Security & Data

Trace how an account signal enters, changes, and leaves the agent

Review provenance, credential scope, runtime behavior, retention, and human approval before connecting production visitor or CRM data.

npx -y @okki-global/okki-go-taroball

Copy → inspect → run in an approved environment

Fact ledger

Controls to verify in your exact configuration

Data sources

  • Config-dependent: first-party events and enrichment sources vary by deployment.
  • Required evidence: source name, field purpose, checked time, and inference status.
  • Review gate: ambiguous company resolution stays unknown.

API keys

  • Operator-controlled: keys belong in the runtime secret store.
  • Required evidence: scope, owner, rotation, revocation, and access logs.
  • Review gate: never place credentials in prompts or exports.

Runtime behavior

  • Not asserted here: inspect package version, files, network calls, logs, and update behavior.
  • Required evidence: test in an isolated environment before production access.
  • Review gate: stop on unexpected permissions.

Retention and deletion

  • Config-dependent: results may persist in agent logs, files, CRM, or providers.
  • Required evidence: map each copy, retention period, correction path, and deletion owner.
  • Review gate: uninstalling is not downstream deletion.

Connection and permission matrix

Input sources

Website eventsRead approved event fields · Config-dependent

CRM accountsRead selected account fields · Config-dependent

Research runtime

ResolutionEvidence synthesis · Human-review required

Signal briefInference labeled · Workflow available

Destinations

Review queueWorkspace output · Runtime-dependent

CRM write-backScoped and optional · Approval required

No third-party name on this page implies an official partnership or universal compatibility. Verify current connector documentation and granted scopes directly.

Compare operating models, not marketing labels

Assessment framework checked 21 July 2026. Unknown means this site does not have current first-party evidence.

DimensionAgent-native skillCentralized seat SaaSBuyer check
Setup pathPackage run in chosen runtimeHosted account and admin setupReview executable actions or vendor controls
Task modelNatural-language research inside agentStandardized application workflowTest repeatability and review ownership
Data disclosureConfig-dependentVendor-dependentRequest field-level provenance
Human reviewRequired by this operating modelVaries by configurationTest approval and override paths
Credential boundaryRuntime secret storeVendor-managed applicationInspect scopes, logs, rotation, and revocation
RetentionRuntime and destination dependentVendor policy dependentMap deletion across every copy
Certification evidenceUnknownVendor-specificRequest current first-party reports

Install through four explicit states

  1. Copy

    npx -y @okki-global/okki-go-taroball

    Success means the command is on your clipboard.

  2. Run

    Inspect package identity and execute only in an approved runtime.

  3. Configure

    Grant narrow credentials and test source and destination access separately.

  4. First result

    Confirm provenance, timestamps, uncertainty, and pending human review.