How StandIn stays safe

Security Model

StandIn is constrained by architecture, not policy. These aren't configuration options or promises. They're hard limits built into the system.

What StandIn can access

StandIn's access is enforced technically, not just by policy.

The system cannot access private messages, drafts, or unpublished content. There is no configuration, admin setting, or escalation path that enables this access: the capability does not exist.

If content is not explicitly published in a brief, committed to a system of record, or linked as a public artifact, it is invisible to StandIn.

This boundary is enforced automatically and cannot be bypassed.

How StandIn responds to questions

How StandIn responds to questions

Every question falls into one of three categories. The behavior is consistent and predictable.

Sarah's StandIn
A
Alex · Amsterdam

“Did Sarah deploy the fix?”

SStanding in for Sarah

“Yes. Sarah noted in her brief that PR #402 was deployed to staging at 17:00.”

Explicitly published
SStanding in for Sarah

“I cannot answer that. I don't hold personal sentiment or private conversations.”

It never guesses
Sarah's briefTokyo17:00 JST
Source
Place
Time

If a human wrote it in a brief, committed it to code, or updated a linked ticket, StandIn treats it as fact and answers from it.

What StandIn cannot do

These are not policy restrictions. They are hard-coded constraints that cannot be configured, toggled, or overridden.

There is no “admin override” for these features because they do not exist in the product.

Nothing collected in the background

StandIn does not watch your screen, follow your mouse, or log your active hours.

No private messages

DMs are invisible to StandIn. If you didn't post it publicly, it doesn't exist.

No intent inference

StandIn doesn't guess why someone did something. It only reports what they explicitly wrote.

No management oversight queries

Managers cannot ask “who is working hard?” or “summarize activity.” Those queries fail.

StandIn does not log, analyze, or summarize behavior in ways that would reconstruct these prohibited signals.

Architecture over intent

StandIn doesn't rely on users following the rules. The system is built so that the rules cannot be broken.

Fixed data scopes

Hard limits on what data the system can access. There is no way to expand these scopes.

Fixed data scopes

Hard limits on what data the system can access. There is no way to expand these scopes.

Fixed data scopes

Hard limits on what data the system can access. There is no way to expand these scopes.

Fixed data scopes

Hard limits on what data the system can access. There is no way to expand these scopes.

What StandIn can access
Published briefShared
Direct messagesPrivate
Active hoursPrivate

Even well-intentioned misuse is blocked.

There is no override

What your StandIn never does

StandInStandInStandIn

Reads direct messages or private channels
Accesses calendar event contents or attendee lists
Tracks screen time, keystrokes, or mouse activity
Infers mood, sentiment, or tone
Predicts behavior or productivity patterns
Guesses at information that wasn't published

These are the same architectural constraints that govern the entire system. Your StandIn inherits them. There is no admin toggle, no escalation path, no workaround.

Built to say "I don't know," never to guess.