Security and operator control

Specific controls for the inbox, inventory, pricing and responses you allow Billboard Agent to use.

Mailbox permissions

You connect the mailbox the agent may use. Microsoft mailboxes can be limited to approved folders. Gmail inquiries are received through verified forwarding; Google consent uses read-only access, but direct Gmail polling is not presented as live.

Inventory access

Inventory imports are stored against your operator account. Every inventory read and write is scoped to that operator.

Tenant separation

Operator records carry an operator ID and PostgreSQL row-level security enforces the boundary in the database.

Data storage

The service stores the inventory, messages, rules and decision records it needs to run the sales workflow. Uploaded files are kept in operator-specific storage paths.

AI model usage

The inquiry and the relevant operator facts are sent to the configured AI model to prepare a response. The reply is checked against recorded prices, dates and links before it can proceed.

Audit history

Changes to operator-owned records write an audit entry. The build includes a control that fails when a new mutation path does not call the audit writer.

Approval controls

You decide which response types need approval. Drafts, pricing decisions and proposed actions remain visible to the operator.

Automatic sending

Automatic sending only occurs for a response type you have allowed. The send gate checks that permission before every outbound message.

Revoking access

A mailbox can be disconnected, which stops it from being polled or used to send. Autonomy can also be returned to drafts-only mode.

Service outages

If the model cannot produce a verified response, the workflow falls back to a draft for a person rather than sending an unchecked answer.

Support

Get in touch if access needs to be removed, a mailbox changes, or a response needs investigation.

Discuss your setup and access requirements

Get in touch
Billboard Agent Security and Operator Control