Managed domains, SSO policy, directory lifecycle, roles, and session revocation define access.
Control the service. Not your employees’ private notes.
Autopen’s enterprise control plane is designed to govern identity, lifecycle, policy, devices, usage, and investigations without giving ordinary administrators a content-reader permission.
Five questions IT should never have to guess at.
Autopen’s enterprise direction starts with the questions procurement, security, privacy, and identity teams actually need answered.
The audio, transcript, notes, metadata, provider, storage, and deletion path is documented explicitly.
Retention, export, sharing, app lock, offline access, and participant notice can be restricted.
Operational, real-tenant, endpoint, deletion, and independent assurance evidence remain required.
Access follows the organization—not a forgotten password.
Production identity is delegated to WorkOS. The design supports organization SAML or OIDC SSO, verified-domain policy, directory-driven joiner/mover/leaver events, bounded roles, and revocable Autopen sessions.
- Require organization SSO and prevent managed-domain bypass through social or password login.
- Provision, suspend, reactivate, and deprovision members through durable directory events.
- Revoke all Autopen sessions when a member is contained or deprovisioned.
- Keep provider tokens out of native callback URLs through PKCE and one-time Autopen codes.
Workforce identity
SAML/OIDC, MFA and Conditional Access at the IdP, verified domains, and discovery from a work email.
Directory source
Signed, replay-windowed, idempotent lifecycle events with durable processing and reconciliation requirements.
Autopen authorization
Active membership, Enterprise entitlement, role, tenant ownership, and restrictive policy are rechecked by the API.
Security controls that do not require content surveillance.
Autopen separates governance metadata from meeting content. Administrators can investigate, contain, and delete without an ordinary route for opening private member transcripts or notes.
Set restrictive defaults
Independent transcript, notes, and Trash retention; export and sharing controls; app lock; offline grace; participant-notice requirement; SSO and MFA intent.
Contain access immediately
Suspend or deprovision members, revoke normal sessions, preserve role hierarchy, and guard against removing the final organization owner.
Know what is enrolled
Platform, app version, enrollment, last-seen, and wipe-command status without collecting a stream of meeting activity.
Investigate without meeting text
Aggregate consumption, append-only security events, CSV export, and signed SIEM projections designed to exclude meeting content.
A wipe request is not called complete until the endpoint says so.
Autopen’s application-level containment path revokes normal sessions immediately and leaves a narrow, device-scoped credential able only to receive and acknowledge its own deletion command.
- The app removes cached content and destroys its local cache-encryption key before acknowledging.
- The administrator sees pending, acknowledged, or expired—not a misleading binary “success.”
- An offline, powered-off, modified, or hostile unmanaged endpoint cannot be represented as erased.
- Managed-app removal and Intune MDM/MAM selective wipe remain the stronger endpoint controls.
Sessions close
Normal access and refresh sessions are invalidated immediately.
Command waits
The narrow credential can receive only its own expiring control command.
Local key destroyed
Content, cache keys, preferences, and normal credentials are removed.
Status becomes evidence
Only a returned acknowledgement changes the command from pending.
Least privilege with a visible privacy boundary.
The final-owner guard and privilege hierarchy prevent lower or equal roles from using a different endpoint to contain a more privileged peer.
| Capability | Owner | Admin | Security admin | Member |
|---|---|---|---|---|
| View organization, members, devices, and aggregate usage | Yes | Yes | Yes | No |
| Revoke sessions or suspend a member | Yes | Yes | Yes | No |
| Change administrator roles | Yes | No | No | No |
| Change security and data policy | Yes | No | Yes | No |
| Wipe devices or purge member content | Yes | No | Yes | No |
| Read another member’s private transcript or notes | No | No | No | No |
What exists—and what still has to be proven.
Source implementation is not operating evidence. We make that distinction explicit so a design partner can evaluate the real maturity of each control.
Available for design-partner review
- Tenant-scoped APIs and authorization tests
- WorkOS broker and directory lifecycle contract
- Role, policy, device, purge, and audit surfaces
- Encrypted client caches and OS-vault sessions
- Content-free audit and signed SIEM design
- Fail-closed managed-environment configuration
Required before enterprise customer use
- Managed production data plane and restore/deletion drills
- Representative IdP and directory lifecycle evidence
- Real iOS MDM and Windows Intune containment validation
- Independent penetration testing and remediation
- DPA, subprocessors, regions, incident and support programs
- SOC 2 Type II program and report when earned
Tell us what your control environment requires.
We want design partners to define the IdP, directory, retention, processing-region, MDM/MAM, SIEM, DLP, consent, and assurance requirements before—not after—real meeting data enters a pilot.