SANDBOX
Administration

Model configuration

Which engines this deployment may route to, and where their data goes.

Only approved models are routed to

An unapproved model is represented here so it is visible, but nothing routes to it. The deterministic local analysers are not a model: every sandbox agent run is attributed to them and is never presented as model output. The Asterxa key is read server-side only and never rendered.
Engines

Configured models (3)

  • (example) third-party cloud modelnot approved

    Not approved · —

    Data leaves the perimeter for this engine. Confirm this is acceptable for the data classification it processes before enabling it.

    Placeholder showing how an unapproved model is represented. Nothing routes to an unapproved model.

    updated 2026-09-29 10:21:42

  • Asterxa engine (agent brain)approved

    Asterxa · Agent roles: extraction, normalisation, policy checks, briefings

    Data leaves the perimeter for this engine. Confirm this is acceptable for the data classification it processes before enabling it.

    Configured per deployment via ASTERXA_API_KEY, read server-side only. When no key is present every role degrades to a visibly-labelled sandbox run.

    updated 2026-09-29 10:21:42

  • Deterministic local analysersapprovedlocal only

    In-process · Sandbox fallback: text heuristics, OCR stub, transcript segments

    Data does not leave the perimeter.

    No model. Deterministic and fully local. All sandbox agent runs are attributed to this, never presented as model output.

    updated 2026-09-29 10:21:42

Data residency reconciled

Where data is STORED versus where it is PROCESSED

These are two different questions, and the earlier UI merged them

A workspace marked In-country describes where records are kept. The Asterxa engine is an external service, so any role routed to it sends the target text off the perimeter. The two statements were previously shown side by side without being reconciled, which read as a contradiction. They are reconciled here by permitted data class.
  • Asterxa engine (agent brain)leaves the perimeter
    Stored: Not retained by this applicationProcessed: EXTERNAL — the Asterxa service (lite.asterxa.ai)Basis: Explicit operator configuration via ASTERXA_API_KEYPermitted data classes: public, internal

    Routing a role to Asterxa SENDS the target text to an external service. Because that crosses the perimeter, only public and internal material may be routed to it in this configuration. Restricted or sensitive case content must NOT be sent: use the deterministic local analysers instead. A workspace's 'In-country' setting governs STORAGE and does not, by itself, authorise external processing.

  • Deterministic local analysersstays in-country
    Stored: In-country — the deployed hostProcessed: In-country — the deployed hostBasis: Built-in, no external callPermitted data classes: public, internal, restricted, sensitive

    No model and no network egress. Not a model — accurate but deterministic, and labelled as such everywhere.

  • This application (record storage)stays in-country
    Stored: In-country — the deployed hostProcessed: In-country — the deployed hostBasis: Workspace data-residency settingPermitted data classes: public, internal, restricted, sensitive

    Records and evidence stay on the deployed host. This is what 'In-country' on a workspace refers to.

A workspace set to 'In-country' governs storage. It does not, by itself, authorise processing outside the perimeter — which is exactly what routing an agent role to an external model does.