Gessa Docs
Generated Reference

Reference

AgentEnv data controls

Sources: server/src/modules/agentenv/export/dataControls.ts.
engine v1.0.234Copy for LLM

This doc publishes the retention, deletion, ownership, and export control for every durable AgentEnv artifact class. There are 13 classes. Ownership is the workspace tenancy boundary proven on PostgreSQL by AER-R6-A: a cross-tenant read/mutation is an opaque not-found. Deletion is reversible (every table ships a down-migration) and, for workspace-columned tables, per-tenant. Customer data ownership is exercised by the trajectory export, which delivers the exact JSONL bytes to the customer's own storage through the platform SSRF/egress policy (safeEgressFetch); Gessa keeps only an audit-ready delivery receipt. Provider secrets in the credential vault are NEVER exported (only the AES-256-GCM envelope is stored, and the plaintext is never persisted).

Artifact classes

Artifact classStorageOwnershipRetentionDeletionExport
credential_vaultagentenv_credential_vaultworkspace_scopedHeld until revoked (AER-R6-B) or rotated; the plaintext secret is never persisted (only the AES-256-GCM envelope).Revocation (fail-closed resolve) then per-workspace erasure (workspace_id column); reversible via 0406_agentenv_credential_vault.down.sql.never_secret
human_baseline_consent_eventagentenv_human_baseline_consent_eventsworkspace_scopedConsent audit trail; DORMANT per RD-10 - no active writer.Reversible via 0262 down-migration; retained as consent evidence while its session exists.not_exported
human_baseline_sessionagentenv_human_baseline_sessionsworkspace_scopedConsent-gated; DORMANT per RD-10 (human baseline deferred) - no active writer.Reversible via 0262_agentenv_human_baselines.down.sql; consent withdrawal erases the session.not_exported
manifestagentenv_manifestsglobal_immutable_contentImmutable published environment artifact; retained while any run references it.Reversible via 0390_agentenv_manifest_artifacts.down.sql; not per-tenant (global content).not_exported
observation_traceagentenv_protocol_observation_tracesworkspace_scopedAppend-only evaluation evidence retained for the run's lifecycle.Reversible via 0391_agentenv_observation_traces.down.sql; erased with its run.trajectory_jsonl
packagentenv_packsglobal_immutable_contentImmutable published pack artifact; retained while any manifest references it.Reversible via 0390 down-migration; not per-tenant (global content).not_exported
protocol_action_authority_bindingagentenv_protocol_action_authority_bindingsworkspace_scopedBounded to the episode's runtime authority window.Reversible via 0389 down-migration; erased with its run/episode.not_exported
protocol_episodeagentenv_protocol_episodesworkspace_scopedInherits the owning run's retention (child of the run aggregate).Reversible via 0389 down-migration; erased with its run.trajectory_jsonl
protocol_execution_idempotencyagentenv_protocol_execution_idempotencyworkspace_scopedOperational execution de-duplication ledger.Reversible via 0389 down-migration; erased with the tenant.not_exported
protocol_idempotencyagentenv_protocol_idempotencyworkspace_scopedOperational de-duplication ledger; retained only as long as replay protection is meaningful.Reversible via 0389 down-migration; per-actor rows erased with the tenant.not_exported
protocol_runagentenv_protocol_runsworkspace_scopedDurable for the run's evaluation lifecycle; bounded operational retention thereafter.Reversible via 0389_agentenv_protocol_repository.down.sql; per-workspace erasure by workspaceId (record->>'workspaceId', indexed).trajectory_jsonl
reward_traceagentenv_protocol_reward_tracesworkspace_scopedAppend-only evaluation evidence retained for the run's lifecycle.Reversible via 0389 down-migration; erased with its run.trajectory_jsonl
trajectory_exportcustomer storage (egress)customer_storageCustomer-controlled: the exact JSONL bytes are delivered to the customer's own storage; Gessa retains only an audit-ready delivery receipt (exportId, contentHash, byteCount), never a second copy of the bytes.Customer-controlled in their storage; the delivery is idempotent and SSRF-bounded (safeEgressFetch).trajectory_jsonl
Was this helpful?Report an issueContact support

On this page