An AI that can publish needs a permission model, not a promise.

Every assistant gets the role the person already has, every scope is readable before approval, and nothing publishes until a person fires it.

An assistant gets the role the person already has

You are being asked to approve a tool an LLM can drive. What decides your answer is what that assistant can read the moment someone connects it, and whose permissions it is reading with. The learning surface your people would otherwise reach ungoverned is role-scoped, admin-gated and logged.

  • Role-scoped access

    Access over MCP is granted only to the data the person's Juno role already permits.

  • No new data categories

    Connecting over MCP does not open up new categories of data.

  • Unpermitted tools stay hidden

    Tools a person is not permitted to use do not appear to their assistant.

  • Sub-processors, by name

    OpenAI, Datadog, SendGrid, Google Cloud and MongoDB are named on our Trust Center.

  • The AI record

    Our Trust Center publishes AI training data and bias, AI security, and employee AI usage.

  • Read, then stop

    An assistant can read within that role and prepare work. Firing it is covered under Approval below.

Every prompt we publish tells the assistant to ask first, preview, and wait for a person: read them all at /prompts.

The AI record on our Trust Center

Delegate identity to the provider you already run

Identity and access is the first section of your questionnaire and the fastest place to reject a vendor. Juno delegates sign-in, provisioning and deprovisioning to the directory you already operate. What follows is the posture; the setup fields live on the integrations page.

  • SAML 2.0 single sign-on

    Okta, Microsoft Entra, Google, and any SAML 2.0 compliant provider.

  • Directory sync

    Your HRIS or HCM syncs over SCIM, on a schedule, with sync logs.

  • Domain-gated provisioning

    Auto-provisioning is gated on the email domains you allow.

  • Deprovisioning follows the directory

    Remove someone in your directory and their Juno access goes with them.

  • No passwords stored

    Juno never sees or stores your users' passwords for any integrated service.

  • The setup itself

    Entry point, certificate, issuer, callback URL and attribute mapping are on the integrations page.

Integrations

Read the scopes before you approve them

A consent screen gets approved somewhere in your company every quarter, usually by someone who cannot read what it grants. Our own documentation publishes, for every integration, what it does, who consents, and the auth model. The negative half is published too, and that is the half nobody publishes.

SlackSlack is requesting permission

Juno Journey

Requested by a workspace admin

WorkspaceNorthstar

This app will be able to

  • users:read, users:read.emailMatch Juno learners to their Slack accounts by email address
  • im:writeOpen a direct message conversation with a learner
  • chat:writeSend notification messages
  • chat:write.publicPost shared content into public channels without being invited to each one
  • channels:read, groups:readList channels so admins can link a Juno channel to a Slack channel
AllowCancel

Revoking access

Remove the Juno app under Slack admin · Manage apps, or disconnect Slack in Juno's admin integration settings.

Google Calendar
What it does Room booking and Juno-managed event invites
Who consents Google Workspace admin
Auth model Admin OAuth consent + service account with domain-wide delegation
Outlook Calendar
What it does Room booking and event calendar sync
Who consents Microsoft Entra admin
Auth model Admin OAuth consent (Microsoft Graph)
Zoom
What it does Create meetings for events, attendance, recordings
Who consents Meeting organizer (per user)
Auth model OAuth 2.0, Zoom Marketplace app
Microsoft Teams meetings
What it does Create Teams meetings for events, attendance, recordings
Who consents Meeting organizer (per user)
Auth model OAuth 2.0 delegated (Microsoft Graph)
Google Meet
What it does Create Meet links for events, attendance
Who consents Meeting organizer; optional org-level reports grant
Auth model OAuth 2.0; optional service account with domain-wide delegation
Slack
What it does Deliver Juno notifications in Slack
Who consents Slack workspace admin
Auth model Slack app with bot token
Microsoft Teams notifications
What it does Deliver Juno notifications in Teams
Who consents Teams admin (app approval)
Auth model Bot Framework app
Email, SMS and push
What it does Deliver notifications outside chat tools
Who consents No org consent needed (Juno-operated)
Auth model Juno-managed provider accounts
  • Least privilege

    Juno requests only the scopes each feature needs, and optional features use separate, optional scopes.

  • Credentials encrypted

    OAuth tokens and API credentials are encrypted before storage and are never exposed to the browser or client apps.

  • Revocable at any time

    Every integration can be disconnected from Juno or revoked from the provider's admin console, with revocation steps on each page.

  • Tenant isolation

    Credentials and synced data are scoped to your organization and are never shared across Juno customers.

  • The application is named

    The consent screen names the requesting application, and the connection is revocable from the client that holds it.

  • No message history

    Juno has no message-history scopes. It cannot read your workspace's messages, files, or conversations. It only sends.

