Skip to content

Platform · Security and deployment

Who gets in, what they can do, and what gets recorded.

Security here is not a badge in the footer. It is each person signing in with their own account, using only the functions their role allows, a human decision before a risky action, and a record of who did what. This page explains those controls in working language, separates what Skyller hosts from what changes when a company contracts its own infrastructure, and ties each commitment to the document that backs it.

See how it works
Skyller · Activity trail

Activity trail

Documents
TimePersonAction
09:42CarlaDocument published

Demonstration · illustrative data

FOUR ACCESS PROFILES

administrator, agent manager, operator and viewer; reviewing and approving documents are separate responsibilities

FUNCTION BY FUNCTION

out of a system with dozens of functions, the team gets only the ones the work requires

STOPS BEFORE ACTING

a high or critical risk function waits for a person's decision

WHO, WHAT, WHEN AND FROM WHERE

the company's activity trail, with origin address and browser

Where this shows up in your day

The questions nobody can answer about the company's AI.

They usually come after the scare: someone left, someone deleted, someone needs to prove what happened. In Skyller, each one has an answer you can show on screen.

HR and IT

“He left on Friday. Did his AI leave too?”

The former employee carried on his phone the AI account he used for work, with the connections and keys he created himself. Nobody remembered to switch it off because there was nowhere to switch it off.

Access follows the directory and the revocation

Operations

“Can the AI delete this on its own?”

An agent with access to the system is useful until the day it runs the wrong instruction. The manager's question is not whether the AI makes mistakes: it is whether it can make one without anyone approving.

A risky action waits for a person

Compliance

“Who saw it, who changed it, who approved it?”

The audit asked to reconstruct a decision from three months ago. Without a record, what is left is people's memory and the answer “I think it went like this”.

Trail filterable by person and resource

How it works

From sign-in to action, five controls in sequence.

None of them requires the person to understand security. They sign in, work and ask; the company decides, beforehand, how far each request goes.

  1. 01

    Identity

    Each person signs in with their own account: the company network login (Active Directory), corporate single sign-on, Google or Microsoft, or a Skyller account with two-step verification. There is no shared account and no master key.

  2. 02

    Role

    Four profiles define what the person can do on the platform. Reviewing and approving documents are responsibilities assigned separately, and being an administrator does not grant the power to approve.

  3. 03

    Function by function

    The company connects a system once and enables only the necessary functions, per person or per group. The same question can execute for someone with the role and only look things up for someone without it.

  4. 04

    Approval by risk

    Every function has a risk level. High and critical ones stop and ask for a person's decision: in the chat, in the approvals inbox or in the team's channel. The approval is valid for that action and that company; it cannot be reused.

  5. 05

    Record

    Who did it, what, when and from where stay in the company's activity trail, by resource type: connections, approvals, documents, members, sign-in. The sign-in history, including wrong passwords, comes from the identity provider.

Skyller · Access to the Customer Service workspace

Access to the Customer Service workspace

Customer Service group
Resource actionPermission
View documentsAllowed
Edit contentAllowed

Demonstration · illustrative data

Live proof

The same sentence, two people, two outcomes.

This is what separates control from promise: the permission belongs to the person who asked, not only to the agent. And a risky action does not go out until someone presses Approve.

  1. Two people ask

    “Record the payment settlement for order 4471.” Ana, from Finance, and Bruno, from Sales, send the same sentence to the same agent.

  2. What happens

    1. 01Skyller identifies the connected system's function and checks whether the person who asked can use it: enablement is per function and per person.
    2. 02For Ana, the function is enabled and classified as risky. Instead of executing, Skyller opens the approval card and waits.
    3. 03For Bruno, the function is not in his role. Skyller looks up the order, does not record the settlement, and says so in the conversation.
  3. Result

    Two different decisions from the same sentence, and both in the trail: who asked, what was enabled, who approved, when and from where.

What this scene does not promise

  • Per-function enablement depends on the system being connected through a bridge that exposes functions separately; without it, Skyller looks up and writes, it does not execute.
  • The risk level comes from each function's classification. The company can require confirmation on more functions and lock that requirement; a person can only waive confirmation where the company has not locked it.
  • Approving via Slack or Telegram depends on the channel connection being contracted and configured; without it, the decision happens in the chat or in the approvals inbox.

Where each thing happens

SaaS operated by Skyller as the default. Your own infrastructure as a project.

Two modes, no generic promise: what stays with Skyller, what stays with the company, and what remains outside in both. Installing the application on a server does not make the AI models and the connected systems run there.

Deployment modes

Default for every plan

SaaS hosted and operated by Skyller

The company signs up, creates hubs and invites people. Application, database, document index and files live in infrastructure operated by Skyller, with a separate organization per company and isolation enforced in the database itself.

Processing commitments, providers and deletion are in the DPA and the Trust Center.

Enterprise · per project and contract

Customer-controlled infrastructure

The platform is deployed in the customer's own cloud or on-premises environment, with deployment led by Skyller. It is not an off-the-shelf plan or an installer to download: it is an Enterprise proposal, sized together with the company's IT.

