Skip to content
Flexday AI Docs

Governance

Data lifecycle and portability

How data is created, used, shared, retained and deleted in Flexday AI, and how Solutions move between workspaces without carrying secrets.

Written for
  • Everyone

Last reviewed

Data in Flexday AI lives inside a Solution from the moment it arrives. It is used under roles, grants and audience tags, shared through Templates or export bundles that never carry secrets, kept according to retention rules, and deleted in a known order when the Solution goes.

At a glance

  • Everything has an owner. Every resource, file and document belongs to one Solution or Template; the audit trail and usage history belong to the workspace.
  • Sharing never leaks credentials. Templates, clones, exports and imports carry names and settings, never secrets.
  • Import always creates something new. An import never merges into or overwrites an existing Solution.
  • Retention runs on a schedule. File Stores that set a retention window or a version limit are cleaned up every hour; by default deleted files and old versions are kept.
  • Deletion is ordered. Deleting a Solution removes what it owns, step by step; the audit trail and the file access log are kept.
Five steps: Create, Use, Share, Retain, Delete
Figure: the data lifecycle.

Create and use

Data arrives by upload in Studio, by the Builder from your chat attachments, through a Flow (a webhook, a query step, a file fetch), or from a generated app through the gateway. From then on, access to it follows the Solution's roles and grants, Fact Base roles and row policies, audience tags and Agent grants. See Data isolation.

Share

RouteBest forWhat travels
TemplateA reusable starting point many people will useIts resources (an Identity only when it uses Basic credentials); Fact Base rows kept or left out, one choice for all of them; apps in draft; Flows and Agents unpublished; Connections and Secret Variables as empty shells. A Solution started from it gets its read endpoints back, while endpoints for Flows, Agents and files are added again.
Solution exportMoving or backing up one SolutionEvery resource, always; Fact Base rows, documents, files and run history, each ticked on its own; non-secret Variable values; no secrets
Fact Base, Flow or Agent exportMoving one resourceThe resource and its requirements; the Fact Base arrives unprovisioned

Export and import in detail

  1. Export. On the Solution's Exports view, choose the data. Linked choices lock on and say why (documents need their files). A background job writes one bundle file to a File Store you pick.
  2. Import. From the Solutions list, upload the bundle or pick it from a File Store. You see where it came from and what it carries first.
  3. The new Solution. Every ID is new and every internal reference is remapped. Flows arrive switched off, Bots unregistered, and webhook Flows with a new address and signing secret. A Flow step that called one of the Solution's own gateways by its full web address now calls the new copy; the import report names any it could not repoint.
  4. Finish setting up. The import report lists every credential to re-enter, every Variable to fill in, and anything the bundle referred to but did not carry.

A bundle records its format, and a bundle that needs a feature an older release cannot read is refused before anything is created. An import that fails with an error removes what it created; if the service running it stops partway, a partly created Solution can be left behind to delete.

Retain

DataRule
File versionsKept, unless the store sets a version limit: then older versions lose their bytes, and their history stays.
Deleted filesKept, unless the store sets a retention window: then they are deleted for good after it. A file a document still uses is skipped.
File access logKept for the workspace's retention window (30 days by default).
Stored form submissionsRemoved after the workspace's retention window.
Resource versionsKept until their resource is deleted.
Conversations and run historyKept until their Agent, Flow, Solution or workspace is deleted.
Audit trailKept until the workspace is purged.
Staged import bundlesKept 24 hours, then removed.

Delete

Deleting a Solution is irreversible. It runs step by step: Flow runs are cancelled, Agent sessions ended, managed Teams Bots unregistered, document indexes and files deleted, the Solution and its records removed, and then its Fact Base schemas and app files dropped. Each step runs even if an earlier one fails. The audit trail and the file access log are kept.

An owner can offboard a whole workspace. Access stops, running work is cancelled and a final export is made; after the workspace's retention window, during which it can be restored, the workspace is purged, its audit trail last, and its encryption key is destroyed. See Portability and exit.

Limits

AreaLimit
Export bundle and staged uploadUp to 5 GB (100 MB through the fallback upload)
Unpacked bundleUp to 50 GiB and 200,000 entries
Concurrent importsUp to 3 staged or running per workspace
StoragePer workspace, shared by files and Fact Base data, set by your plan

What an evaluator can verify

To confirmWhere to look in a trial
What an export carriesA Solution's Exports tab: choose the data to include; choices that depend on each other say why. The bundle is written to a File Store you pick.
That an import is always new, and leaves secrets behindImport the bundle from the Solutions list: it creates a new Solution, and the import report lists every credential to re-enter and every Variable to fill in.
How long files are keptA File Store's Settings: Versions kept and Retention (days).
That deletion removes what a Solution ownsDelete a test Solution, then confirm that its apps, datasets, documents and files are gone from every list.
The Export a working copy page of the Service Desk Copilot Solution: what the bundle carries, the note that credentials stay behind and secret values do not travel, and the data to include, with Fact Bases, Doc Bases and the File Store they need ticked
Notice what the export screen says before anything is written: every resource travels, credentials stay behind, and a choice another depends on is locked, with its reason.
The Settings tab of the IT knowledge DOCS filestore: its policy fields for a per-file size cap, accepted and rejected types, versions kept and retention in days, all left empty, with what each field means
Notice the two retention fields left empty, the default: every version keeps its bytes, and a deleted file is kept until a retention window is set.