Skip to main content
This page covers the parts of the platform’s shape that affect how you build on it: the isolation boundary, retention, hosting and delivery guarantees.

The account is the boundary

The account is the unit of tenancy. Users, Spaces, assistants, flows, credits and storage all belong to exactly one account, and data is isolated per account — one account’s data is not reachable from another. Credentials are account-scoped rather than global: a user signs in to a specific account by name, and the same email address can hold a login on more than one account. Use separate accounts where you want a hard separation — different environments, or different parts of the business that should not see each other’s work.

Roles and permissions

How access is divided inside an account →

Delivery is at-least-once

Work is dispatched with acknowledgement and redelivery, which means a step can be delivered more than once — for example if it times out and is retried.
Design flow steps to be idempotent. A step that charges a card, sends an email or appends a row should be safe to run twice, or should check whether it already ran.

Retention

Two separate clocks: Set the retention period under Account → Data Retention. Abbie’s run traces are readable in the app under Abbie → Logs while they are within the 7-day window.

Plans & pricing

Retention ceilings, credits and storage by plan →

Hosting

New accounts choose how their data is hosted before they start. Today that is a single region — Europe — and a choice of 1 or 3 nodes. Running across 3 regions uses 3× the storage. The choice is not tied to your plan.

Connecting programmatically

API access uses API keys, which you create in personal Settings under API keys. Keys can be scoped to a single user or to the whole account, and can be restricted to specific endpoints.
An account-scoped key acts for the account rather than for one person, so its blast radius is much larger than a user-scoped key’s. Prefer user scope unless you genuinely need account scope.
There is no audit log of API usage — key usage is not recorded anywhere you can review after the fact. Treat key rotation and narrow scoping as the control.

API keys

Creating, scoping, restricting and expiring keys →

Security

Traffic is encrypted in transit, with TLS 1.2 as the floor. Sign-in supports passwords, passkeys, an authenticator app, Google and GitHub. There is no SSO, SAML, SCIM or IP allowlisting — don’t plan an integration around them.

Security overview

Authentication, sessions and what we do and don’t hold →

Next steps

Flows overview

Triggers, steps and flow automation

Core concepts

Abbie, Spaces, assistants and flows