Skip to main content
Telara

Security

Decide what an agentmay see and do.

  • Agent 365 evaluates inside Microsoft.

Identity, scope, and credentials resolve on the call — before the write, in your tenant.

GitHub
Jira
Linear
Slack

GitHub

  • Read repository Allowed
  • Open pull request Approved
  • Force-push main Blocked

Jira

  • Read issue Allowed
  • Create issue Approved
  • Delete project Blocked

Linear

  • List issues Allowed
  • Update status Approved
  • Archive team Blocked

Slack

  • Read channel Allowed
  • Post message Approved
  • Invite guest Blocked
Claude Code
Cursor
Windsurf
OpenAI
Telara Logo
GitHub
Jira
Linear
Slack

tool

Resolve.ai

team

Platform eng

team

On-call

tool

Analyst

user

Maya Chen

tool

SRE bot

team

Security

user

Jordan Lee

tool

Docs agent

Actions gated per integration

Security Model

Discovery. Policy. Record.

The gate in front of the write — architectural, not a vendor-owned record.

Estate discovery

See the agents and clients already in the organisation before you gate them.

Policy at execution

Identity, scope, and short-lived credentials resolve on the tool call — before the write.

Decision record

Each agent has a defined read scope, write scope, and approval gates. Every decision is recorded.

Infrastructure

In practice.

Every call authenticated. Every store isolated.

Credential path

A service can only mint the next hop.

MCP Gateway

tenant identity + role

Knowledge Service

scope: read:index

Indexing Service

scope: read:source

Integration Service

github · create_pr

Token at hop 3

41s left
sub
svc/indexing-service
aud
svc/integration-service
scope
call:github
tenant
t_northwind
cannot mint write:*

Not in the parent scope. A service cannot widen its own grant.

Tenant boundary

Separate storage by design

Schema isolation

Structured Data

Users, metadata, and configuration in a dedicated schema. No shared tables.

Index isolation

Semantic Index

A separate index per tenant. Another org's query cannot reach your content.

Space isolation

Connection Map

Your entity graph in a dedicated space — structural separation, not a query-time filter.

Namespace isolation

Cache & Sessions

Namespaced per tenant. Encrypted at rest. TTLs enforced.

Permissions

Per-agent IAM.

Defined read, write, and approval gates. Enforced at runtime.

AgentRead scopeWrite allowedApproval gated
Incident responderIncidents + linked PRs/tickets/servicesCreate incident comments, update status
Acknowledge + escalate
Code quality agentPRs, commits, issues across reposCreate PR comments, labels
Close issues, approve PRs
Review agentPR diff + code context + similar patternsPost review comments
Approve / request changes
Security agentRepos, dependencies, CVE dataCreate security issues
Merge or close security PRs
IAM agentIAM policies, permissions, access logsFlag policy violations
Modify any permission grants
Onboarding agentAll public org docs + onboarding materialsUpdate onboarding docs
Write to protected spaces

Approval gates require human confirmation. Every action, approved or not, is audited.

Encryption everywhere

AES-256 encryption at rest across all data stores
TLS 1.3 for all data in transit, inter-service and client
Credentials stored as encrypted secrets, never in plaintext
All indexed data encrypted per tenant in isolation
Auth tokens are short-lived, signed, and tenant-scoped

Self-hosted option (roadmap)

Not yet offered. The platform already ships as Helm charts, and customer-cloud delivery on your own GCP, AWS, or on-prem is planned so data stays inside your network. Portable permissions, knowledge, and sessions staying in that deployment is sovereignty.

Helm chart deployment on Kubernetes
All services: Knowledge, Indexing, Agent Runtime, Gateway
Bring your own cloud credentials and API keys
Annual software license with no per-query cost to Telara
Same security architecture as cloud, no shared infrastructure

Observability

Audit & observability

Every action logged. Tamper-evident. Retained to your spec.

Full audit trail for all agent actions and queries
Immutable event log: actor, action, resource, timestamp
Exportable to your SIEM (Datadog, Splunk, CloudWatch)
Approval gate decisions logged with approver identity
Permission violations trigger automatic alerts

Standards

Compliance status

SOC 2 Type II

Controls implemented; audit planned

HIPAA

Planned

GDPR

Processor-aligned

Self-hosted

On the roadmap

Security review and control details available on request.

Book a demo

Telara is invite-only. Talk to us and we will provision your workspace.

Book a demo