Enterprise design-partner program

Control the service. Not your employees’ private notes.

Autopen’s enterprise control plane is designed to govern identity, lifecycle, policy, devices, usage, and investigations without giving ordinary administrators a content-reader permission.

!
Pre-production status: application controls are implemented for review, but managed infrastructure, real-tenant validation, operating evidence, contracts, and independent assurance remain launch gates. This page is not a certification claim.
A truthful control story

Five questions IT should never have to guess at.

Autopen’s enterprise direction starts with the questions procurement, security, privacy, and identity teams actually need answered.

IdentityWho can sign in?

Managed domains, SSO policy, directory lifecycle, roles, and session revocation define access.

DataWhere does content go?

The audio, transcript, notes, metadata, provider, storage, and deletion path is documented explicitly.

PolicyWhat can users do?

Retention, export, sharing, app lock, offline access, and participant notice can be restricted.

EvidenceCan the claims be proven?

Operational, real-tenant, endpoint, deletion, and independent assurance evidence remain required.

Identity and lifecycle

Access follows the organization—not a forgotten password.

Production identity is delegated to WorkOS. The design supports organization SAML or OIDC SSO, verified-domain policy, directory-driven joiner/mover/leaver events, bounded roles, and revocable Autopen sessions.

  • Require organization SSO and prevent managed-domain bypass through social or password login.
  • Provision, suspend, reactivate, and deprovision members through durable directory events.
  • Revoke all Autopen sessions when a member is contained or deprovisioned.
  • Keep provider tokens out of native callback URLs through PKCE and one-time Autopen codes.
01

Workforce identity

SAML/OIDC, MFA and Conditional Access at the IdP, verified domains, and discovery from a work email.

02

Directory source

Signed, replay-windowed, idempotent lifecycle events with durable processing and reconciliation requirements.

03

Autopen authorization

Active membership, Enterprise entitlement, role, tenant ownership, and restrictive policy are rechecked by the API.

Policy and administration

Security controls that do not require content surveillance.

Autopen separates governance metadata from meeting content. Administrators can investigate, contain, and delete without an ordinary route for opening private member transcripts or notes.

Organization policy

Set restrictive defaults

Independent transcript, notes, and Trash retention; export and sharing controls; app lock; offline grace; participant-notice requirement; SSO and MFA intent.

Member lifecycle

Contain access immediately

Suspend or deprovision members, revoke normal sessions, preserve role hierarchy, and guard against removing the final organization owner.

Device inventory

Know what is enrolled

Platform, app version, enrollment, last-seen, and wipe-command status without collecting a stream of meeting activity.

Usage and audit

Investigate without meeting text

Aggregate consumption, append-only security events, CSV export, and signed SIEM projections designed to exclude meeting content.

Remote containment

A wipe request is not called complete until the endpoint says so.

Autopen’s application-level containment path revokes normal sessions immediately and leaves a narrow, device-scoped credential able only to receive and acknowledge its own deletion command.

  • The app removes cached content and destroys its local cache-encryption key before acknowledging.
  • The administrator sees pending, acknowledged, or expired—not a misleading binary “success.”
  • An offline, powered-off, modified, or hostile unmanaged endpoint cannot be represented as erased.
  • Managed-app removal and Intune MDM/MAM selective wipe remain the stronger endpoint controls.
01 · Revoke

Sessions close

Normal access and refresh sessions are invalidated immediately.

02 · Deliver

Command waits

The narrow credential can receive only its own expiring control command.

03 · Delete

Local key destroyed

Content, cache keys, preferences, and normal credentials are removed.

04 · Acknowledge

Status becomes evidence

Only a returned acknowledgement changes the command from pending.

Permission model

Least privilege with a visible privacy boundary.

The final-owner guard and privilege hierarchy prevent lower or equal roles from using a different endpoint to contain a more privileged peer.

CapabilityOwnerAdminSecurity adminMember
View organization, members, devices, and aggregate usageYesYesYesNo
Revoke sessions or suspend a memberYesYesYesNo
Change administrator rolesYesNoNoNo
Change security and data policyYesNoYesNo
Wipe devices or purge member contentYesNoYesNo
Read another member’s private transcript or notesNoNoNoNo
Evaluation status

What exists—and what still has to be proven.

Source implementation is not operating evidence. We make that distinction explicit so a design partner can evaluate the real maturity of each control.

Available for design-partner review

  • Tenant-scoped APIs and authorization tests
  • WorkOS broker and directory lifecycle contract
  • Role, policy, device, purge, and audit surfaces
  • Encrypted client caches and OS-vault sessions
  • Content-free audit and signed SIEM design
  • Fail-closed managed-environment configuration

Required before enterprise customer use

  • Managed production data plane and restore/deletion drills
  • Representative IdP and directory lifecycle evidence
  • Real iOS MDM and Windows Intune containment validation
  • Independent penetration testing and remediation
  • DPA, subprocessors, regions, incident and support programs
  • SOC 2 Type II program and report when earned
Shape the first approvable pilot

Tell us what your control environment requires.

We want design partners to define the IdP, directory, retention, processing-region, MDM/MAM, SIEM, DLP, consent, and assurance requirements before—not after—real meeting data enters a pilot.