Review what OrgX receives, how local hooks differ from hosted MCP, and which controls need deployment-specific evidence.
Last updated September 7, 2026
Try OrgX in the browser without local hooks
Review the requested scopes and use synthetic data before connecting a work environment.
Workspace access and connector permissions determine which records a client can read or change.
Use available activity records and request identifiers when reporting an issue. Coverage depends on the surface.
Verifier-ready controls
Reviewers should not have to infer whether OrgX has scoped OAuth, audit history, exportability, permission boundaries, or a retention story. These are the concrete controls and routes we can point to today.
OAuth scopes
MCP pairing starts from authenticated user intent and moves through a consent step where connector permissions are approved before tools are exposed.
Review packet includes the consent flow, session-lifetime policy, and scope-to-tool mapping without publishing internal routes.
Permission boundaries
Workspace operations use endpoint-specific authentication and authorization. Review the current API contract and requested workspace before a write.
Review packet includes the control model and representative policy evidence without exposing internal handler names or privileged route inventory.
Audit trail proof
Audit evidence can identify an actor, workspace, target, event, and timestamp. Confirm coverage for the action under review.
Authenticated reviewers can request timestamped audit extracts through support or in-product export paths.
Data export
Usage exports, learned-workspace exports, and audit extracts are explicit authenticated workflows. Unsupported export surfaces fail closed instead of implying silent coverage.
Review packet lists available export types, formats, requester requirements, and expected response behavior without publishing internal route templates.
Retention policy
Backups, operational logs, and workspace records have separate lifecycles. The data-handling summary below identifies what is documented and what still needs deployment-specific evidence.
Request current retention, backup, and deletion evidence for the specific deployment.
Export walk-through
The export path is meant to be boring: authenticated, timestamped, no-store responses that can be attached to a security review without manual reconstruction.
Processor review
The one-pager summarizes controls, export routes, and processor coverage. The sub-processor page maps each provider to purpose, data categories, and operating controls for buyer diligence.
Report a suspected issue with the minimum redacted evidence. Do not include secrets, raw transcripts, or employer code. Response commitments depend on your applicable agreement.
Report the affected surface, time, and redacted request identifiers.
Isolate impacted services, rotate credentials, and enable maintenance mode where necessary.
Confirm the observed impact and communicate verified scope and remediation guidance.
Use the incident findings to prioritize fixes and regression checks.