Docs / Concepts

Updated October 2, 2026

Trust and Security: The Architecture Behind ASTRA

Mindlyft's trust story is architectural, not a certificate: there is no separate platform holding your data, every agent has its own scoped identity, every consequential action waits for a human, and every write is logged in a tamper-evident trail. Here is how the four pieces fit together.

What this covers

No separate platform

Work runs inside your own CRM, tools, and repos, not a hosted app holding your data.

Scoped identity per agent

Each agent holds its own credential, limited to the fields its job needs.

Human approval gate

Customer-facing and system-of-record writes wait for a person before they execute.

Tamper-evident audit trail

A SHA-256 trail of what happened, what it was based on, and how to undo it.

01

What does "trust and security" actually mean for an AI agent in a CRM?

It means four separate, checkable things, not one abstract promise. Where does the data live while the agent works on it. Who is the agent acting as when it writes. Who has to agree before a consequential write happens. And what gets recorded so a wrong action can be found and undone. A vendor that only answers one of these, usually the first with a security page, has not actually addressed what happens once an agent is live and drafting changes to a real customer record. Mindlyft is built so all four have a direct, verifiable answer rather than a policy statement about intentions.

02

Where does your data live while Mindlyft works?

Inside your own accounts. Mindlyft runs inside the CRM, automation tools, and repos a team already uses, rather than a separate platform that imports your data and holds it. There is no Mindlyft database that becomes the system of record instead of your Salesforce or HubSpot, and no login to a hosted app that stops working the moment a subscription pauses. This is also why cancelling never strands a team: because the work was never anything other than configuration and writes inside accounts the customer already owns and controls, nothing has to be exported or migrated out when the engagement ends.

03

What stops one agent from acting as if it were a different one, or as a person?

A scoped identity, issued per agent rather than shared. ASTRA does not log in as you and does not use one master key across every workflow it runs. Each agent that writes to Salesforce, HubSpot, Jira, Gmail, or Slack holds its own named identity, permissioned to only the objects and fields that specific job needs. That is what makes a write attributable to a specific agent rather than to "the integration" in general, and what lets one workflow be turned off without touching any other, because disabling an identity revokes exactly the access that identity held and nothing else.

04

What has to happen before a consequential action actually executes?

A named person has to say yes. ASTRA gates actions by consequence: a reversible, internal write, logging a call, filling a field that does not touch pipeline math, drafting a follow-up into a holding queue, runs on its own because it is cheap to undo if something is off. Anything that reaches a customer or changes a system of record, a stage change, an amount, a sent email, a merged record, is drafted and held until a person approves, edits, or rejects it. A drafted action sitting unreviewed does not expire into an execution; nothing happens to the CRM or a customer's inbox because a draft went unanswered. The gate is enforced in the execution path itself, not in a prompt asking the model to behave.

05

What happens to the record of what an agent did?

It is written into a tamper-evident audit trail, hashed with SHA-256 so the record of what happened cannot be quietly altered after the fact. Each entry captures what the agent did, what it acted on, who approved it if approval was required, and what is needed to reverse it. That last part is not an afterthought: every executed write carries enough context that undoing a mistake is a single action rather than a data-recovery project. The trail exists specifically so trusting ASTRA does not depend on trusting that it behaved; it depends on being able to check.

06

Can a security or RevOps reviewer actually verify this, or is it just a page like this one?

It can be tested directly, because each control lives in a system outside Mindlyft's own claims about itself. Scope is verifiable in the target system: look at what an agent's credential can actually touch in Salesforce or HubSpot and compare it to what the workflow needs. The gate is verifiable by attempting a consequential action and confirming it is held rather than executed. The trail is verifiable by tracing a sample of writes in the CRM's own audit log back to a proposal and an approver. And the kill switch is verifiable by disabling an agent and confirming its credential stops working everywhere, immediately. None of these checks require taking Mindlyft's word for it, which is the point: the controls are enforced in systems the customer already owns and can inspect.

07

Does ASTRA read more of my data than it needs to act?

