You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
QuickVoice already has organizations, configurable roles/permissions, API keys, audit records, secret references, URL safety, redaction, recording controls, zero-PII behavior, and retention jobs. Enterprise adoption additionally requires separation of environments and duties, centralized identity lifecycle, evidence-grade policy enforcement, data-subject workflows, regional/deployment controls, and tested recovery objectives.
Outcome
Enterprise administrators can provision users and service identities, constrain who may build/test/deploy/operate, enforce privacy and tool policies, export security evidence, fulfill data obligations, and operate a documented deployment profile without relying on informal process.
Required capabilities
Projects and development/staging/production environments with scoped resources, permissions, promotion, and separation of duties.
Fine-grained RBAC, groups, custom roles, service accounts, approval policies, break-glass access, and periodic access review.
Permission checks are centralized, deny by default, organization/environment scoped, and tested for UI, API, realtime, worker, MCP, and background-job paths.
Promotion and high-risk policy changes can require a second authorized approver and always produce immutable evidence.
SCIM deprovisioning revokes active sessions and service access within a documented interval.
Zero-PII, retention, hold, export, and deletion rules have explicit precedence and cover analytics, evaluations, traces, exports, recordings, transcripts, tool payloads, and backups.
Secret plaintext never appears in normal API responses, logs, audits, exports, or blueprints.
Backup restore and failover procedures are exercised automatically where possible and through documented drills otherwise.
Threat-model, authz, identity lifecycle, audit completeness, privacy workflow, encryption, guardrail bypass, recovery, and migration tests are included.
Boundary
These are technical controls and evidence surfaces. Issues and documentation must not claim HIPAA, SOC 2, PCI, GDPR, or other certification/compliance status without independent verified evidence and applicable agreements.
Parent roadmap: #76
Problem
QuickVoice already has organizations, configurable roles/permissions, API keys, audit records, secret references, URL safety, redaction, recording controls, zero-PII behavior, and retention jobs. Enterprise adoption additionally requires separation of environments and duties, centralized identity lifecycle, evidence-grade policy enforcement, data-subject workflows, regional/deployment controls, and tested recovery objectives.
Outcome
Enterprise administrators can provision users and service identities, constrain who may build/test/deploy/operate, enforce privacy and tool policies, export security evidence, fulfill data obligations, and operate a documented deployment profile without relying on informal process.
Required capabilities
Child issues
Acceptance criteria
Boundary
These are technical controls and evidence surfaces. Issues and documentation must not claim HIPAA, SOC 2, PCI, GDPR, or other certification/compliance status without independent verified evidence and applicable agreements.