Connections
Connection credentials and tokens are encrypted at rest, and connection traffic is encrypted in transit. Hosted integrations use provider authorization flows where available so you can grant access without giving a Righthand the account password. Each connection can be controlled through:- Scope: Personal, Righthand, or Team ownership.
- Righthand access: which Righthands can use the connection.
- Tool permissions: Yes, Ask, or No for individual tools when available.
Connection Security
Configure least-privilege access and revoke a connection safely.
External communications
Each Righthand has separate Allow, Ask, or Never controls for email, messages, calls, Slack, calendar actions, and connected-app actions. These controls apply to externally visible outbound actions, not simply to reading or drafting.External Communications
Understand per-channel policy and conversational approval.
Voice authentication
When a voice passphrase is configured for a user, it helps authenticate that user on calls with Righthands. Treat the passphrase as a secret and do not reuse an account password.Voice Authentication
Learn when a passphrase is configured and how to get help changing it.
Practical security checklist
- Connect the least-privileged provider account that can do the job.
- Assign access only to the Righthands that need it.
- Use Ask for consequential tools and outward actions that need review.
- Keep passwords, personal access tokens, recovery codes, and API keys out of messages and repositories.
- Remove access both in Righthand and at the provider when a credential should no longer work.
- Review Activity after changing a sensitive connection or policy.
For security or account-access help, contact support@humans.righthand.ai.