Data security and access control
Agents inherit your permission model. They read and write what their role allows, in an environment your compliance team already approved.
The first question every enterprise buyer asks about agents is what they can see. The answer should be boring: exactly what the role permits, and you can prove it afterwards.
An agent is not a special case with its own credentials and its own exceptions. It gets a role inside the permission model your administrators already maintain, and when that model changes the agent’s access changes with it. Anything else is a shadow permission system nobody audits.
On compliance we are precise about who holds what. Creatio and the underlying cloud platforms carry the infrastructure attestations — HIPAA-eligible hosting, regional data residency, the standard enterprise audit reports. We configure your deployment inside those controls and document how.
- Role-based access control governs an agent exactly as it governs a user — an agent cannot read a record its role cannot read
- HIPAA-eligible infrastructure where your sector needs it, on platforms and hosting that publish their own audit reports — we configure inside those controls and can point your risk team at the current report rather than a summary of it
- Residency, retention and handling terms are written into the contract, not assumed from a defaults page
- Healthcare engagements are scoped with your privacy officer before an agent touches a record
