Security at Crew.
Crew is designed so companies can give AI employees real responsibility without giving up control.
Permissions, approvals, credentials, company data and activity are protected at every layer.
Our principles
Security built into how Crew works.
These four decisions sit underneath every other control, and none of them is a setting somebody can quietly turn off.
Human approvals
Consequential actions stop for a person. Six destructive ones can never be moved off approval by any setting, at any level.
Scoped permissions
Forty-six actions across twelve categories, each set to allowed, ask, or never — at the workspace, employee, project or single-task level.
Encrypted credentials
Keys and connection tokens are encrypted before they are written and decrypted only at the call that needs them. A model never sees a value.
Full activity history
Every administrative decision is recorded — who did what, when, and what happened. The event, never the credential.
How it works
Built so companies stay in control.
Crew combines the flexibility of a model with the structure a company needs. The same four beats run every piece of work, whether a person started it or a schedule did.
People set direction
You define the goal, provide the context, and set what this employee may do without asking.
Employees work in context
An employee acts on your instructions, inside those permissions, using only the systems you connected.
External actions ask first
Anything consequential stops for a person — and approving one message does not authorise the next draft of it.
All work is recorded
The decision, the action and the result are kept for as long as the workspace exists.
What Crew protects
A secure foundation for real work.
Your data, your tools and your people. Here is what that means in practice, described precisely enough to be checked.
Workspace isolation
Every record belongs to one workspace, and row-level security is on for every table. The workspace is never taken from the browser — it is resolved inside the database from the signed-in account.
Audit trail and traceability
Hires, connections, credentials created and re-scoped, approvals decided, permission changes, invitations, deletions and password events. Every entry names the event, never the secret.
Connected tools and OAuth
Connections are made through each provider's own consent screen, and Crew verifies the binding rather than accepting it. Disconnecting Google, Slack, GitHub, Stripe or Vercel revokes the grant with that provider before Crew deletes its copy.
Role-based access
Owner, admin, member and viewer decide who can change permissions, hold credentials, decide an approval or delete a workspace — and those checks are enforced at the database privilege layer, not only in the interface.
Approval-gated actions
Sending mail, pushing code, changing data or spending money can each require a person. Work that starts on a schedule or from an inbound event gets no more authority than work somebody started by hand.
Credential handling
Each stored key is scoped to the hosts it may reach and the employees that may use it. Where one must go outside, Crew's broker makes the request and returns only the result, so the value never reaches the model.
Questions
Frequently asked questions.
You decide which actions need a person, at whichever level makes sense — this piece of work, the project, the employee, or the whole workspace. When an employee reaches one it stops and asks. The approval is bound to the specific thing approved, so approving one email does not authorise a redrafted one, and two people clicking at once cannot send it twice. Six destructive actions cannot be moved off approval by any setting.
Reporting a vulnerability
If you have found a weakness in Crew, please tell us before you tell anyone else. Send enough detail to reproduce it and we will acknowledge it, tell you what we found, and tell you when it is fixed. Attribution on request.
Start with a secure foundation.
Give your team the reach of AI employees, with the control your company actually needs.
