Human approval by default
ORPA can organize and draft. Customer-facing messages, bookings, invoices, and charges stay under an authorized person’s control.
Security is handled as operating work: use less access, isolate each workspace, verify important events, and keep a person in control.
ORPA can organize and draft. Customer-facing messages, bookings, invoices, and charges stay under an authorized person’s control.
Gmail uses read-only permission. ORPA cannot send, delete, archive, relabel, or mark Gmail messages as read.
OAuth tokens are encrypted before storage. Stripe, Google, database, and AI secrets remain on the server and are not shipped to the browser.
Supabase row-level access rules scope business records to the signed-in workspace. Server-only token vaults do not expose browser access policies.
Stripe webhook signatures are checked before billing or payment records are changed. Sensitive routes also verify the request origin.
Important integration, review, scheduling, and payment events are recorded so the workspace has a trace of what happened.
Connecting a service does not give ORPA unlimited control. Each integration has a specific job and permission level.