STRAZAdocs

FAQ

Short answers to the questions people ask first about Straza, each with a link to the page that covers its topic.

On this page

These are the questions people ask first about Straza. Each answer is short and links the page that covers the topic in full.

AI inside Straza

There is no AI inside Straza. Every decision is deterministic policy evaluation over a signed snapshot, as Policies describes. The optional classifier is a fixed heuristic with no model, no network and no state. The sentinel is rule-based detection. It runs after the fact and blocks nothing. No AI in the product gives the reasons, starting with why model traffic is never proxied.

When strazad is down

Nothing fails open. In the enterprise profile, governed actions are denied once the cached session token expires, at most five minutes after it was minted, because the grace period is zero. The standalone profile adds 15 minutes of grace. A decision that needs the server, such as an approval, is denied within 2 seconds with a reason that says the security layer is unreachable.

Working offline shows the deny an agent reads when the grace runs out. Lifetimes and timeouts lists every bound in one table.

Straza and your identity manager

Your identity manager stays the source of who exists, which roles they hold and who sponsors each AI agent. Straza receives that over SCIM 2.0 and turns it into decisions at every action. A role assignment reaches a running agent at its next check-in, and a deactivation revokes the user’s sessions.

Identities and roles explains why the identity manager stays the master. Connect identity connects midPoint, Okta or another SCIM client, with a guide for each.

Prompts and model outputs

Straza does not filter prompts or model outputs. It decides what an agent does, the tool calls and commands, and it never sits on the wire between the agent and its model. When a policy set turns on recording, the conversation is recorded for audit, word for word or with secrets masked, and the model’s traffic is still never filtered or rewritten.

Record a conversation turns recording on. What Straza does not try to do lists the other non-goals.

Data that leaves your infrastructure

Decisions happen on the agent’s machine or on your strazad. strazad and its clients send no usage data, and none of them checks for updates. Beyond that, what leaves is what your configuration turns on. A Slack approval card carries the requester, the action and the redacted call preview to Slack, as Slack shows.

A phone push travels through Apple’s or Google’s push service, a WebPush or ntfy host you allow, or the Straza relay at push.straza.ai, as an envelope with no content. The relay is off for strazad on its own. The Helm chart, the compose template and the demo stack turn it on, and The hosted relay says what it receives. Outbound connections lists every destination strazad dials and how to turn the relay off.

Search documentation

Search page titles, commands, and article text.

↑ ↓ Choose resultEnter OpenEsc Close