Security, permissions, and data boundaries
Understand workspace isolation, sensitive information, AI authorization, and high-risk action controls.
Updated 2026-08-01
YundaDesk isolates customers, conversations, knowledge, skills, memory, and channel configuration by workspace. Member roles further restrict what each person can view or perform.
Protect credentials#
Channel tokens, API keys, mailbox passwords, and store secrets must be submitted only through secure configuration fields in the product. Never place them in knowledge, Yuna conversations, customer messages, screenshots, or shared documents.
AI authorization#
- AI can use only capabilities registered and ready for the current workspace.
- Customer data and actions remain subject to the current member's permissions.
- Refunds, price changes, and outbound messages require confirmation or approval.
- The capability center shows availability; permissions and confirmation requirements still apply.
- When required business information, memory, or a connected feature is unavailable, the AI should explain the limitation rather than invent success.
Knowledge and memory#
Use knowledge for business facts, AI skills for reusable procedures, customer memory for one customer's context, and Yuna memory for merchant-team preferences. Memory must not bypass knowledge review or hold unnecessary sensitive content.
Member security#
Use individual accounts, assign least privilege, review login records, and revoke access promptly when a member leaves.
Data requests#
Use the product's governed process for customer export, correction, and deletion requests, and follow applicable law.