Runtime: user-controlled · Data status: source-dependentCopy · Run · Configure · Review
Warmly data provenance and runtime control ledger

Security & Data

Warmly operational trust begins with inspectable data behavior

Document where account evidence came from, when it was observed, which credential exposed it, where the result traveled, and who approved its use.

A populated CRM field is not self-validating. Warmly research should preserve provenance, freshness, confidence, correction, suppression, retention, and deletion decisions beside the value.

Three control objectives

01

Trace every material claim

Retain source context and observation date. Mark provider classifications, estimates, and team inference distinctly from reported facts.

02

Limit every credential

Store API keys outside prompts and repositories. Use test credentials, minimum scopes, named owners, rotation, and revocation paths.

03

Review every destination

Define CRM write permissions, logs, exports, temporary files, correction, suppression, access, retention, and deletion before production.

Readiness gates, not decorative percentages

Data provenance

Required

Pass when a reviewer can identify the source role, observation date, transformation, and unresolved conflict for every decision-critical field.

Credential handling

Required

Pass when secrets are scoped, externalized, tested, revocable, and absent from prompts, exports, repositories, screenshots, and shared logs.

Review and deletion

Required

Pass when a named reviewer controls downstream use and operators can correct, suppress, retain, or delete results according to policy.

Evidence to keep with the run

Package review

Version, runtime, requested permissions, network destinations, errors, retry behavior, update path, and uninstall steps.

Data method

Connected provider, requested fields, fallback order, timestamps, identity rules, unknown states, and correction path.

Approval record

Account rationale, role relevance, human reviewer, suppression check, applicable regional requirements, and downstream decision.

No SOC 2, ISO, GDPR, coverage, accuracy, or refresh certification is asserted here. Confirm current provider and package documentation before relying on a control.

Inspect before you connect

Run the first task in a test environment with a known cohort, minimum-scope credentials, and a written acceptance log.

npx -y @okki-global/okki-go-taroball