Security & governance

In brief

AskMarcel separates document lookup (v1/v2/MCP) from logged guided diagnostics (Harness Beta). The technician stays accountable; the API traces assumptions without job-site PII in public docs.

Technician role (actor_profile)

actor_profile and qualified_technician on Harness Beta sessions are product-surface assumptions — not proof of F-Gas or electrical licensing. Your stack must still carry real identity, certifications and field permissions.

  • Never infer regulatory clearance from an API boolean
  • Log who started the session on your CMMS side (tech ID)
  • Escalate to a lead when procedure safety_level = high

Risky actions & allowlist

Harness Beta does not execute physical actions — it returns sourced steps. Refrigerant work, mains isolation or board swaps stay human-controlled.

  • Beta brand/family allowlist — not the 400k+ global lookup corpus
  • Explicit abstention when no exact OEM source (v2 / strict source policy)
  • Session stop: session_closed status; a resumed session uses the current Beta pack

Audit trail

Each Harness turn emits timestamped session_events. The manufacturer lookup obtained at start is journaled; Beta packs remain mutable and a resumed session uses current pack content. REST/MCP calls are server-logged (route, latency, key) without publishing full client bodies in docs.

  • request_id / session_id on v2 responses for support correlation
  • Diagnostic provenance: chunk_id, document_id, page_start when sourced
  • Revoke keys instantly from /developers if leaked

GDPR & data

Public examples use fictional or anonymised fault codes and brands — never customer address, job name or phone.

  • Do not send job-site PII in symptom or user message fields
  • Email watermark on PDF snapshots for traceability
  • Access / erasure requests via the Support page

Create my key →

Create my key →