Skip to content

Operations

Access and retention

Manage permissions, connection keys, and evidence availability.

Workspace and project permissions determine who can view evidence and manage deployments. A model-traffic key does not grant administration access. Keep the selected workspace and project visible when reviewing a run, changing configuration, or preparing data.

Workspace access#

ActionBoundary to check
View a run or source recordAuthorized workspace/project scope and retained evidence availability.
Grade or curate evidenceThe additional curation permission required by the operation.
Change deployment configurationManagement permission and an explicit governing revision.
Activate or roll back a supported versionAvailable lifecycle capability, authorized actor, and the recorded version transition.

Access to a run does not automatically authorize key rotation, configuration changes, or model lifecycle operations. The platform checks the required capability for each action.

Connection and keys#

Use the existing deployment's connection instructions and available key controls. Revocation or disabled admission holds further work. A credential change must not silently change the workspace, provider, or session being used.

Manage the platform key and provider credential independently. Saved workspace provider connections support their own workflows; they do not automatically populate model gateway requests. See Bring your own key and Connect a deployment.

Evidence retention#

The session integration retains supported request, proposal, and review evidence. Runs and Data apply selected-field redaction to their permitted projections. General dashboard content settings should not be assumed to disable capture for this connection or to remove its encrypted originals.

Expired, deleted, or no-longer-authorized evidence can become unavailable for inspection, grading, or export. Platform expiry does not establish immediate deletion from every downstream system. Keep the source identity and the reason evidence is unavailable distinct from the review outcome.

Read Security and evidence for storage and sanitization boundaries, and Versions and adaptation before preparing evidence for a supported training workflow.