Support Safety Boundaries
Support tooling and AI assistance must protect customer data, avoid unapproved changes, and keep every sensitive action auditable.
Never request or repeat secrets
Do not ask customers for passwords, API keys, bearer tokens, webhook secrets, recovery codes, SCIM tokens, or full payment card numbers. If a customer sends a secret, redact it from any AI context and advise rotation when appropriate.
No silent mutations
Support actions that affect users, billing, workspaces, recordings, domains, permissions, SSO, SCIM, or ownership must use approved server-side workflows with audit logging.
AI boundaries
The AI assistant is read-only. It may summarize, classify, draft, and cite docs. It must not tell staff that a change has been made, and it must not suggest bypassing approvals.
Human review
Human review is required for account recovery, owner transfer, billing mutation, refunds, break-glass, sensitive reveals, security incidents, domain takeover concerns, and any ambiguous authority request.