Trust · Your team
Using Scopebond with your employees
Scopebond records what coding agents do on your team's computers, and those records can identify people. This page says what is recorded, who sees it, how long it is kept, what Scopebond is not for, and what you need to do as the employer. A DPIA template and a one-page works-council summary are at the end.
Under data protection law your organization is the controller of what Scopebond records about your staff and contractors, and Avouro LLC is your processor. Our Data Processing Agreement sets out both roles. This page is information to help you meet your duties; it is not legal advice.
What is recorded
The Scopebond hook runs on a computer next to a coding agent such as Claude Code, Cursor or Codex. For each action the agent asks to take, it checks your rules, signs a record of what was asked and what was decided, and sends that record to your workspace. A record can contain:
- The computer's name, as the operating system reports it when the computer connects. It is often a person's name.
- File paths and the working folder, which can contain an operating-system user name, for example as the name of a home folder.
- The first 64 characters of a command, after common secret shapes are removed on the computer, with a fingerprint of the whole command. Secret removal is best effort, so a secret typed into a command can still be recorded.
- Git remotes, network hosts and web addresses the agent uses, with secret-like values removed.
- MCP server and tool names. Tool arguments are kept only as a fingerprint.
- The time, the agent, the rule that applied and the decision.
- Reasons people type when they ask for or approve an override, and the name and email address of the workspace members involved.
Scopebond does not record file contents, prompts, the agent's answers, keystrokes, screenshots, screen time or activity outside the agent's actions. The operating-system user who approves an override on a computer is kept only as a fingerprint.
With the default evidence detail, notable actions, such as blocked ones, are recorded in full and routine actions as one signed summary every five minutes. Full detail records every action; it is available on Team and above, lasts 30 days at a time, and each change is written to the workspace's audit log.
Who sees per-person data
Only members of your workspace see its records, in the role you give them:
| Role | What they see |
|---|---|
| Owner | Everything in the workspace, including members, each person's computers, the audit log, billing and deletion. |
| Admin | Everything an owner sees except owner-only rights. |
| Reviewer | All records exactly as signed; can review approvals and export. |
| Viewer | All records, read-only, with secret-like values in record details masked again. |
| Scoped member | Only the environments granted to them, with the same masking as a viewer. |
Alerts and exports go only where your admins send them: email to members, Slack or a webhook. Avouro staff access workspace data only to operate, secure and support the service, as the Data Processing Agreement sets out.
How long it is kept
- Records are listed in Activity for your plan's retention period: 30 days on Free, 90 days on Team, one year on Business, or as agreed for Enterprise. Then they leave Activity.
- The full signed records stay in the workspace's evidence segments until the workspace is deleted.
- A deleted workspace can be restored for 7 days; then it is purged, evidence segments included. Encrypted backups roll off within 30 days.
The Privacy Policy has the full list.
What Scopebond is not for
Scopebond is for governing coding agents and keeping evidence of what they did. It is not for evaluating people.
- It has no per-person productivity score or ranking.
- Do not use it to measure performance, productivity, working time or behaviour, or as the basis of decisions about someone's employment. Our Terms and Data Processing Agreement exclude that use.
- A record shows what an agent was asked to do on a computer and what Scopebond decided. It does not show who was at the keyboard, why, or how well they work.
Your duties as the employer
Avouro does not monitor how you use Scopebond beyond operating and securing it, and does not check these steps. They are yours:
- Tell your people. Before you connect their computers, tell staff and contractors what Scopebond records, why, who sees it, how long it is kept and how to exercise their rights (GDPR Articles 13 and 14). Some US states also require written notice of electronic monitoring, such as New York, Connecticut and Delaware.
- Choose a lawful basis. For most employers it is a legitimate interest in securing systems and code (GDPR Article 6(1)(f)), with a balancing test. Consent is rarely valid in employment.
- Assess the risk. Systematic monitoring of employees' tools usually calls for a data protection impact assessment (GDPR Article 35). The template below covers the questions.
- Involve employee representatives where the law requires it. In Germany, introducing a technical system able to monitor employees' behaviour or performance needs the works council's co-determination under section 87(1) no. 6 of the Works Constitution Act (BetrVG), usually as a works agreement. In France, the social and economic committee (CSE) must be informed and consulted first. In the Netherlands, the works council's consent is needed for a system that can monitor staff (Works Councils Act, article 27). Other countries have similar rules; check local law.
