Security & governance
In brief
AskMarcel separates document lookup (v1/v2/MCP) from logged guided diagnostics (Harness Beta). The technician stays accountable; the API traces assumptions without job-site PII in public docs.
Technician role (actor_profile)
actor_profile and qualified_technician on Harness Beta sessions are product-surface assumptions — not proof of F-Gas or electrical licensing. Your stack must still carry real identity, certifications and field permissions.
- Never infer regulatory clearance from an API boolean
- Log who started the session on your CMMS side (tech ID)
- Escalate to a lead when procedure safety_level = high
Risky actions & allowlist
Harness Beta does not execute physical actions — it returns sourced steps. Refrigerant work, mains isolation or board swaps stay human-controlled.
- Beta brand/family allowlist — not the 400k+ global lookup corpus
- Explicit abstention when no exact OEM source (v2 / strict source policy)
- Session stop: session_closed status; a resumed session uses the current Beta pack
Audit trail
Each Harness turn emits timestamped session_events. The manufacturer lookup obtained at start is journaled; Beta packs remain mutable and a resumed session uses current pack content. REST/MCP calls are server-logged (route, latency, key) without publishing full client bodies in docs.
- request_id / session_id on v2 responses for support correlation
- Diagnostic provenance: chunk_id, document_id, page_start when sourced
- Revoke keys instantly from /developers if leaked
GDPR & data
Public examples use fictional or anonymised fault codes and brands — never customer address, job name or phone.
- Do not send job-site PII in symptom or user message fields
- Email watermark on PDF snapshots for traceability
- Access / erasure requests via the Support page
Next steps
- API matrix: /api/docs/which-api
- Harness sessions: Beta surfaces in public-surface.json export
- Field service & CMMS: /solutions/hvac-field-service-software
