Orbira Labs Join the waitlist

Category: Privacy

  • How we think about permissions and trust

    How we think about permissions and trust

    Giving software access to your email, calendar and documents is a real decision. We think it should be explicit, granular and reversible.

    Orbira asks for the narrowest access that gets a job done. Every connection can be reviewed and removed. Actions that send, share or delete can require your approval, and every run leaves an audit trail you can read.

    Trust is built in small steps, so we start conservative and let teams loosen controls as they gain confidence.

  • A short checklist for connecting tools safely

    A short checklist for connecting tools safely

    Connecting an app to your email, calendar or documents is a real decision. This checklist works for Orbira and for any other tool.

    The checklist

    1. What can it read? Ask for the narrowest set. If it only needs one folder, do not grant the whole drive.
    2. What can it write? Start read-only. Add write access when you have a specific workflow that needs it.
    3. Can you see what it did? There should be a log you can read, not just a promise.
    4. Can you revoke it? Find the disconnect button before you connect.
    5. Who else on your team is affected? Shared inboxes and shared drives expose other people’s messages.
    6. What happens to the data? Read the privacy policy for what is stored, for how long, and how to delete it.
    7. Is there a human step before anything leaves? For anything that sends or shares, the answer should be yes.

    A note on shared resources

    If you connect a shared mailbox, tell the people who use it. They have a right to know that software is reading and sorting their messages.

    Revisit quarterly

    Set a reminder every three months to look at the list of connected tools. Remove the ones you no longer use. Unused connections are quiet risks.

    What we do about it

    Orbira is built around these questions. Connections are scoped per tool, approval gates default to on for risky steps, and every run has a log. You can read more on the docs and privacy pages.