Reads are broad, writes are narrow, and that asymmetry is deliberate rather than an oversight. ASTRA can read widely across a connected tool, pull a record, summarize a call, check a field, because a wide read path is safe: nothing changes as a result of a read. The write path is the one that is scoped tightly, limited to the specific fields and objects a given workflow is permitted to change. Treating the two differently is what keeps the system useful, an agent that could not read context broadly would draft worse actions, while still keeping the one path that can actually damage a record narrow and attributable.

08

What happens when a new integration or workflow is added? Does it inherit the same controls?

Yes, by default rather than by a new policy someone has to remember to write. The classification a new action type gets is the cautious one until it earns otherwise: if it is hard to reverse or visible to a customer, it is treated as consequential and held for a person, the same as every other action in that category. A new connector does not get a blanket allow because it is unfamiliar, and it does not need a bespoke security review before day one, because the scope, gate, and trail apply to it the moment it is registered under an agent's identity. Controls that depend on someone remembering to apply them to the next integration eventually get missed; controls that are the default for anything new do not have that failure mode.

09

How is this different from a compliance certificate?

A certificate attests that an organization's processes were reviewed at a point in time. It says something about how a company runs, not about what a specific agent can do to a specific record on a specific day. The four controls above answer the second question directly: an agent's reach is limited by its own scoped credential right now, not by a policy someone wrote; a consequential write is held for a human right now, not eventually audited after the fact; and a mistake is reversible right now, with the context needed to fix it attached to the entry. Mindlyft is upfront that this page describes architecture, not a list of certifications, because the architecture is what actually determines what an agent can do to your systems on any given day.

FAQ

Does Mindlyft store or host my CRM data on a separate platform?

No. ASTRA runs inside your own Salesforce, HubSpot, Jira, Gmail, and Slack accounts. There is no separate Mindlyft-hosted database that becomes a second system of record, and nothing to migrate out if the engagement ends.

Can one agent do what another agent, or a person, is allowed to do?

No. Each agent holds its own scoped identity, limited to the objects and fields its specific workflow needs. A compromised or misbehaving agent cannot reach beyond that scope, and disabling it does not touch any other agent's access or any person's login.

Will ASTRA ever change a deal stage or send an email without a person approving it first?

No. Any write that reaches a customer or changes a system of record is drafted and held for a named person to approve, edit, or reject. Only reversible, internal writes run without waiting.

Can I see everything an agent has done, and undo a mistake?

Yes. Every executed action is written into a SHA-256 tamper-evident audit trail with what was done, what it was based on, and the context needed to reverse it, so correcting a wrong write is a single action, not a cleanup project.

Is this the same as a SOC 2 or ISO certification?

No, and this page is not a substitute for one. It describes the architectural controls, data residency, scoped identity, the approval gate, and the audit trail, that determine what an agent can actually do to your systems, which is a different and more specific question than what a point-in-time compliance audit answers.

Does ASTRA read more of my CRM than it writes to?

Yes, deliberately. Reads are broad because a read cannot change anything, so ASTRA can pull context widely to draft a good action. The write path is the one kept narrow, scoped to the specific fields and objects a workflow is permitted to change.

Does a brand-new integration get the same controls as an established one?

Yes, by default. A new action type is treated as consequential, and held for a human, until its track record earns automatic status. Scope, the approval gate, and the audit trail apply from the moment an integration is registered under an agent's identity, not after a separate review.

Agents do the work. You approve what reaches the customer.

Mindlyft is the approval and audit layer over your AI GTM agents: every customer-facing action drafted, human-approved, reversible, and logged. We engineer the first workflow free.

Apply for a slot
Start with one workflow

Tell us the call that keeps leaking.

We engineer the follow-through inside the tools your team already runs: the CRM update, the ticket, the recap, the handoff. Nothing customer-facing ships without your yes, and every write leaves a receipt you can reverse.

or book a 45-minute call$5,995 a month30-day cyclesFirst workflow free, you keep it