# Scout security

> How Scout inherits your permissions, how review works, and how your content is handled.

Source: https://docs.uniform.app/docs/guides/ai/scout/scout-security

Scout is Uniform's AI agent for content authoring. It acts as a human-in-the-loop assistant: it inherits the permissions of the person using it, and every change it makes lands in draft state for review before anything publishes.

## What Scout can and can't do

- Scout has no permissions of its own. It acts as the requesting user and can only see or change what that user can already see or change.
- Scout writes only to draft state. It cannot publish, and it has no access to published content. Workflow stages that auto-publish reject Scout's transitions so a human must perform them.
- Scout can delete entries, compositions, patterns, assets, and content models, but never silently. Pending deletes surface with a distinct treatment and a separate confirm action.
- Deleted entries, compositions, patterns, and assets go to [Trash](https://docs.uniform.app/docs/guides/content-organization/trash) and can be restored for the project's retention period, typically 30 days. Deleting a component definition or content type is permanent.
- We recommend restricting the permissions of the people who use Scout to the entities they need, so a session cannot accidentally delete [content types](https://docs.uniform.app/docs/guides/models/content-types), [component definitions](https://docs.uniform.app/docs/guides/models/components), or [visitor dimensions](https://docs.uniform.app/docs/guides/classification/visitor-dimensions).
- Scout cannot manage users, team settings, or billing, and cannot edit, move, or delete existing project map nodes.
- AI features can be disabled at the team level.
- On the [Enterprise plan](https://uniform.dev/pricing/), you can bring your own OpenAI or Azure OpenAI endpoint and API key to control the model and provider directly.

## Reviewing Scout's changes before they land

- [Review changes](https://docs.uniform.app/docs/guides/ai/scout/using-scout#apply-modes-autonomous-vs-review-changes) is the default apply mode for new threads. Scout stacks edits as [pending edits](https://docs.uniform.app/docs/guides/ai/scout/using-scout#pending-edits-and-review-changes), and nothing changes in your content until you apply them.
- You can switch a thread to Autonomous if you want Scout to apply edits as they work. The choice is a personal preference, not a team policy.

## What happens to your content and prompts

- Uniform opts out of provider-side prompt storage on model calls. OpenAI retains request logs for 30 days for abuse monitoring only, never for training.
- Your content is never used to train Uniform's or any provider's models. This is a contractual commitment in the DPA.
- Chat threads are encrypted and isolated per user and project, and auto-delete one year after last activity. Users can delete them sooner at any time.
- [EU data residency](https://docs.uniform.app/docs/guides/regions) is available for chat storage.

## Guarding against prompt injection

- Scout's instructions and retrieved content are kept in separate channels, so field content is treated as data, not as instructions.
- Content fetched from external URLs is isolated, truncated, and marked as untrusted. Fetching blocks private networks, localhost, and cloud metadata endpoints.
- Scout can only act through a typed, schema-validated set of tools. It cannot take free-form actions. [Connected MCP servers](https://docs.uniform.app/docs/guides/ai/scout/connect-mcp-servers) and integrations add tools that are equally schema-bound.
- AI-generated output is stored as structured data and passes through the same sanitization as human-authored content before it reaches your site.

## Oversight and compliance

- Scout's edits appear in the same content history as manual edits: who changed what, and when.
- Scout is not classified as high-risk under the EU AI Act. It assists with content, not decisions about people.
- Penetration testing covers the AI agentic features. See the [Uniform trust center](https://uniform.dev/trust) for current reports.
- Content created or edited through Scout is yours. Uniform claims no IP rights over it.

## Model providers and sub-processors

- Scout runs on OpenAI's current GPT-class models for generation. Contact the Uniform team for the current model list.
- Supporting infrastructure includes Cloudflare (hosting and chat storage), AWS (backend), and PostHog (privacy-mode telemetry, no prompt content).
- Named sub-processors and their processing regions are published in the [Uniform trust center](https://uniform.dev/trust) and kept current.

> **Note:**
>
> Questions about a specific control or your contract terms? Contact your Uniform account team.
