SANDBOX
Settings

Integrations, retention and roles

Where each credential belongs, how long data is retained, and what each role may do. No credential value is ever displayed, logged, or sent to the browser.

Integrations

Asterxa — the agents' brain

Configured
Environment variable
ASTERXA_API_KEY
Base URL
https://lite.asterxa.ai/api/v1
Status
Asterxa is configured. Agent runs are executed by Asterxa.
Credential value
Never displayed. There is nothing to show here, and this application never renders, logs, or transmits the key to the browser.
Where it belongs
In the application's own .env file, set by the operator. The file is gitignored; .env.example ships with an empty placeholder.

The key is read server-side only, in a single module. If it is absent, agent runs degrade to labelled sandbox analysers rather than pretending to be live.

Platform connectors

Where each platform credential belongs

  • FacebookRequires Access

    A Meta app token, supplied by the operator in the server environment after App Review and Business Verification. Not stored by this application.

  • TikTokRequires Access

    No credential is issued for Pakistan today — Research Tools eligibility excludes Pakistan. Any token would be held by an eligible-region collaborator.

  • XLive

    X API pay-per-use credentials, configured by the operator in the server environment. Not stored by this application.

  • InstagramRequires Access

    A Meta app token for the authorised professional account, supplied by the operator in the server environment. Not stored by this application.

This table describes locations, not values. No connector credential is stored by this application.

Retention

Retention policy

Documented defaults. Change on the Settings page. Retention is a policy decision for the operator, not a hard-coded value.

Roles

What each role may do

  • operator
    • ingest and investigate URLs
    • run agents
    • open and progress cases
    • assemble and seal evidence
    • prepare enforcement requests
  • reviewer
    • everything an operator can do
    • approve or return cases at the approval gate
    • authorise enforcement requests
  • admin
    • everything a reviewer can do
    • manage watchlist and integrations
    • configure retention

The lawful-ground gate is enforced server-side, so no UI state can bypass it.

Standing statement

This application does not remove content from any platform, does not suspend accounts, and does not guarantee that any platform will act on a request. Blocking or restricting content is a power of the Pakistani state exercised by PTA, not a power of this application. Regulatory content is quoted for operational reference only and is not legal advice.