Data access and safe operation
Keep customer data safe in Spacebrain with the right roles, careful imports and exports, reviewed AI actions, consent checks and clean offboarding.
Spacebrain holds your customers' details and can message them, so a few good habits go a long way. This guide gives you a practical checklist for access, imports and exports, AI, messaging consent and deletion. It's for workspace owners, admins and anyone who handles customer data.
Before you begin
- Know who owns your workspace and who the admins are.
- Know which rules apply to your business, such as privacy law and messaging rules in the countries where your customers live. Spacebrain gives you the tools, but you're responsible for using them lawfully.
Work in the right workspace
Each workspace keeps its data separate. Agencies can also open client sub-accounts, but the agency overview isn't the same as being inside the client's sub-account.
- Check the workspace name at the top of the sidebar before you import, send, delete or change a connection.
- Refresh or close old browser tabs after you switch workspaces.
See navigation and workspaces.
Give people only the access they need
- Open Settings → Workspace and review the Members tab.
- Give each person the lowest role that lets them do their job: Viewer to look, Editor to change content, Admin to manage people and settings.
- Use the Permissions tab to limit access further with permission groups.
- When someone leaves, reassign their deals, tasks and conversations, then select Remove Member.
Connect outside services, such as email and phone providers, with accounts your business controls, not a personal account that leaves with an employee.
Handle customer data carefully
- Import only the fields you need.
- Keep consent, source, opt-out and owner details with each contact.
- Remove passwords and unnecessary personal details from screenshots, support messages and AI prompts.
- Export only when you need to, store exports securely and delete working copies when you're done.
- Never paste passwords, API keys, card numbers, private keys or one-time codes into notes, prompts, knowledge bases or support messages.
Use AI safely
Orbit and AI Copilot are helpful, but you're still in charge.
- Orbit never makes an important change without a review card. Read what will change, which record it affects and the credit cost before you select Confirm. See Orbit, your AI assistant.
- Check the sources. Open the records behind an answer before you act on it.
- AI Copilot acts on its own only in Auto mode, and only within the limits you set. Start in Draft. See AI Copilot.
- Keep policies in knowledge bases, not in people's heads, so the AI answers from approved information. See Knowledge hub.
- Hand over to a person for legal, medical, financial or safety decisions, and for anything that can't be undone.
Messaging and consent
Before you contact anyone, check:
- They agreed to hear from you on that channel.
- Your sender name and business are clear.
- Quiet hours and time zones are respected.
- Opt-outs are honored on every channel and in every automation.
- Call recording notices are in place where required.
- Text messaging registration, such as A2P 10DLC in the US, is complete. See phone outreach and compliance.
Deleting and disconnecting are different
These are separate actions:
| Action | What it does |
|---|---|
| Delete a record in Spacebrain | Removes it from Spacebrain. |
| Disconnect a provider in Spacebrain | Stops Spacebrain using that connection. |
| Revoke access at the provider | Stops the provider accepting Spacebrain's requests. |
| Delete data at the provider | Removes it from the provider's own systems. |
Doing one doesn't do the others. Read each confirmation message carefully. To close your whole account, see delete your account. For a formal privacy request, contact support.
Offboarding checklist
When someone leaves your team:
- Reassign their open deals, tasks and conversations.
- Change or remove any provider connections they set up with their own accounts.
- Revoke any AI agent access tokens they created in Settings → AI Agents. See connect AI assistants with MCP.
- Remove them from the workspace in Settings → Workspace → Members.
- If they owned a workspace, transfer ownership before they leave.
If something goes wrong
| Problem | What to do |
|---|---|
| Data went to the wrong workspace | Stop related automations, then delete or move the records. Check who was contacted. |
| An AI action changed the wrong record | Open the record, correct it and dismiss any similar pending approvals. |
| A secret was pasted into a note or prompt | Delete it, then change the password or key at the provider straight away. |
| You suspect someone else is using an account | Remove their access, change affected passwords and contact support. |
FAQ
Can AI see data my role can't?
No. Orbit only uses data the person asking can already open.
Does disconnecting an integration delete its data?
Not necessarily. Records already in Spacebrain usually stay. Check the confirmation message and the provider's settings.
Next step
Review who can do what in roles and permissions.
Next step
Keep moving
Open the relevant Spacebrain screen or contact support if you need help.
Last updated on