Skip to content

Security

The Security section

Default tool mode for new workflows — Automatic or Needs approval, shipping as Needs approval. This is the starting posture for every workflow drafted from here on. Per-tool settings on each workflow’s Access tab tune it further.

Static and always on: nothing from this workspace trains Alma’s models or anyone else’s, on every plan.

The remaining rows are grouped by concern — Authentication, Membership & invites, Data protection, AI guardrails, Developers & network, and Audit & compliance — and link to Billing. They cover SSO and SAML, SCIM provisioning, session length, allowed email domains, data residency and retention, model defaults, IP allowlisting, and SOC 2 evidence.

Concern Where
What Alma may do in a tool, and who Connections → Tools & access
Who approves what, per workflow Workflows → Access
Who can see a topic Memory → Topics
Who holds admin Members
What external callers can read API