How much runs inside the environment is defined in the project, component by component.

Fully local operation, with AI models, storage and connections inside the customer's environment, is only described that way when each of those pieces is local and that is written into the project and the contract. It is not inferred from the Enterprise name or from where a server sits.

Location and processing board

Component by component, in both modes.

Location and processing board · Component by component, in both modes.
Application and databaseSaaS operated by SkyllerInfrastructure operated by Skyller. One organization per company; the database refuses another company's row even for the table owner.Enterprise on customer infrastructureIn the customer's own cloud or on-premises environment, as defined in the project.
Documents and search indexSaaS operated by SkyllerFiles and index separated per company, in Skyller's infrastructure. Previous document versions are preserved.Enterprise on customer infrastructureIn the environment defined in the project, with the same per-company isolation.
AI answers from external modelsSaaS operated by SkyllerPrompts, context and files go to the model providers needed for the answer, listed in the integrated services. No use for training, including on the fallback route.Enterprise on customer infrastructureThe same API providers, unless the project replaces them with local models that are defined and proven.
Models running on Skyller's serversSaaS operated by SkyllerUnderstanding documents, reading scanned pages, transcribing audio, reranking searches, refining memory and selecting tools run on servers operated by Skyller. In a contingency, they may use providers from the integrated services list.Enterprise on customer infrastructureRequire graphics cards in the customer's environment; sized in the project.
Connected systems (ERP, CRM, in-house system)SaaS operated by SkyllerThey stay where they are. Skyller calls only the enabled functions, with the credential authorized for that person.Enterprise on customer infrastructureSame; the bridge to internal systems can sit inside the customer's network.
Channels (Slack, Telegram, WhatsApp)SaaS operated by SkyllerThe channel vendor's service, contracted as an add-on connection. The message passes through the channel's infrastructure.Enterprise on customer infrastructureSame; the channel vendor remains outside the environment.
Web search by the toolsSaaS operated by SkyllerExternal search and page-reading services, listed in the integrated services; used only when the tool is triggered.Enterprise on customer infrastructureSame; they remain outside the environment.
Sign-in and identitySaaS operated by SkyllerIdentity provider operated by Skyller. The company directory stays at the company and owns the password.Enterprise on customer infrastructureDefined in the project; the customer's directory remains the source.

Server requirements for Enterprise are provided per project: graphics card capacity for the local models, memory, storage, concurrent users and document volume. There is no single number valid for every company, and there is no off-the-shelf on-premises plan.

Real application

An offboarding, from the directory to the trail.

The case that shows up most in security assessments: someone leaves the company on a Friday. What Skyller does, what the company decides and what gets recorded.

  1. 01HR

    Disables the person in Active Directory at 5 pm, as it does with any other company system.

  2. 02Skyller

    The person can no longer sign in with the network login. The access that was open lasts until the session limit, measured in hours, and then dies.

  3. 03Administrator

    Revokes the person's access in Members. Skyller ends the sessions, removes the seat, revokes the API keys and the personal credentials for connected systems, and disconnects their personal connectors.

  4. 04Skyller

    Records each of those decisions in the activity trail: who revoked, what, when and from where.

  5. 05Audit

    Three months later, filters the trail by person and resource type and reconstructs the sequence without depending on anyone's memory.

Comes ready

  • Four access profiles, review and approval responsibilities, groups
  • Approval card in the chat, approvals inbox and signature bound to the action
  • Activity trail with origin address and browser
  • Encrypted credentials and chained revocation on offboarding

The company decides

  • How people sign in: company directory, single sign-on, Google or Microsoft, or an account with two-step verification
  • Which functions of each system are enabled, for which people and groups
  • Which functions require confirmation beyond high risk, and whether a person can waive it
  • The governance mode for documents and who reviews and approves

For your IT team

What IT will ask, with the answer and the limit.

Select a topic to see its capabilities, conditions, and limits.

Company single sign-on
SAML or OIDC, bound to a company domain verified through a DNS record. A seat report compares who is in the provider with who has access in Skyller: missing seat, orphan seat or role mismatch. Available from the Corporate plan.
The company's Active Directory
Direct federation with the directory, read-only: Skyller does not edit or delete a federated user and syncs the profile periodically. The directory owns the password. Disabled there, the person can no longer sign in; an already open session expires within the session limit, measured in hours, and the administrator can end it sooner.
Two steps and password attempts
Two-step verification with an authenticator app, enabled by the person or required by the administrator for a member. Repeated wrong-password attempts lock the account temporarily.
Sessions and sign-in history
Each person sees where the account is connected and ends any access they do not recognize. The sign-in history, including attempts with a wrong password, comes from the identity provider, which is the one that sees those events.

Questions from whoever decides

What usually holds the security assessment back.

Next step

Bring your company's security questionnaire.

Try it free with your team and watch profiles, approval and the trail working with test data. Or book a demo: the team answers your IT's questions with the product on screen and the DPA on the table.