[Lab] unifies identity, policy, and telemetry across Video, Code-gen, and Deep Research—so you can move fast without losing control.


Sources & IDP → Governance & Data Plane (Identity, Policy, Telemetry) → Model & Cost Router → Products (Video, CX/VCX, Deep Research) → Admin & APIs.
Okta, Azure AD, Google Workspace
Automated user provisioning
Role-based access control
Workspaces & projects, least-privilege scopes, service accounts & PATs
Approvals for legal/brand/security sign-off
Write once, enforce everywhere (generate, edit, export, PR).
exports: watermark=required • regions=[US,EU] | data: pii_redaction=strict | models: allowed=[A.latest,B.saver] • max_cost=$0.20prompt → retrieval set → draft → edits → checks → export/PR
paragraph ↔ source/doc/snippet/author/date
Exports: JSON/CSV evidence packs; webhooks for SIEM
AWS KMS/GCP KMS/Azure KV
At rest/in transit, key rotation, egress controls
Fall back to higher-quality only when needed
Reduce unit cost; quotas & alerts
For reproducibility and audits
Certified connectors with ACL-aware sync & write-backs
Connector SDK for partners; versioned schemas
Choose where [Lab] runs—SaaS, your VPC, or your data center.
Fastest path to value; full feature set
Dedicated VPC in your AWS/GCP/Azure; peered networking, private egress
Helm-based install; you manage infra, we provide updates & support
AWS KMS/GCP KMS/Azure KV, HSM optional
VPC peering / PrivateLink / Private Service Connect
Pin workloads & storage to chosen regions
Allow-listed endpoints; offline mode for selected tasks
Rolling upgrades; canary channels; maintenance windows
Prometheus/Grafana, OpenTelemetry, logs to your SIEM
Encrypted snapshots; RPO/RTO targets by tier
Standard or premium SLAs, named TAM (enterprise)
Model gateway can run in-VPC; bring your own model endpoints if required
Some third-party features (e.g., specific watermark services) may require outbound access—documented in the runbook
Identity, policy, telemetry, audit APIs, router, connectors
Video / CX / VCX / Deep Research / Agents
Customer-managed keys
Private network options
Regional compliance
Enhanced support
No by default; optional anonymized feedback only under policy.
Yes—allow-list providers/versions; route by task; set budgets & replays.
No—start with one and expand; policies & identity carry over.
We inherit source permissions and enforce workspace RBAC; cross-workspace access is blocked unless approved.
Yes—download evidence packs (JSON/CSV) or stream via webhooks to your SIEM.