Skip to main content

Privacy & Governance

The Personal Assistant operates in a unique position - it is a tenant resource provisioned and funded by the organization, but it serves an individual employee with potentially sensitive personal data. This guide covers the privacy model, admin governance controls, the settings control model, pause/resume mechanics, and deactivation procedures.

Privacy Policy

The PA privacy policy is configured at the tenant level by an administrator. It applies uniformly to all Personal Assistants in the organization and controls what administrators can see about employee PA activity.

Privacy Levels

Private - Employee Privacy First

Admin Can SeeAdmin Cannot See
PA exists (yes/no)Goals, projects, and tasks
PA status (active, paused, deactivated)Chat conversations
PA nameActivity log details
Activation dateEmail content
Custom instructions
Employee profile data
Tool usage details
Insights and analytics

Best for: Organizations that prioritize employee autonomy and trust. The admin retains lifecycle control (pause, resume, deactivate) but cannot view any PA content.

Metadata Only - Balanced Approach (Default)

Includes everything visible under Private, plus:

Admin Can SeeAdmin Cannot See
Total execution countGoal descriptions and details
Total token usage and costProject and task descriptions
Tool usage statistics (which tools, how often)Chat message content
Goal count and titles (not descriptions)Email content
Task count and completion rateCustom instructions
Last active timestampEmployee profile answers
Wake-up frequency settingResearch outputs
Data access permissions granted

Best for: Organizations that need cost visibility and usage monitoring while preserving employee privacy on content.

Full Visibility - Full Transparency

Includes everything visible under Metadata Only, plus:

Admin Can SeeStill Not Visible
Full goal details (titles and descriptions)Email content in the employee's primary mailbox (Graph API access is user-scoped)
Project and task detailsEmployee's personal device data
Activity log with full details
Chat conversation history
Custom instructions
Employee profile data
Insights analytics

Best for: Regulated industries, high-security environments, or organizations where administrative oversight is expected or required.

Configuring the Privacy Policy

Administrators can set the privacy policy from the PA privacy configuration area in Control Bridge:

  1. Navigate to the PA configuration section
  2. Select the desired privacy level (Private, Metadata Only, or Full Visibility)
  3. Click Save Changes
warning

Changing the privacy policy takes effect immediately for all PAs in your organization. All PA users in the tenant receive an in-app notification informing them of the policy change and the new level. Consider communicating the reasons for any changes to your team proactively.

Settings Control Model

The PA uses a boundary-based control model where administrators set constraints and employees work within them:

Admin-Controlled Settings (Boundaries)

SettingAdmin ControlsEmployee Can Adjust Within Boundaries
Working HoursAdmin sets the allowed time rangeEmployee sets wake-up frequency within those hours
Daily Execution LimitAdmin sets the maximumEmployee cannot exceed it
Available ToolsAdmin defines the approved poolEmployee selects from the pool
Available ModelsAdmin defines the approved modelsEmployee selects their preferred model from the pool
Escalation BehaviorAdmin sets the defaultEmployee can adjust within the admin's allowed options

Employee-Only Settings

These settings are controlled exclusively by the employee. Administrators cannot change them, even with Full Visibility:

  • PA name, avatar, and communication style
  • Custom instructions
  • Data access permissions (primary mailbox, calendar, contacts, files, meetings)
  • Goals, projects, and tasks
  • Wake-up frequency and weekend work preferences
  • Summary frequency and delivery channel

Admin Governance Controls

What Administrators Can Always Do

Regardless of the privacy policy, administrators retain full lifecycle control:

ActionEffectEmployee Notified
Pause PAPA stops all execution immediatelyYes
Resume PAPA resumes execution and calculates next wake-upYes
Deactivate PAPA agent soft-deleted; requires full re-setup to reactivateYes
Add tools to available poolEmployee can assign these new toolsYes
Remove tools from available poolTool removed from PA if employee had assigned itYes
Add LLM modelsEmployee can select these new modelsYes
Remove LLM modelsModel removed if currently selected by employeeYes
Change working hoursPA respects new hours on next cycleYes
Change daily execution limitNew limit enforced immediatelyYes
Change privacy policyApplies to all PAs immediatelyYes (all PA users notified)
Remove PA User rolePA deactivated and role removedYes

What Administrators Cannot Do

Even with the Full Visibility privacy policy, administrators cannot:

  • Send messages as the PA
  • Modify the employee's goals, projects, or tasks
  • Change the employee's personalization settings (name, avatar, style, instructions)
  • Change the employee's data access permissions (primary mailbox, calendar, contacts, files)
  • Access the employee's primary mailbox through the PA
  • Impersonate the employee in PA interactions

