Privacy-ready customer service platform with access control and audit trail
Roles with granular permissions, scope by team or inbox and masking of personal data. Audit trail, automatic consent, data subject requests, 2FA, SAML SSO and usage limits. Who did what and when, without slowing down customer service.
- access layers: permissions, scope and fields
- 3
- evidence for every consent recorded
- SHA-256
- usage alerts per metric each month
- 80 · 100%
What the GWhats Security and Governance layer is
Security, governance and privacy (LGPD) bring together the controls that define who enters the customer service platform, what each person sees and does, and how everything is recorded. The Roles & Access module applies RBAC in three layers: granular permissions per area, scope by account, teams or inboxes, and field visibility with Visible, Masked or Hidden rules for name, email, phone, tax ID and address. The final decision happens on the backend, not by hiding buttons.
The Governance & LGPD hub registers the DPO, sends the consent request on first contact through the channel itself, handles data subject requests with JSON export or anonymization, applies central retention and legal holds and keeps the audit trail. The layer is completed by Presentation Mode for demos without sensitive data, 2FA, active sessions, personal token, SAML SSO, usage limits, per-account AI keys, and time zone and language as the account's authority.
Access control, audit and privacy in one place
Operational governance for companies with a DPO, IT and compliance at the table.
Role-based access control (RBAC)
Create roles with granular permissions per area and separate keys for exporting, deleting and auditing. Start from ready-made templates such as DPO, supervisor, finance or outsourced.
Personal data masking
Name, email, phone, tax ID and address can be Visible, Masked or Hidden. The rule applies to API, CSV and real time, and the call button works without revealing the number.
Audit trail
Logins, configuration changes, template applications, agents, inboxes, contact deletions and data subject requests, with configurable retention and filters by period and type.
Governance & LGPD
DPO, automatic inbound consent with SHA-256 evidence, export and anonymization of data subjects, central retention of messages and conversations and legal holds that are never deleted.
Presentation Mode
Blur on avatars, names, phones, emails, messages, media and amounts for demos and recordings. Each agent toggles it with Cmd/Ctrl+Shift+P, and the state persists.
2FA, active sessions and personal token
Two-factor authentication with an app and recovery codes, a list of sessions per device with remote sign-out and an API token that regenerates instantly.
SAML SSO
Sign in through the corporate IdP, such as Okta, Azure AD or Google Workspace, with automatic agent provisioning on first login and MFA at the provider.
Usage and consumption limits
Messages, conversations, contacts, AI requests and AI tokens measured per month, with per-account limits and webhook alerts at 80% and 100%, never blocking messages.
AI keys, time zone and account language
Your own keys for nine AI providers (BYOK) with account-then-global precedence, Maestro health with Test connection, and a single time zone and language as the account's reference.
Permission, scope and field: three layers in one role
Each native role combines read or manage permissions per area, an operational scope (Whole account, Specific teams or Specific inboxes) and per-field visibility rules. A missing permission is a denial, and the final decision always happens on the backend, never only in the interface.
- Scope limits lists, search, counters, bulk actions, export and real-time delivery.
- Masked or hidden fields are locked for editing, including through API and CSV.
- Role template gallery: DPO, supervisor, finance and outsourced service.
Who did what and when, with configurable retention
The native audit trail records logins, configuration changes, template applications, agent and inbox changes, contact deletions and data subject requests. Every governance action creates an event, including changes to Presentation Mode categories and consent grants or refusals.
- Chronological list with actor, action, target and date/time, filterable by period and type.
- Trail retention set in days by the administrator.
- Consent with evidence: technical IDs, normalized token and SHA-256 hash, never the raw text.
2FA, active sessions and SAML SSO
Each user enables two-factor authentication with an authenticator app and recovery codes, reviews sessions by device and location and ends any of them remotely. For the company, SAML SSO moves login to the corporate IdP and provisions the agent on first entry.
- SAML 2.0 with Okta, Azure AD / Entra or Google Workspace; MFA happens at the IdP.
- Automatic provisioning from email, first_name and last_name; the role comes from account governance.
- Regenerable personal API token: the previous one stops working immediately.
Consumption measured monthly, with alerts before the cap
Five metrics per account and calendar month: messages, conversations, contacts, AI requests and AI tokens. The operator sets limits per metric and the platform alerts by webhook when crossing 80% and 100%, once per metric per month, without ever blocking the message flow.
- Totals available to the account, to the operator and through the API.
- Per-account AI keys (BYOK) for OpenAI, Anthropic, Google, Groq, xAI, DeepSeek, OpenRouter, Cohere and ElevenLabs.
- Fault-tolerant metering: informational alerts, no automatic blocking.
How it works
- 1
Control who gets in
Enable SAML SSO or require 2FA, review active sessions and treat API tokens as passwords.
- 2
Define what each person sees and does
Create roles from templates, restrict the scope to teams or inboxes and mask personal data per field.
- 3
Meet privacy obligations daily
Register the DPO, turn on automatic consent, configure retention and handle data subject requests.
- 4
Audit, demo and measure
Check the audit trail, use Presentation Mode in demos and track usage and limits.