Docs/Security & governance

Permissions & data access

Access is scoped to the account that owns the Workspace.

Workspace ownership

The signed-in account that creates a Workspace can view its sources, questions, Runs and history. Requests for a Workspace or a source owned by another account are rejected.

Member invitations, team roles and shared Workspace permissions are not implemented. The website’s hosting audience is separate from access to a Workspace’s data.

Saved information

PatternLab stores Workspace names, instructions, source text snapshots, uploaded files, connection timestamps and execution history. Uploading a replacement keeps older source versions available for historical evidence.

This release does not provide a Workspace deletion or retention control. Do not assume a particular retention period, data residency guarantee or compliance certification from the product UI.

External source access

API and MCP connections support public HTTPS endpoints only. PatternLab does not save external application credentials or execute MCP tools. Downloading a saved source requires its owning account to be signed in.

History and auditability

History shows recent Workspace events and saved results. It is useful for reviewing what happened, but it is not an immutable enterprise audit log.