Least-privilege by default
The co-worker only ever holds the data scopes the workflow needs. We don't ask for "broad access" and narrow later. We ask for the minimum and expand only with explicit approval.
In 2—4 weeks we ship a working co-worker for one real business workflow – your data, your tools, human approval.
See the engagementYour data does not need to move to Riyalabs. We map the workflow, identify the minimum context, and choose the deployment model that fits your risk level.
Read the security briefCohort-style learning labs for marketing, finance, ops, and exec teams. Hands-on with real workflows, not slides.
See the curriculumThe questions your CISO will ask – and the answers we already have.
For sensitive workflows we recommend Model C – customer-hosted. The co-worker runs in your environment. Your data does not need to move to Riyalabs.
Everything that touches sensitive data stays in your environment, behind your firewall, under your identity provider, with your retention policy.
Riyalabs is your implementation and operations partner. We help configure, ship, and review – we don't host your data.
Access is composed of three layers – and we design every co-worker against all three from day one.
The co-worker only ever holds the data scopes the workflow needs. We don't ask for "broad access" and narrow later. We ask for the minimum and expand only with explicit approval.
RBAC roles for viewer, reviewer, approver, and admin are explicit and owned by a named human on your side. SSO and your identity provider drive the membership – not us.
One token per source, scoped to the minimum required. Read-only by default. Write actions are a separate scope and always run through an approval gate before they fire.
If a co-worker behaves badly, you should not need to call us first. Owner-controlled, in your environment, documented before launch.
A single owner-controlled toggle stops the co-worker immediately. No support ticket. No waiting. The co-worker stops reading, stops drafting, stops sending.
Prompts, tools, and data scopes are versioned. Roll back to any previous version with one action. Any earlier outputs are still traceable to the exact version that produced them.
Every action, every prompt, every approval, every send – recorded with the user, the timestamp, and the scope used. The log is yours, in your environment.
The leakage questions are real. Here are the three lines we won't cross.
Your prompts, outputs, and data are not used to train a shared model. Period. Where third-party model APIs are used, we configure them with the no-training option enabled.
Your co-worker does not share memory or context with another customer's co-worker. Each engagement runs against an isolated configuration, in your tenant.
Every data access – what source, what fields, when – is logged at response time. If you ask "did the co-worker read this record on this date," the audit log answers it.
Drawn from real CISO and security architect conversations during procurement. Open any one for the answer.
We'll walk through the data-flow diagram, the kill-switch path, and the audit log for your candidate workflow – before any code gets written.