Evidence-led company researchHuman review before outreach

Security & Data

Inspect provenance, permissions, and review gates before scale

Company intelligence is operationally trustworthy only when a reviewer can trace where a field came from, when it was observed, how it changed, and what the workflow may do next.

Security and data provenance consolenpx -y @okki-global/okki-go-taroball

Fact ledger

Four questions every deployment must answer

Config-dependent

Data provenance

Record the provider, field, source date, permitted purpose, and fallback order. A waterfall can improve fill while making conflicts and deletion requests harder to explain.

Verified practice

Credential handling

Use environment secrets with minimum scope. Keep API keys out of prompts, repositories, shared screenshots, prospect exports, and error reports.

Inspect locally

Runtime behavior

Review package permissions, outbound connections, retries, rate limits, logs, temporary files, and destinations. Installation success does not prove safe configuration.

Config-dependent

Retention and deletion

Specify who can access intermediate and final records, how corrections propagate, when stale data expires, and how suppression or deletion is enforced.

Connection matrix

Follow the data through each runtime stage

The labels below describe evaluation states, not official partnerships. Confirm supported runtimes and providers in current package documentation.

Input sources

Company provider
API credential · least privilege · status: configure and verify
Email verifier
Point-in-time deliverability signal · status: optional
CRM cohort
Known test records · status: reviewer supplied

Research agent

Task brief
Firmographic, technographic, recency, and exclusion criteria
Resolution
Domain and entity comparison with explicit unknown state
Review gate
Named human accepts, corrects, rejects, or withholds action

Output destinations

Preview
Local review surface · no automatic sending
CRM update
Disabled until mapping and rollback are approved
Outreach draft
Separated from send permission and suppression checks

Compare operating models, not badge counts

Evaluation method checked 21 July 2026. Changing vendor facts, pricing, certifications, and integrations must be confirmed from official sources.

DimensionAgent-native researchSeat-based platformReviewer test
Setup pathPackage, runtime, configured sourcesManaged application and accountDocument every required permission
Task modelNatural-language brief with structured outputSaved filters and platform workflowsRun the same known cohort
Source disclosureDepends on configured connector and outputDepends on vendor documentationDemand field-level source and date
Human reviewMust be designed as an explicit gateDepends on team processTrace who approved the next action
Security evidenceInspect package and runtime locallyReview current vendor materialsMark unconfirmed claims Unknown
Deletion controlDepends on every connected storeDepends on vendor and integrationsTest a correction and deletion end to end

Unknown is a valid result. It is safer than turning absent public evidence into a favorable or unfavorable claim.

Run a controlled security review

  1. Copy the exact command and record the package version.
  2. Run in a test environment and inspect the installation prompt.
  3. Configure minimum-scope credentials through a secret store.
  4. Review a known cohort, including an exclusion and an ambiguous identity.
npx -y @okki-global/okki-go-taroball

Do not connect live outreach until provenance, secret handling, access, retention, deletion, suppression, opt-out, and human approval controls have been tested.