Integrations, retention and roles
Asterxa — the agents' brain
- Environment variable
- ASTERXA_API_KEY
- Base URL
- https://lite.asterxa.ai/api/v1
- Status
- Asterxa is configured. Agent runs are executed by Asterxa.
- Credential value
- Never displayed. There is nothing to show here, and this application never renders, logs, or transmits the key to the browser.
- Where it belongs
- In the application's own .env file, set by the operator. The file is gitignored; .env.example ships with an empty placeholder.
Where each platform credential belongs
- FacebookRequires Access
A Meta app token, supplied by the operator in the server environment after App Review and Business Verification. Not stored by this application.
- TikTokRequires Access
No credential is issued for Pakistan today — Research Tools eligibility excludes Pakistan. Any token would be held by an eligible-region collaborator.
- XLive
X API pay-per-use credentials, configured by the operator in the server environment. Not stored by this application.
- InstagramRequires Access
A Meta app token for the authorised professional account, supplied by the operator in the server environment. Not stored by this application.
This table describes locations, not values. No connector credential is stored by this application.
Retention policy
Documented defaults. Change on the Settings page. Retention is a policy decision for the operator, not a hard-coded value.
What each role may do
- operator
- ingest and investigate URLs
- run agents
- open and progress cases
- assemble and seal evidence
- prepare enforcement requests
- reviewer
- everything an operator can do
- approve or return cases at the approval gate
- authorise enforcement requests
- admin
- everything a reviewer can do
- manage watchlist and integrations
- configure retention
The lawful-ground gate is enforced server-side, so no UI state can bypass it.
Standing statement