GroveDeck Contact

Learner data stays in your system.

How our AI agents access your Cornerstone system, how we handle data, how the Safe Change Framework works and how we fit inside your security controls.

Access you control.

You provision our access. You define the scope. You revoke it in a click.

  • Nothing new to log into. There’s no GroveDeck account, app or dashboard for your team to manage.
  • You revoke it in a click. Our access lives in your Cornerstone system, so you remove it the same way you remove anyone’s. Once it’s off, all our work in your system stops, the agents’ included.
  • You set up our access yourself. Your team creates two things in your own Cornerstone system: API credentials, used wherever the API covers the task, and an admin account for GroveDeck for the rest. Both are limited to the work you’ve agreed.
  • Only the access the work needs. We ask for access to the parts of your Cornerstone system our work touches, and nothing more.
  • No shared passwords. We sign in only with the account and API credentials you create for us, and you revoke both in your own system.
  • We follow your security rules. Our accounts show up in your own access reviews like anyone else’s. We work inside Cornerstone’s own access controls, and nothing we do requires getting around them.

What the agents read. What we keep.

Your training records and learner data stay in your Cornerstone system. The agents read what they need, and Certified Cornerstone Experts approve every change.

  • Read-only, in the moment.

    The agents read configuration, permissions, org structure, learning assignments, data feeds and reports only when the work needs it, read-only wherever the API covers it. Home address, personal contact details, birth date and government ID numbers are removed from what they see, and they keep no copy of learner data. Certified Cornerstone Experts approve any fix.

  • Never training input.

    The agents use AI. Nothing they read in your system becomes training input for any external model.

  • What we keep.

    Written runbooks, configuration notes and the change log for your organization, held on GroveDeck systems. They record how your platform is set up and why, not learner records. They’re used only for you, never train a model, and go to you in full if you leave. We delete our copies within 90 days of handover.

The Safe Change Framework.

Every action our agents take is sorted into one of three tiers before it runs, and Certified Cornerstone Experts own the result.

  1. Observe.

    Read-only checks and scheduled reports. Run automatically, fully logged.

    Runs automatically

  2. Change.

    Any edit to your live system. The agents prepare it and write up the reasoning; Certified Cornerstone Experts approve it inside the limits you set.

    Experts approve

  3. Escalate.

    New permissions, mass edits to training records, anything touching personal data or outside your signed scope. Your named owner approves first, then our Experts.

    Your owner, then our Experts

A human in the loop on every change. Nothing reaches your live platform without a person approving that specific change.

The people behind the agents. Certified Cornerstone Experts. Cornerstone is all we do, and has been for more than ten years. Our Experts approve every change and reply within one business day.

  • The agents watch 24/7. Changes land in business hours.

    The agents watch your system 24/7. Certified Cornerstone Experts approve during business hours (US Eastern), so that’s when changes reach your live system. The agents honor the blackout windows you set.

  • Every change on the record.

    Who requested it, what the agents prepared, who approved it, when, before and after, and whether it can be rolled back. You receive the log as a weekly digest and as an export whenever you ask.

Compliance posture.

  • NDA and Data Processing Agreement signed before access is provisioned.
  • For UK and EU clients, GDPR terms are set out in the DPA. GroveDeck data resides in the United States.
  • Handling that accounts for CCPA and other state privacy laws for US clients.
  • Cornerstone’s own data controls remain authoritative. We don’t override system-level privacy settings.

AI governance.

The agents use AI to read your system, watch for drift, flag what’s worth changing and prepare the change. Certified Cornerstone Experts approve each one. The agents operate inside the guardrails your security and HR teams have already set and take instructions only from us. Requests come to us by email. The agents work inside your organization’s AI policy, and we confirm how in writing.

If you have a formal AI use policy for third-party vendors, we review it before engagement.

Questions? Answers.

Does your AI train on our system data?

No. Nothing the agents read in your environment is training input for any external model. We provide this in writing if procurement requires it.

Can the agents change our system on their own?

No. The agents prepare changes. Certified Cornerstone Experts approve each one. Escalate items and anything outside the scope you signed go to your named owner first. Nothing reaches your live platform without a person approving that specific change. Every executed change is logged and the log is yours. See how we work.

What happens to our access when we leave?

You deprovision it through your own Cornerstone system controls. No standing access remains once you revoke it, and we confirm that in writing. You receive the full change log, runbooks and configuration notes in a readable format, and we delete our copies within 90 days.

Do you sign our NDA and DPA?

Yes. Before anyone logs in. If you have a vendor-specific template, send it to hello@grovedeck.com and we’ll review it.

Send us your requirements.

Running a vendor security review? Send us what your team needs. Certified Cornerstone Experts reply within one business day.

Prefer email? hello@grovedeck.com

Formal documentsNDA, DPA and AI usage statement
ReplyWithin one business day
CommitmentMonth to month, no multi‑year contract
Send us your requirements