Skip to main content

Security & Responsible Use

Data handling

Connector credentials and other secrets are never returned by any tool, read or write.

Some tools default to holding back the more sensitive parts of a result, returning only what's needed to answer the question unless you explicitly ask for more. Tool calls are logged for support and abuse-monitoring purposes, the same as your other activity in Matia.

How write actions are flagged

A small number of tools change something in Matia: enabling or disabling a monitor, updating asset governance, and running an integration action. See Tool Reference for the complete list.

Matia marks each of these as a non-read-only action, so an assistant can tell a write apart from a read before it runs it. Most assistants use that signal to ask you to confirm first.

That marking is a signal to your client, not something Matia enforces. Whether an assistant prompts you, and how, is up to that client. Some prompt on every tool call, including reads; some can be configured to stop asking. Don't treat the prompt as the thing standing between an assistant and a change to your workspace.

What actually gates a write

Permissions do. A write tool is only offered to your assistant if your Matia roles allow it, and the server re-checks on every call, so an assistant cannot run a write you couldn't run yourself, regardless of how its confirmation behaves. See Authentication & Access Management for which roles unlock which actions.

If you want a connection that cannot change anything at all, give the account read-only roles: the write tools are then never offered in the first place.

ON THIS PAGE

Need Help?

Get help and support on all things Matia.

Contact Us