Privacy and encryption

Privacy and encryption

Understand what Agent Approve receives and how your selected setup mode affects access to event content.

Agent Approve receives the information needed to show supported agent activity and make policy or approval decisions. The exact content depends on the integration, event type, mode, and encryption settings you choose.

  • Privacy levels control how much command detail remains in event history.
  • Data Retention controls how long you keep that history available in the app.
  • Encryption keys explains end-to-end encryption, rotation, Key Retention, and missing-key recovery.

Approval content and history

Approval Mode needs enough command or tool information to evaluate your active policy. When end-to-end encryption is enabled, your computer creates a service-encrypted approval copy and a separate device-encrypted copy. The service opens the approval copy to evaluate policy. It cannot use that same copy as your readable event history.

The device-encrypted copy used for event history follows your selected Privacy Level. Other supported activity content is also encrypted for your devices when end-to-end encryption is enabled.

Some metadata remains available so Agent Approve can route a request and show when an agent, event, or decision occurred. End-to-end encryption does not mean that every field is hidden or that policy can be evaluated without processing approval content.

See Encryption keys for key handling and Privacy levels for the difference between tool name, summary, and full-content history.

Do not paste secrets into support messages. When troubleshooting, remove tokens, keys, full device identifiers, private repository paths, command output, and customer data unless Support asks for a specific redacted field.

Go out and grab a coffee

We'll ping you if your agents need you. Try Agent Approve free for 7 days.