Govern · For CISOs and security teams

Bring AI tool sprawl back under control.

Give people purpose-built AI workflows inside one governed environment. Approve the models, extensions, capabilities, and services they can use—and trace where organizational data is allowed to go.

Deployment map

One environment, explicit data routes

Workflows start in the desktop app today. A planned web app will connect through either an organization-operated dashboard or an ISA Warden-hosted dashboard. The choice determines who operates the dashboard and holds its data; other data follows the configured model, storage, tool, and extension routes.

device

Desktop app

The user-facing client and local execution boundary available today.

planned

Web app

A planned browser client available through an organization-operated or ISA Warden-hosted dashboard.

local

Embedded dashboard

Optional local SurrealKV dashboard bound to a dynamic 127.0.0.1 port.

local

Local model

Selected requests can be processed on the device.

managed

Private dashboard

An organization-operated dashboard where dashboard data stays in that organization’s environment.

hosted

Hosted dashboard

An ISA Warden-operated dashboard where dashboard data is held by ISA Warden.

managed

Artifact storage

Files may use deployment-configured object storage and signed links.

external

Configured provider

Model requests leave the device when an approved remote provider is selected.

Data-flow matrix

See where organizational data can go

Every enabled capability can create a data route. Use this matrix to build the inventory for your selected workflows and deployment.

Potential ISA Warden data paths and the controls that govern them
DataOriginMay go toPrimary controlBehavior
Chat and model requestsDirect host chat, an agent, or an extension workflowThe selected local model or configured remote providerModel selection and provider configurationConfigurable
Workspace metadataDesktop app, planned web app, and dashboardEmbedded local dashboard, organization-operated private dashboard, or ISA Warden-hosted dashboardDashboard selection, workspace roles, and group linksConfigurable
Files and artifactsUser, workspace, or extensionLocal cache and, when configured, dashboard-backed artifact storageUser grants, file permissions, group links, and storage configurationDeployment-dependent
Extension dataMounted extensionIts isolated group folder or an explicitly granted file or folderManifest permissions, current-user rights, host policy, and launch contextConfigurable
Audio and transcriptionDesktop capture selected by the userLocal processing or a configured transcription providerExtension permissions, available host capability, and provider selectionConfigurable
Tool and extension requestsHost, agent, or extension workflowAn enabled local tool or approved external endpointTool availability, extension permissions, host policy, and outbound network controlsDeployment-dependent
CredentialsUser or administrator configurationCredential storage varies by credential type and build scopeDesktop and deployment configuration; verify each credential path in reviewDeployment-dependent

Identity and access

Apply one control model across workflows

Instead of giving every point tool its own access model, ISA Warden combines identity, workspace roles, group visibility, and resource permissions.

01

Password protection

Dashboard passwords are salted and hashed with Argon2.

02

Expiring sessions

Successful dashboard login issues a signed JWT with a configured lifetime.

03

Granular authorization

Workspace roles provide permissions for managing and using resources.

04

Group separation

A resource existing in a workspace does not automatically make it available to every group.

05

Permission-checked routes

Protected dashboard operations authenticate the request and reject access when the required scope is absent.

Extension boundaries

Add workflows without adding unchecked access

Normal extension interfaces run in an iframe and reach host services through a permission-gated bridge. Each workflow asks for specific capabilities; privileged native code or host mods remain separate, visible trust decisions.

Explicit capabilities

Extensions declare the permissions they need. A declared permission still requires host support and policy approval.

Frozen launch context

The host injects the active extension, workspace, and group scope instead of trusting scope supplied by iframe code.

No dashboard tokens in the iframe

The host handles workspace authentication. Ordinary extension code does not receive dashboard tokens.

User-controlled file grants

Workspace files and folders require an explicit grant, scoped to the extension and launch context. Grants can be read-only and revoked in Settings.

Isolated extension storage

Each extension writes its own content beneath its group folder. Shared projects provide identity, not access to another extension’s files.

Higher-trust code is visible

Native code and host mods require explicit privileged declarations and separate review; ordinary UI remains iframe-isolated.

Encryption and credentials

What ISA Warden protects—and what you operate

ISA Warden enforces the controls built into the product. Your organization chooses and operates the deployment, connected services, storage, and surrounding data protections.

ISA Warden security responsibility matrix
AreaStatusWhat this means
Web app hosting (planned)Review requiredWhen available, the web app can use an organization-operated dashboard or an ISA Warden-hosted dashboard. The selected route determines who controls hosting and who holds dashboard data.
ISA Warden-hosted dashboard (planned)Review requiredDashboard data is held by ISA Warden in the hosted option. Hosting controls, regions, retention, subprocessors, backups, and contractual terms must be documented before launch.
Dashboard password hashingBuilt inRandom salts and Argon2 hashing are used for dashboard passwords.
HTTPS dashboard transportSupportedThe desktop client supports HTTPS dashboard connections when TLS is deployed. TLS termination and certificate operation belong to the deployment; the dashboard server does not configure TLS in-process.
Managed model-server credentialsBuilt inProduction desktop builds use the operating-system credential store for the managed local model-server secret. This does not describe every credential type.
Saved dashboard loginsReview requiredThe desktop app stores these in an encrypted local bundle, but its current key-management design requires review for your threat model.
Database, files, and backups at restDeployment-ownedChoose and verify volume, database, object-storage, backup, and key-management controls. ISA Warden does not make one universal at-rest guarantee.
Workspace-level payload encryptionReview requiredNo general workspace payload-encryption protocol is established by the current implementation. Validate each selected data route and provider instead.
External monitoring and telemetryDeployment-ownedInventory and verify the exact application build and dashboard configuration before documenting monitoring or telemetry behavior.

Configuration matters

Turn platform controls into data policy

Define which workflows people may use, what data they can access, and which local, private, or external routes are approved.

  1. Document which use cases select a local model and which may use a remote provider.
  2. Decide between the embedded dashboard, an organization-operated private dashboard, and the planned ISA Warden-hosted dashboard; document who holds dashboard data.
  3. Terminate TLS for remote dashboard traffic and maintain certificates.
  4. Configure encryption, access, retention, and tested recovery for databases, files, object storage, and backups.
  5. Review every extension’s permissions, publisher, external endpoints, and native or host-level code.
  6. Allowlist or monitor outbound destinations required by selected models, tools, and extensions.
  7. Define retention and deletion behavior for conversations, files, artifacts, recordings, caches, and logs.
  8. Confirm monitoring and telemetry behavior for the exact release and deployment configuration.
  9. Assign owners for incident response, credential rotation, dependency review, and desktop/dashboard updates.

Next step

Consolidate workflows. Control capabilities. Govern data routes.

Review how ISA Warden can bring purpose-built AI workflows into one controlled environment for your organization.