  • No tenant access from Teams

    Teams notifications request no Microsoft Graph API scopes and have no access to your tenant's data.

  • Calendars, bounded

    Juno does not read email, contacts, files, or the content of events it did not create.

Confine an admin to one area, and keep the record

A new platform usually arrives with a new set of administrators who can see everything inside it. Juno's roles are scoped by domain, so an administrator can be given one area and no others. What any of them does is on the record.

  • Domains, named

    Roles scope to People, Content, Budget, Development, Engagement, Events, Channels, Company Automations and Platform.

  • The resolution rule

    Your effective access in a given area is the higher of your base role and your domain role for that area.

  • Blocked

    A blocked user can authenticate and sees no content.

  • Scoped admin roles

    Content Admin and Super Admin are documented roles, each bounded by the domains it holds.

  • The audit trail

    View the system audit trail: who did what, when, filtered by action, user or date.

Roles and permissions

Nothing publishes or assigns until a person confirms

The row that did not exist two years ago is the one your board now asks about every quarter. Here is the mechanism, in the order it runs. An LLM connected to Juno reads inside one person's permissions and prepares the work; a person fires it, on a card that shows what is about to happen.

  • The approval card

    Every write action shows an approval card, and nothing is executed until you confirm.

  • The audience, resolved

    The card shows the number of learners, a sample of names and any filters applied, and it is editable before you approve it.

  • Automations start paused

    All automations are created paused, with a one-click Enable so you can review the rule before it goes live.

  • Refusals name the gap

    A refused action returns a blocked card explaining what permission is needed.

  • Drafts stay invisible

    Drafts stay invisible to learners until you publish them.

  • High-impact actions, named

    Publishing, assigning and notifying learners are named as high-impact actions to review before you confirm.

  • Prompt injection, named

    Our own documentation tells you to be mindful of prompt-injection risk when an assistant processes untrusted content.

  • The audience is shown, count and a named sample, before anything sends

  • Every send fires from a card a person confirms

  • Read-only until each action is approved

  • Every save keeps the previous version restorable

  • An assistant that cannot read a number says "not measured"

Juno MCP

Read with

Two pages next to this one, and one of them is about a different subject entirely.

  • IntegrationsThe per-integration mechanics, the field-level setup and the exact permission strings.
  • Cybersecurity & PrivacyTraining your people on security and privacy obligations is a different page from how Juno secures your data.

Questions people ask.

What is Juno's certification and compliance status?

Juno is ISO/IEC 27001 certified; our Trust Center also lists GDPR and CCPA under compliance. The ISO/IEC 27001 certificate is available on request through the same page. A penetration test report and a network diagram are available on request as well. SecurityScorecard grades Juno A. The page carries the date it was last reviewed.

Which model provider processes our data, and what does the assistant see?

OpenAI is named as a sub-processor on our Trust Center, alongside Datadog, SendGrid, Google Cloud and MongoDB. An assistant connected over MCP reaches only the data the person's Juno role already permits. Connecting does not open new categories of data, and tools that person cannot use do not appear.

Which identity providers do you support, and how is provisioning handled?

Juno supports SAML 2.0 single sign-on with Okta, Microsoft Entra, Google and any SAML 2.0 compliant provider. Your HRIS or HCM syncs over SCIM on a schedule, with sync logs. Auto-provisioning is gated on the email domains you allow, and Juno never stores your users' passwords for integrated services.

Can we limit an administrator to one area?

Yes. Roles scope by domain, so an administrator can hold People and nothing else. The domains are People, Content, Budget, Development, Engagement, Events, Channels, Company Automations and Platform. Effective access in an area is the higher of the base role and the domain role. A blocked user authenticates and sees no content.

What does each connector access, and who approves it?

Each integration is published with what it does, who consents and the auth model, and the consenting party is named exactly: a Google Workspace admin, a Slack workspace admin, or the meeting organizer for calendars. Juno requests only the scopes a feature needs, and each documentation page lists the exact permission strings.

What can the AI do without a human?

It can read within the permissions of the person who connected it, and it can prepare work. Finishing the work is a separate step that belongs to a person. Every write action stops at an approval card that resolves the audience and can be edited, and nothing runs until a person confirms. Automations are created paused.

How do we revoke access?

Every integration can be disconnected from Juno or revoked from the provider's own admin console, and each documentation page carries the revocation steps. An MCP connection is revocable from the client that holds it. Removing someone in your directory removes their access, because provisioning follows the directory.

Where are the documents, and who can we talk to?

The penetration test report, the network diagram and the ISO/IEC 27001 certificate sit behind a request on our Trust Center, which is also where the sub-processor list and the control families are published. If a questionnaire row is not answered there, request the document on the Trust Center or book a demo.

How is Juno priced?

Pricing is published on the pricing page.