- Follow employment law where you employ people, including national rules under GDPR Article 88 and, in the UK, the Information Commissioner's guidance on monitoring workers.
- Choose the right region when you create a workspace. Organizations in the EU/EEA, the UK or Switzerland should choose the European Union region; today workspaces are created in the United States, and the European Union region opens soon. The choice is yours and cannot be changed later.
Your controls
- Evidence detail. Keep the default, which sends routine actions as summaries, and turn on full detail only for a limited time.
- Roles and masking. Give people who do not need full record details the viewer role, which masks secret-like values again, and limit scoped members to the environments they need.
- Records on the computer. Set how long records are kept on each computer before they are removed there.
- Rules. Decide which actions are checked and which are blocked, monitored or allowed.
- Retention. Choose the plan whose retention fits your purpose, and delete a workspace you no longer need.
- Region. Choose the workspace's region when you create it.
- Access requests. Owners and admins can export the audit log and, on plans with exports, evidence segments, to answer a person's request. Each person can download their own account data in Settings.
DPIA template
Copy these headings into your own DPIA document and answer each prompt. The facts on this page and in the Data Processing Agreement's Annexes I and II answer most of the description.
1. Description of the processing
- Purpose: which agent risks are you governing, and what evidence do you need to keep?
- Scope: which teams, computers and coding agents are connected, and in which workspace and region?
- Data: which of the items under "What is recorded" apply, and at which evidence detail?
- People: whose computers are connected (employees, contractors, others), and who has which workspace role?
- Recipients: alert destinations, exports, Avouro as processor and its sub-processors.
- Retention: your plan's period, and when you will delete the workspace.
2. Necessity and proportionality
- Lawful basis and, for legitimate interest, the balancing test.
- Why governing agents needs records that can identify a person, and what you do to keep that to a minimum (roles, evidence detail, retention).
- How staff are informed, and how they exercise access, objection and other rights.
- The written rule that the records are not used to evaluate individual performance or behaviour.
- Transfers outside your country and their safeguards (the Data Processing Agreement, section 11).
3. Risks to the people concerned
- Records used for something other than agent governance, such as judging people's work.
- Too many people seeing per-person records, or seeing them longer than needed.
- Secrets or personal data in commands, paths or web addresses that removal on the computer misses.
- A feeling of being watched, and its effect on trust and on how people work.
- Unauthorized access or a breach at your organization, at Avouro or at a sub-processor.
4. Measures to address the risks
- Purpose limitation in a policy or works agreement, and who may look at records and when.
- Role assignments, default evidence detail, and the retention period.
- Telling people not to type secrets into commands, paths or tool arguments.
- Periodic review of access, alert destinations and exports.
- Avouro's measures (Data Processing Agreement, Annex II) and its breach notice to you.
5. Consultation and sign-off
- Advice of your data protection officer, if you have one.
- The views of staff or their representatives, and the works-council outcome.
- Residual risk, and whether prior consultation with your supervisory authority is needed (GDPR Article 36).
- Who approved the assessment, the date, and when you will review it.
Works-council summary
A one-page summary to share with your works council or employee representatives.
| What it is | Scopebond checks the actions of AI coding agents against the company's rules, blocks actions that break them, and keeps a signed record of what was asked and what was decided. It is supplied by Avouro LLC (Michigan, USA) as the company's processor. |
| Purpose | Protecting systems and code from unsafe agent actions, and keeping evidence of what agents did. Not performance or behaviour evaluation. |
| What is recorded | For each agent action: computer name, file paths and working folder (which can contain a user name), the first 64 characters of the command after secret removal, git remotes, network hosts, MCP tool names, time, rule and decision; override reasons and the members involved. |
| What is not recorded | File contents, prompts, the agent's answers, keystrokes, screenshots, screen time, and anything the agent does not ask to do. |
| Who sees it | Workspace members in the roles the company assigns (owner, admin, reviewer, viewer, scoped member); alert recipients the company chooses; Avouro only to operate and secure the service. |
| How long | Listed for the plan's retention period (30 days to one year); signed evidence until the workspace is deleted; backups 30 days. |
| Points for a works agreement | Purpose limited to agent governance and security; no use for evaluating individual performance or behaviour; the roles allowed to see records; the evidence detail level and when full detail may be switched on; the retention period; use of records about a person only to investigate a security incident, with the works council informed; how staff are informed; a review date. |