ClientFlowApply for pilot
Open menu

Security

Security architecture for Notion-powered delivery teams.

ClientFlow touches operational Notion workspaces, so security needs to be visible: OAuth lifecycle, encrypted vault storage, tenant isolation, data flow, Delivery Receipts, replay behavior, and the enterprise roadmap.

Current posturePrivate pilot ready

Enterprise procurement items such as SOC 2, data residency, backup policy, and a public status page are roadmap items, not launch claims.

Architecture

How a signed client becomes auditable Notion work.

User

ClientFlow login and dashboard session

OAuth

Bounded Notion workspace authorization

ClientFlow

Tenant validation, mappings, playbooks, preview

Execution

Durable queue and rate-limited worker

Notion

Projects, tasks, owners, dates, recurring deliverables

Replay Queue

Failed-action replay without duplicating completed work

Delivery Receipt

Business-readable evidence of plan, approval, outcome, and blockers

Data flow

Only the data needed to plan, execute, and explain a run.

  1. ConnectUser authorizes a Notion workspace with OAuth.
  2. VaultWorkspace token is encrypted at rest before persistence.
  3. MapClientFlow stores database IDs, role mappings, schema hashes, and watched values.
  4. PreviewPlanner returns simulated project, task, relation, owner, and date changes.
  5. ExecuteWorker writes pages through a per-workspace rate-limited Notion client.
  6. Receipt StoreDelivery Receipts and action records keep success, warnings, failures, blockers, and replay state.

Safeguards

Security controls that match the product's execution model.

OAuth lifecycle

Connect, refresh, revoke, disconnect, and pause dependent rules.

Encrypted vault

Notion OAuth tokens use AES-256-GCM at rest.

Data minimization

Retained workspace content is limited to what operation, recovery, and customer-requested history require.

Tenant isolation

Dashboard reads use tenant scope and RLS; worker jobs verify tenant and workspace IDs.

Rate limits

Per-workspace token buckets honor Notion Retry-After behavior.

Replay safety

Idempotency keys prevent successful actions from being duplicated.

Reliability targets

Operational software needs measurable behavior.

Detection target<5 min P95 status change to execution start

Time to value<20 min guided first successful run

Run reliability target99%+ without unrecoverable error

Receipt retention target90 days of Delivery Receipts on all plans

Enterprise roadmap

What larger buyers will ask before rollout.

These are not required for the first agency wedge, but they are the right path as ClientFlow moves toward larger consultancies and operational teams.

Backups

Database backup and restore policy is an enterprise-readiness item.

Disaster recovery

Durable queues and idempotent replay reduce accepted-run loss after crashes.

Data residency

Regional residency options are roadmap items for larger buyers.

Incident response

Public incident process and customer notification policy are planned.

Status page

A public status page belongs with the first larger customer rollouts.

SOC 2 roadmap

Controls, evidence collection, vendor review, and audit readiness are the path.