Confidential technical resources for evaluating First Recon AI. Access is provided by your First Recon contact.
The governed workspace puts chat, agents, and company knowledge in one surface, with the runtime judging every interaction on the way to the model. This page covers what is inside it, how it is delivered, what IT controls, what data it touches, and day one.
Four experiences share one governed path. Nothing in the workspace reaches a model around the runtime, and nothing needs a second policy system.
Every enabled model provider behind one picker. Prompts are judged on the way in and responses on the way out, and redaction lands inline so work keeps moving.
Agent runs are governed like human users, with the same access policies, the same logging, policy enforced at the action, and approval gates at the point an action would execute.
Enterprise sources sync through a permission-aware connector, and source-system permissions are enforced at index time and again at retrieval. The flow is diagrammed on Integrations.
A team feed for reusable outputs: workflows, findings, and tools shared across the team instead of trapped in one person's history.
| Runtime function | In the workspace |
|---|---|
| Observe | Every chat, agent run, and knowledge query on the record |
| Detect | Meaning and intent judged in real time; the depth is on Semantic security |
| Enforce | Allow, redact in place, hold for human review, or block, before anything reaches a model; the mechanics are on Data protection |
| Trace | A sealed, metadata-only receipt for every decision, exportable to your SIEM |
The external release is web-first. The browser workspace is the day-one lane with the full capability set; macOS and Windows desktop applications follow once they clear the same stability bar. Enforcement at the endpoint belongs to the Endpoint Security; the two products pair rather than overlap.
| Delivery | Status | What runs there | Enforcement posture |
|---|---|---|---|
| Browserany managed or unmanaged device | Available | The full workspace: chat, agents and Cowork, company knowledge, Pulse, administration | Full runtime protections on the governed path |
| DesktopmacOS · Windows | Staged rollout | The same workspace, plus the desktop-led experiences as they land | Same governed path; pairs with the Endpoint Security for controls at the endpoint |
| Mobilecompanion | Coming soon | Companion access to the governed workspace | Same governed path |
The console that governs the Secure Enterprise AI Workspace also governs the Endpoint Security, one policy surface rather than per-product settings sprawl.
One policy set across browser, desktop, and endpoint: allow, redact, hold for human review, or block, tuned by department, team, or role. The catalogs are browsable in full on Data protection.
Enable providers and models per tenant from the catalog; people only see what you turned on. The live catalog is browsable on Architecture.
Connect enterprise sources under explicit include and exclude scoping per site or drive. Source permissions ride along; nothing is flattened into a shared index.
Metering and caps enforced inline on the governed path, before a model call completes, so spend control applies at the same point as policy rather than as a report after the fact.
Single sign-on through your identity provider, with group and role mapping; agents inherit the same access policies as people.
Interactions the runtime cannot judge cleanly hold for designated reviewers instead of being rounded to allow or block. The trail keeps the decision, not the content.
The workspace handles four kinds of data, each with a different boundary. Which trust boundary applies to raw content depends on the deployment option; that comparison is on Data & residency.
| Data | Where it lives | What leaves the boundary |
|---|---|---|
| Prompts and responsesuser and agent content | Judged inline in the decision path | Only the allowed or redacted version crosses to a model provider; raw content is not retained as evidence |
| Company knowledgeconnected sources | Tenant-isolated governed data plane | Only what the runtime allows into a specific interaction, permission-checked for the requesting user |
| Decision evidenceaudit trail | Audit Ledger, tenant-isolated | Sealed, metadata-only receipts, exported to your SIEM |
| Held-for-review itemsthe one exception | Visible to designated reviewers until they decide | The decision, not the content |
Rolling the Secure Enterprise AI Workspace out is an identity connection and a policy decision, not an infrastructure project. The pilot team works governed from the first session.