Admin PA Management Page

Administrators can manage an employee's PA from Manage > Team > Users > select the user > PA Settings tab. This page shows:

  • PA status with Pause and Deactivate buttons
  • PA name, email, activation date, and last active timestamp
  • Usage metrics (visible at Metadata Only and Full Visibility policy levels): execution count, token usage, and estimated cost
  • Available tools and models configuration (with edit capability)
  • Working hours, daily execution limit, and escalation behavior settings

Pause and Resume

Who Can Pause and Resume

ActorPauseResume
EmployeeCan pause their own PACan resume their own PA (unless admin-paused)
AdministratorCan pause any employee's PACan resume any PA (including employee-paused)
Important Rule

If a PA is paused by an administrator, the employee cannot resume it. The employee sees: "Paused by your administrator. Contact them to resume." Only the administrator can resume an admin-paused PA.

Pause State Model

The PA uses a single status field with a last-write-wins model. This means:

  • If the employee pauses and then the admin also pauses, the status becomes paused_by_admin
  • When the admin resumes, the PA goes back to active regardless of the employee's prior pause
  • The employee can re-pause if desired after the admin resumes

This approach keeps the state model simple and avoids compound pause states.

What Happens When Paused

When a PA is paused, regardless of who initiated the pause:

  1. Scheduled wake-ups stop - The timer skips this PA
  2. Email triggers stop - Incoming emails to the PA's shared mailbox are not processed
  3. Chat is disabled - The employee sees "Your PA is currently paused" in the chat interface
  4. PA Hub becomes read-only - The employee can view history but cannot trigger actions
  5. "Wake Up Now" button is disabled - Shows the paused state
  6. Goals, projects, and tasks are preserved - No data is lost
  7. Next wake-up is cleared - The scheduled next wake-up time is removed

What Happens When Resumed

When a PA is resumed:

  1. The next wake-up time is calculated based on the current time and frequency
  2. Email triggers are re-enabled
  3. Chat becomes available again
  4. The PA Hub is fully interactive
  5. A "PA resumed" activity entry is logged

Providing a Reason

Both employees and administrators can optionally provide a reason when pausing. The reason is logged in the activity trail for audit purposes.

Deactivation

Admin Deactivation

Administrators can deactivate an employee's PA from Manage > Team > Users > select the user > PA Settings tab.

A confirmation dialog is displayed: "Are you sure you want to deactivate this employee's Personal Assistant? This will stop all PA activity and the employee will need to re-complete setup to reactivate."

Deactivation triggers the following:

  1. PA status is set to deactivated
  2. The PA agent is soft-deleted
  3. The email subscription (Graph API webhook) is removed
  4. The employee receives an in-app notification and email explaining the deactivation
  5. The action is logged in the audit trail
warning

Deactivation is a significant action. The employee will lose access to their PA and will need to go through the full two-phase setup process (admin + employee) to get a new PA. Previous goals, projects, tasks, and chat history are preserved but linked to the old agent and not migrated to the new PA.

Employee Deactivation Request

Employees cannot directly deactivate their PA. Instead, they can:

  1. Navigate to PA Hub > Settings > Danger Zone
  2. Click Request Deactivation
  3. This sends a notification to the administrator
  4. The administrator must approve and perform the deactivation

Re-Provisioning After Deactivation

To re-provision a PA after deactivation:

  1. The administrator must complete the Admin Setup Wizard again
  2. The employee must complete the Employee Setup Wizard again
  3. A new PA agent is created with fresh configuration
  4. Previous data (goals, projects, tasks, chat history) is preserved but linked to the old agent and not carried over

Role Removal

If an administrator removes the PA User role from an employee:

  1. If the PA is active, it is deactivated first (following the deactivation flow above)
  2. The role is removed from the user
  3. The employee loses access to the PA Hub
  4. PA data is preserved in the database for audit purposes
  5. The employee receives a notification

Audit Trail

All governance actions are logged automatically to the activity log:

Activity TypeDescription
admin_pauseAdministrator paused the PA
admin_resumeAdministrator resumed the PA
admin_deactivateAdministrator deactivated the PA
admin_tool_changeAdministrator modified available tools
admin_model_changeAdministrator modified available models
admin_settings_changeAdministrator modified settings (hours, limits, escalation)
employee_pauseEmployee paused their PA
employee_resumeEmployee resumed their PA
employee_tool_changeEmployee changed tool assignments
employee_config_changeEmployee changed personalization or settings

Data Retention

  • PA data follows the same retention policies as other Outermind Inc. data
  • When an employee leaves the organization (user deleted), PA data follows the GDPR deletion flow
  • Deactivated PA data is retained until the user record is deleted
  • Activity logs follow the standard audit log retention policy