Trust

Every step on record.
Nothing changes without a person.

What RoleAxis logs, what it never does on its own, and what it keeps of your data.

What is logged

Every step of every action
Drafted, waiting, approved, rejected, executed, reversed: each change of state is written to a log that is only ever added to. Each entry carries a hash of the one before it in your workspace, so an entry changed or deleted afterwards breaks the chain, and checking the chain finds where.
Who acted
A person signed in with their own account is logged by name. The shared workspace key is logged as the shared key. A reversal recorded by a RoleAxis operator is logged as a RoleAxis operator, with who.
Why
A rejection carries a note saying why, when your policy asks for one (it does by default). A reversal always carries a note.
Changes to your policy
Every change to the workspace policy is logged with who made it, when, and the policy before and after.

What never happens without a person

Nothing is written to your system without approval
An agent reads, checks and drafts. A hold, a transfer or an order is written only after the person your policy names approves it.
Above your threshold, only a signed-in person
An action worth more than the amount your policy sets (USD 2,000 by default) needs a person signed in with their own account. The shared key cannot approve it. An amount that cannot be read in USD counts as above.
Tax, bank and master data are out of reach
Tax rates, journal entries, bank and IBAN details, closed periods and the chart of accounts are never written. Actions of that kind are refused before a draft exists.
An agent held at recommends stays there
Your policy can keep any agent to recommendations only, and no agent can be set above what it is built to do.

Your data, in plain words

What is stored
The encrypted credential for each connector, each drafted finding with the records it points to (bill numbers, amounts, names), and the log. Stock and ledger tables are read when an agent runs, not copied.
Workspaces are separate
Each workspace sees only its own findings, actions and log.
Disconnecting
Ask us and we remove a connector and its credential. Your findings and log stay readable until you ask us to delete the workspace. Self-serve disconnect is not built yet.
The assessment
The free assessment reads nothing from your systems. It uses only what you type into it.

Start with one role.
The assessment is free and takes minutes.

Trust · RoleAxis