Trust with clear boundaries

Identity proves who you are. Permissions decide what you can access.

Understand OpsAI MFA, invitation-bound workspace access, protected collector credentials and private report delivery.

Verified sign-in and MFA

Microsoft and Google sign-in use the canonical OpsAI authentication flow. MFA remains required. A provider account or matching email domain does not grant access to an existing workspace. Public acquisition readiness remains subject to provider configuration.

Explicit workspace access

A workspace invitation is bound to its intended identity and role. Customer owners retain control over membership. AOT support access is explicit and audited; commercial partner relationships do not grant operational access by themselves.

Private infrastructure credentials

Monitoring credentials belong in the protected OpsAI setup flow. The marketing website does not collect them. Collectors monitor supported sources with the authorized scope; advisory AI does not change infrastructure.

Private reports and honest retention

Reports require authorized access and are stored privately. Operational detail, hourly history and daily summaries have different retention periods. A year of daily summaries is not a year of raw logs.

Collector distribution

Managed-pilot Windows signing requires explicit customer IT trust. It is not public certificate-authority trust. Branding does not change the legitimate signing publisher, immutable Edge identity or monitoring protocol.