Desktop app
The user-facing client and local execution boundary available today.
Govern · For CISOs and security teams
Give people purpose-built AI workflows inside one governed environment. Approve the models, extensions, capabilities, and services they can use—and trace where organizational data is allowed to go.
Deployment map
Workflows start in the desktop app today. A planned web app will connect through either an organization-operated dashboard or an ISA Warden-hosted dashboard. The choice determines who operates the dashboard and holds its data; other data follows the configured model, storage, tool, and extension routes.
The user-facing client and local execution boundary available today.
A planned browser client available through an organization-operated or ISA Warden-hosted dashboard.
Optional local SurrealKV dashboard bound to a dynamic 127.0.0.1 port.
Selected requests can be processed on the device.
An organization-operated dashboard where dashboard data stays in that organization’s environment.
An ISA Warden-operated dashboard where dashboard data is held by ISA Warden.
Files may use deployment-configured object storage and signed links.
Model requests leave the device when an approved remote provider is selected.
Data-flow matrix
Every enabled capability can create a data route. Use this matrix to build the inventory for your selected workflows and deployment.
| Data | Origin | May go to | Primary control | Behavior |
|---|---|---|---|---|
| Chat and model requests | Direct host chat, an agent, or an extension workflow | The selected local model or configured remote provider | Model selection and provider configuration | Configurable |
| Workspace metadata | Desktop app, planned web app, and dashboard | Embedded local dashboard, organization-operated private dashboard, or ISA Warden-hosted dashboard | Dashboard selection, workspace roles, and group links | Configurable |
| Files and artifacts | User, workspace, or extension | Local cache and, when configured, dashboard-backed artifact storage | User grants, file permissions, group links, and storage configuration | Deployment-dependent |
| Extension data | Mounted extension | Its isolated group folder or an explicitly granted file or folder | Manifest permissions, current-user rights, host policy, and launch context | Configurable |
| Audio and transcription | Desktop capture selected by the user | Local processing or a configured transcription provider | Extension permissions, available host capability, and provider selection | Configurable |
| Tool and extension requests | Host, agent, or extension workflow | An enabled local tool or approved external endpoint | Tool availability, extension permissions, host policy, and outbound network controls | Deployment-dependent |
| Credentials | User or administrator configuration | Credential storage varies by credential type and build scope | Desktop and deployment configuration; verify each credential path in review | Deployment-dependent |
Identity and access
Instead of giving every point tool its own access model, ISA Warden combines identity, workspace roles, group visibility, and resource permissions.
Dashboard passwords are salted and hashed with Argon2.
Successful dashboard login issues a signed JWT with a configured lifetime.
Workspace roles provide permissions for managing and using resources.
A resource existing in a workspace does not automatically make it available to every group.
Protected dashboard operations authenticate the request and reject access when the required scope is absent.
Extension boundaries
Normal extension interfaces run in an iframe and reach host services through a permission-gated bridge. Each workflow asks for specific capabilities; privileged native code or host mods remain separate, visible trust decisions.
Extensions declare the permissions they need. A declared permission still requires host support and policy approval.
The host injects the active extension, workspace, and group scope instead of trusting scope supplied by iframe code.
The host handles workspace authentication. Ordinary extension code does not receive dashboard tokens.
Workspace files and folders require an explicit grant, scoped to the extension and launch context. Grants can be read-only and revoked in Settings.
Each extension writes its own content beneath its group folder. Shared projects provide identity, not access to another extension’s files.
Native code and host mods require explicit privileged declarations and separate review; ordinary UI remains iframe-isolated.
Encryption and credentials
ISA Warden enforces the controls built into the product. Your organization chooses and operates the deployment, connected services, storage, and surrounding data protections.
| Area | Status | What this means |
|---|---|---|
| Web app hosting (planned) | Review required | When available, the web app can use an organization-operated dashboard or an ISA Warden-hosted dashboard. The selected route determines who controls hosting and who holds dashboard data. |
| ISA Warden-hosted dashboard (planned) | Review required | Dashboard data is held by ISA Warden in the hosted option. Hosting controls, regions, retention, subprocessors, backups, and contractual terms must be documented before launch. |
| Dashboard password hashing | Built in | Random salts and Argon2 hashing are used for dashboard passwords. |
| HTTPS dashboard transport | Supported | The desktop client supports HTTPS dashboard connections when TLS is deployed. TLS termination and certificate operation belong to the deployment; the dashboard server does not configure TLS in-process. |
| Managed model-server credentials | Built in | Production desktop builds use the operating-system credential store for the managed local model-server secret. This does not describe every credential type. |
| Saved dashboard logins | Review required | The desktop app stores these in an encrypted local bundle, but its current key-management design requires review for your threat model. |
| Database, files, and backups at rest | Deployment-owned | Choose and verify volume, database, object-storage, backup, and key-management controls. ISA Warden does not make one universal at-rest guarantee. |
| Workspace-level payload encryption | Review required | No general workspace payload-encryption protocol is established by the current implementation. Validate each selected data route and provider instead. |
| External monitoring and telemetry | Deployment-owned | Inventory and verify the exact application build and dashboard configuration before documenting monitoring or telemetry behavior. |
Configuration matters
Define which workflows people may use, what data they can access, and which local, private, or external routes are approved.
Next step
Review how ISA Warden can bring purpose-built AI workflows into one controlled environment for your organization.