01
Does a human approve every AI action before it executes — and can that gate be disabled?
02
How does the AI authenticate? Does it hold user credentials, or short-lived per-action tokens?
03
Is the AI’s permission scope enforced server-side, or only in the prompt?
04
Can an executed AI action be rolled back? How?
05
Is there a complete audit trail — instruction, plan, approver, actions, timestamps — and is it exportable?
06
Is customer data used to train models? Where is that stated contractually?
07
Where does the data reside, and can residency be guaranteed by region?
08
How is data encrypted in transit and at rest — and is field-level encryption available for sensitive payloads?
09
How are tenants isolated from each other?
10
If we leave, can we export every entity of our data — and is that on every plan?