Trust & Security
Autonomy you can audit.
Volobox treats agents like employees: they have an identity, permissions, a manager, and limits. Trust is engineered into the platform, not promised in a policy document.
The model
Three modes of agent authorization
Pick per agent, per situation: from fully supervised to independent within explicit boundaries.
User-delegated
The agent acts strictly as an extension of the person who asked, with their permissions. Every write produces an approval card that person must accept. The default, and mandatory for personal assistants.
Manager-escalated
The requester's permissions are tried first. When they are not enough, the agent's designated manager approves, or a standing rule the manager owns pre-approves it within a budget.
Self-authorized
The agent is a first-class principal with its own memberships in projects, spaces, and drives. Inside that boundary it works without approval cards (like an employee) under mandatory rate limits.
Approvals
Every write asks, until you decide it doesn't have to
In Agent mode, write actions become proposal cards: see exactly what will happen, approve or reject, and get a deep link to what was created. Ask mode is fully read-only: write tools are simply not available.
- Standing auto-approval rules with per-hour, per-day, or lifetime budgets
- Manager escalations and agent questions arrive in your Inbox
- Agent-wide safety limits cap writes per run and per hour (hard-enforced)
Transparency
See everything, after and during
Live execution
Watch coding sessions in real time: terminal, diffs, plans, questions, per-turn cost.
Run traces
Every agent run keeps a trace of tool, MCP, and sandbox calls.
Audit log
Authorization decisions and security events, exportable as CSV/JSONL or pulled into your SIEM over the API.
Cost visibility
Usage and cost per model and per conversation in admin settings.
Activity history
Agent actions appear in the same feeds as human actions, attributed to the agent.
Personal-data gates
Shared agents cannot reach personal data; separate gates guard personal tools.
Isolation & data control
Your data stays yours
Sandbox isolation
Agent code execution happens in isolated VMs with budgets, idle pause, and destroy controls.
Scoped secrets
Encrypted secret scopes; tokens never travel inside packs or exports.
Deployment freedom
Cloud or on-premise. Bring Claude, GPT, Gemini, Kimi, or an open-source model you host. Workspace knowledge indexing runs inside your deployment.
Enterprise security
For your security review
Engineered in today: role- and permission-based access control, OpenID Connect authentication, an exportable audit log with API access for your SIEM, encrypted secrets, isolated execution, and on-premise deployment.
Evaluating Volobox? Talk to us about SSO, data residency, network isolation, and our compliance roadmap. We'll walk through the architecture with your security team.
Bring your security team to the demo.
The governance model is best shown live: approval cards, limits, and audit included.