Exports
Many ways in, one controlled way out. Exports run as safe background jobs and never include another customer’s data.
Requestadmin · export type
→Queue
→export.generate jobBuildtenant-forced · redacted
→Envelopestatus · checksum
→Downloadread scope
→Deleteadmin
What you can export
Safeguards
- ●The requested
tenant_idis forced to match the active tenant. - ●Secrets, API keys, webhook secrets, tokens, and password-like fields are redacted.
- ●Creating an export requires
admin; reading requiresread. - ●No data export happens without explicit human approval.
◈DeletionDeleting operational data removes raw customer data and stops new data coming in. Export first if you need a copy.