Permission Sets

Added by Justin Sheehan Justin S. May 21, 2026 8:29pm
Column
In progress
Assigned to
Justin Sheehan Justin S.
Notes
  • Justin drafts governance and permission-set scenarios.
  • Arlan / team schedule a follow-up governance meeting.
  • Team decides default posture for admin visibility and chat history.
  • Team defines what data can be retained for memory and what should remain private.
  • Team creates a simple affiliate-facing security and trust summary.
🟣 The Ambassador Way AI - Astra - Daryle.AI: Security and Go-to-market Affiliate Discussion | Jeff Albert, Arlan Friesen, Ben Pascut, Eric Emly, Malina Pascut
Subtasks
Project plan permission sets *APP *APP, Justin Sheehan Justin S. Tue, Jun 2
Justin Sheehan
Justin Sheehan Chief Journey Officer May 21, 2026 8:35pm May 21, 2026 8:35pm
Draft permission-set options
  •  Locked-down “Fort Knox” version. 
  •  Balanced default version. 
  •  More open innovation / testing version. 
Decide who can see chat history
  •  Company admins? 
  •  Ambassador-level super admins? 
  •  Only under safety, legal, or support escalation? 
  •  This was one of the biggest unresolved governance questions. 
Define data retention rules
  •  What gets saved? 
  •  What gets deleted? 
  •  What can users control? 
  •  What can companies configure? 
Decide how content flagging should work
  •  What types of prompts get flagged? 
  •  Who gets notified? 
  •  Should this be required or configurable by company? 
Define company knowledge-base rules
  •  What documents can be uploaded? 
  •  What needs approval first? 
  •  What should be restricted, especially financial, legal, HR, or sensitive documents? 
Clarify company memory vs. model training
  •  Make it simple: Daryle.AI may use approved internal knowledge to improve the private company experience, but it is not training OpenAI, Anthropic, or Gemini models.
  1. Schedule a follow-up governance meeting
  •  Review the security white paper. 
  •  Review permission-set options. 
  •  Decide the default policy posture before rolling out to affiliates.