Security And Data Handling
Use this page when explaining Daeda AI’s access, data handling, approval model, or browser extension to a customer or security reviewer.
At A Glance
Section titled “At A Glance”- You choose which categories of HubSpot data Daeda AI can use.
- Your connected AI provider can receive information used to answer your requests.
- Write Plans remain drafts until a person reviews and executes them in HubSpot.
- License keys can be rotated when access ownership changes.
- The Daeda Bridge is optional and only runs in an enabled browser and portal session.
- Connected portal data can be removed when the portal no longer needs Daeda AI.
Least Privilege
Section titled “Least Privilege”Start with the smallest useful data access set. The connected-portal flow exposes selectable HubSpot data groups, so users can add access for the work they actually need instead of granting every optional scope at once.
The current app configuration includes 5 required installation permissions and 55 optional permissions. Administrators who need their exact HubSpot names can use the Permissions And Scopes reference.
Mirrored Data
Section titled “Mirrored Data”Connected portals prepare a controlled, queryable copy of the HubSpot data you selected. Daeda AI calls this the portal mirror. The connected portal card shows whether that data is ready for questions and planning.
| State | Meaning |
|---|---|
| BUILDING | Daeda AI is preparing or refreshing mirrored data. |
| FAILED | The latest data preparation did not complete successfully. |
| IDLE | No data preparation is running. |
| PARTIAL | Some mirrored data is available with gaps. |
| READY | Mirrored data is ready for use. |
Human Approval
Section titled “Human Approval”A write plan is a draft until a user opens it in HubSpot, reviews the operation list, and chooses to execute it. Asking an assistant for a change does not by itself apply that change to HubSpot.
Users should reject drafts that target the wrong portal, ask for unexpected access, include destructive actions, or do not match the requested business outcome.
License Keys
Section titled “License Keys”License keys connect assistant workspaces to Daeda AI. Keep keys scoped to the workspace that should prepare plans, rotate keys when ownership changes, and avoid sharing keys across teams with different approval responsibilities.
Never include a license key in screenshots, shared documents, support messages, or a project file committed to source control.
Bridge Sessions
Section titled “Bridge Sessions”Bridge-backed actions use the browser profile where the Daeda Bridge extension is installed and connected. Users should confirm the active portal, session status, and connected-portal bridge toggle before executing bridge-backed plans.