lower or equal roles from using a different endpoint to contain a more privileged peer.

CapabilityOwnerAdminSecurity adminMember
View organization, members, devices, and aggregate usageYesYesYesNo
Revoke sessions or suspend a memberYesYesYesNo
Change administrator rolesYesNoNoNo
Change security and data policyYesNoYesNo
Wipe devices or purge member contentYesNoYesNo
Read another member’s private transcript or notesNoNoNoNo
Evaluation status

What exists—and what still has to be proven.

Source implementation is not operating evidence. We make that distinction explicit so a design partner can evaluate the real maturity of each control.

Available for design-partner review

  • Tenant-scoped APIs and authorization tests
  • WorkOS broker and directory lifecycle contract
  • Role, policy, device, purge, and audit surfaces
  • Encrypted client caches and OS-vault sessions
  • Content-free audit and signed SIEM design
  • Fail-closed managed-environment configuration

Required before enterprise customer use

  • Production data-plane operating evidence and restore/deletion drills
  • Representative IdP and directory lifecycle evidence
  • Real iOS MDM and Windows Intune containment validation
  • Independent penetration testing and remediation
  • DPA, subprocessor, region, incident-response, and support commitments
  • SOC 2 Type II program and report when earned
  • Organization policy for protected accounts, including who may hold a recovery copy and how a member is told
Enterprise pilot requirements

Define the controls your environment requires.

Design partners help define the IdP, directory, retention, processing-region, MDM/MAM, SIEM, DLP, consent, procurement, and assurance requirements before real meeting data enters a pilot.