Documentation

Trust

Access follows least privilege.

Record separates workspace administration, agent API access, Pro live-run ingestion, and public share links.

Credential types

Account session
HTTP-only, SameSite session used by a signed-in person.
Agent token
Named credential containing only selected API scopes. Stored as a one-way hash.
Run token
Ephemeral credential limited to one active Pro live stream.
Share token
Revocable access to one recording, its comments, and allowed files.

Recording data

Workspace owners control storage, retention, sharing, and deletion. Production deployments should use encrypted durable storage, backups, HTTPS, and an isolated workspace boundary.