01Role-Based Access Control
Every resource on Opal is permissioned, including Agents, Flows, Tasks, Knowledge, Skills, Guardrails, Connectors, and Variables. Roles determine who can view, edit, publish, and administer, so the right people reach the right resources.
02Single Sign-On
SSO integrates authentication at the organization level, so access follows your existing identity provider and offboarding happens in one place.
03Guardrails
Guardrails apply to Agents and Agent Templates, enforcing input and output policy on every interaction by blocking, rewriting, warning, or logging before content reaches users or leaves the platform.
04Version control
Every resource on Opal is versioned. Changes are tracked across a clear history so teams can understand what changed, when it changed, and by whom.
05Draft and publishing workflow
Resources are edited in draft. Changes are reviewed and approved before they go live. Published versions remain stable and available while drafts are in progress, so teams can develop and test without disrupting active work.
06Activity Log
A comprehensive log records all activity across the organization, including resource creation, edits, configuration changes, access events, and agent interactions. The Activity Log provides the documented audit trail compliance and security teams require.
07Linked resources
Every resource on Opal tracks its dependencies. Before changing an agent, a model, a guardrail, or a knowledge file, teams can see what depends on it, preventing unintended downstream impact and making change management informed.
08Resource tags
Apply custom tags to resources for organization, discoverability, and cross-resource management at scale.
09Variables
API keys, tokens, and configuration values are stored as named, permissioned secrets. Sensitive values are referenced by name and never exposed in the interface after saving.
10Zero data retention
For supported models and providers, zero data retention is applied automatically, so prompts and responses are not stored on model provider infrastructure. No additional configuration is required.