Access tied to role and organization
Core separates platform operators, company owners and agents, and customer portal users. Local QA covers cross-tenant denial, session revocation and logout.
PrivDesk treats identity, tenant isolation and human approval as part of the support workflow. The current evidence is from local Core and browser tests.
Review your requirementsThese behaviors have local implementation and selected tests. Production certification, penetration testing and hosted acceptance are later gates.
Core separates platform operators, company owners and agents, and customer portal users. Local QA covers cross-tenant denial, session revocation and logout.
Requests, cases and knowledge have organization access rules. Staff-only notes are excluded from customer portal responses.
Knowledge publication and AI drafts have human review steps. Approved AI text remains unsent until a staff member sends the reply.
Core has organization AI policy, approved knowledge context and audit reads. In the verified local journey, a simulated model proposed text; the agent edited and approved it, then chose whether to send. Wider retrieval quality, citations, abstention and real provider acceptance remain open.
Customer reply still unsent until the agent acts.
Simulated AI response, real Core persistence.The local stack runs Core, PostgreSQL, S3 compatible storage and a separate worker. A hosted pilot still needs TLS, restore proof, monitoring, a continuously running worker and review of the chosen region and provider setup.
See deployment status