Enterprise Security and Governance
Haystack Enterprise Platform is built for teams that need clear boundaries between organizations, workspaces, and users, and who need to explain where data goes and who can change production pipelines. Read this overview to learn about the platform's security and governance features.
Identity and Access
Haystack Enterprise Platform uses role-based access control (RBAC), and preset and custom roles. For details, see User Roles and Permissions.
Organization admins can configure single sign-on (SSO) with common identity providers (Google Workspace, Okta, generic OpenID Connect (OIDC), generic SAML). For setup and troubleshooting, see Enable Single Sign-On (SSO) and Manage an SSO Connection.
Secrets and Credentials
Secrets and integrations store provider credentials, so that you can easily add them to your pipelines without passing API keys. You can scope secrets to specific workspaces or organizations. For details, see Secrets and Integrations. For instructions on how to add them, see Add Secrets and Add Integrations.
Data Isolation and Privacy
To understand upload paths, indexing, search, and optional calls to hosted models, check Data Flow in Haystack Enterprise Platform. To learn about the privacy implications of storage, retention, and model providers, see Data Privacy and LLM Providers.
To connect your own S3 bucket or OpenSearch cluster, follow the instructions in Connect Your Own File Storage.
Operational Records
Haystack Platform stores search history, pipeline traces, and pipeline logs for troubleshooting and review. How long we keep each type (including trace expiry) is in the FAQ What's the Retention Policy for Search History and Pipeline Logs?. To inspect traces in the UI, see Trace Your Pipelines in the UI.
Related Information
Was this page helpful?