Scoped access
The customer creates and controls access. Reviews use read-only permissions wherever the system supports them. Access is limited to the named systems and work.
Corbel states the access, data, provider, approval, change, incident, evidence, and exit boundaries before accepting responsibility. Trust is part of the operating design, not a claim added afterward.
This page describes current commitments and current limits. It does not claim a certification or generalized enterprise readiness.
The exact controls are completed against the engagement’s systems, data, workflow risk, and customer requirements before relevant access begins.
The customer creates and controls access. Reviews use read-only permissions wherever the system supports them. Access is limited to the named systems and work.
Each customer receives separate working space and credential handling. Client records, exports, screenshots, prompts, and bespoke artifacts do not move between customers.
Consequential business decisions remain with named people. The workflow states what Corbel may perform, what requires approval, and what must escalate.
Models and providers are disclosed for the engagement. Corbel reviews the applicable privacy, retention, location, and training settings before client data is processed.
A Review does not change the live system. Authorized production work uses documented approval, testing, backup or recovery, rollback, acceptance, and a change record.
Offboarding states what is returned, retained, or deleted; how access is revoked; what documentation transfers; and how completion is confirmed.
Corbel does not sell client data, use it for advertising, or use it to train a general model. The engagement documents define the approved purpose, systems, information, providers, locations, and retention schedule.
Confirm the work, need-to-know access, included and excluded information, approved providers, processing locations, and retention terms.
Use only the information needed for the agreed purpose, keep customer work isolated, and prevent credentials from entering repositories, ordinary email, or working documents.
Return agreed materials, revoke Corbel access, delete or retain information according to the signed schedule, and document the offboarding state.
Corbel currently operates as a scoped service business, not a hosted multi-tenant customer platform. It does not currently claim SOC 2, 24/7 support, blanket regulatory compliance, or generalized enterprise readiness.
Corbel will complete or decline the requirements of a proposed scope before accepting it. A customer should not infer a control, certification, coverage level, or service target that is not written into the engagement.
The engagement names incident contacts, communication requirements, customer decision owners, and the evidence retained for investigation and corrective action.
Stop or limit the affected activity and protect relevant evidence.
Notify the named contacts according to the agreed severity and communication path.
Investigate, recover, document contributing conditions, and track corrective action.
Update the workflow, control, runbook, evaluation, or operating standard when evidence supports a change.
Corbel is operated separately from Parallel Human. The relationship creates no default or implied right to move client information or client-derived patterns across that boundary.
Corbel will defer or decline work when the required access, coverage, jurisdiction, data handling, assurance, staffing, or incident capability is not ready. A sale does not override the operating boundary.
Corbel will identify the access, provider, approval, data, incident, evidence, and exit controls the work requires before deciding whether to proceed.