Security approach
Client work stays with the client it belongs to.
Agencies hold other businesses' brands, accounts, and unpublished work. Agency OS is designed so access follows the agency, the client, the role, and the stage of the work, and so the important decisions are made by people and kept on record.
On this page
- Eight security principles
- How client review access works
- How this website handles your data
Status labels show where each capability stands today.
Security principles
- 01
Tenant-aware access
Each agency's data is separated from every other agency's. Requests are checked against the agency they belong to.
- 02
Role-based permissions
Team members act within their role. Owners, managers, and production staff see and do different things.
Available - 03
Client-scoped review
A client reviewer sees only the batches and items shared with that client. Nothing from another client is reachable.
Beta - 04
Private asset storage
Uploaded work is private by default and is not published to the open web.
- 05
Approval gates
Paid, publishing, and send actions require a person to approve them first. Campaigns deploy paused.
Available - 06
Audit history
Review decisions, versions, and annotations are kept as an operational record of who did what and when.
Beta - 07
Usage controls
Expensive AI actions show a cost estimate before they run. Usage tracking and budgets are in private pilot.
Private Pilot - 08
Credential separation
Connections to ad platforms and other services are held server-side, separate from anything a client or browser can see.
Agency OS Review
How client review access works
- Clients sign in to a review workspace in your agency's brand.
- They see only what was shared with them, item by item.
- Reviewed versions are locked; approvals are tied to the exact version.
- Website previews can be shared with expiring signed links.
About this website
This marketing site is deployed separately from the Agency OS application. It does not connect to the application or its database. Form submissions are validated server-side, protected against spam, and forwarded to our team.
Need security documentation for a vendor review? Ask during your walkthrough and we will share what applies to your setup.
Book a Product Walkthrough