Security
Security and data flow
For IT and security teams. MX Stage runs only on your PC, and the AI cannot write to Maximo. A write happens only when a person checks the diff in the work screen and presses Commit to Maximo. There is no MX Stage cloud, and your Maximo data never reaches TSUNAGI.
1. Architecture and data flow
AI assistantClaude Desktop, ChatGPT desktop, IBM Bob or another assistant your company has contracted and approved
The user's PC (MX Stage)Bridge: one Node.js process on the PC, listening on 127.0.0.1 only
Work screen: a browser tab (Chrome or Edge) with the sheets, the diff and the commit button
Work screen: a browser tab (Chrome or Edge) with the sheets, the diff and the commit button
Your MaximoJSON API (
/maximo/api) over HTTPS, authenticated with a Maximo API key| Connects to | What flows |
|---|---|
| Your Maximo | Reads, and writes of changes a person approved, directly from the PC (relayed by the bridge). No CORS settings are needed in Maximo. |
| AI assistant | The results of the tools the AI calls (counts, aggregates, and the values of rows the AI reads). This part goes to the AI provider and is covered by your agreement with them. Large changes (rules and matching) run inside the work screen, so those rows never pass through the AI. |
| GitHub, npm (optional) | Only if automatic updates are on (off by default): the latest version number from GitHub, once a day. Installing an update downloads the new version from GitHub and its packages from the npm registry. Nothing about you is sent. |
| Demo data (optional) | Only when you press Download data and connect in Settings → Demo: fictional data (about 10 MB) served by TSUNAGI on Cloudflare, downloaded once. Nothing is sent. |
| TSUNAGI | Nothing is sent. No telemetry. License keys are verified on the PC without contacting us. |
2. Credentials
- The Maximo API key is entered only in the work screen settings. The AI's tools do not accept keys and do not use a key pasted into the chat.
- If you choose "Save on this PC": the bridge encrypts it with AES-256-GCM and protects that key with Windows data protection (DPAPI; only that Windows user can open it). A saved key is not given to the work screen (the browser).
- If you connect without saving: it is kept only in the work screen tab's memory (a Web Worker) and passed to the bridge with each call to Maximo. It is never written to disk and locks after 30 minutes without use.
- Recommended: create a Maximo user for MX Stage and issue its API key under a security group that allows only the object structures it needs. Maximo's own permissions and auditing then apply.
3. Write controls
- No write path for the AI: the AI's tools stop at requesting a commit; running it can only be called from the button in the work screen.
- Human check: a person reviews the counts and the diff, presses Commit to Maximo and confirms. MX Stage writes the first record only, reads it back, and sends the rest after a person has seen the result.
- Conflict detection: each record is read again just before sending; if someone else changed it after loading, it is skipped and listed. The run stops on an error or a result it cannot confirm.
- New records: records added in the work screen are created only after checking that no record with the same key exists. Maximo's automatic numbering is not used; the numbers are entered.
- No duplicate writes: every record carries a
transactionid. Nothing is retried automatically; results that cannot be confirmed are left as "check in Maximo". - Limits and extra confirmation: up to 200 records per commit. Deleting child rows (more than 10 per record or 50 in total) and changing values to empty need extra confirmation. Top-level records cannot be deleted.
- Undo: before a commit, any batch can be undone. There is no automatic rollback after a commit. The diff report keeps the old values.
4. Audit trail
| Diff report (Excel) | Saved before the commit. One row per changed cell: record key, column, old value, new value, author (AI or person), reason and time. A summary sheet with the connection, environment, object structure, request note, counts and work history. It contains Maximo data, so handle it under your own policies. Download a sample (fictional data) |
|---|---|
| Write log (CSV) | Saved after the commit (the diff report saved after a commit includes it too): record key, transaction ID, HTTP result, Maximo reason code and result (no attribute values). |
| In Maximo | Writes are made by the user you create for MX Stage, so Maximo's own history and auditing show them too. |
5. Requirements and limits
- Windows 10 or 11, Chrome or Edge, Node.js 22.6 or later (the installer can set it up). macOS and Linux are untested.
- IBM Maximo or Maximo Application Suite (Manage) with the JSON API (
/maximo/api) and an API key. Environments that allow only login authentication (MAXAUTH) or LDAP are not supported yet. - Only an HTTPS connection from the PC to Maximo is needed.
6. Source code
The source code is public on GitHub (Business Source License 1.1; each version becomes Apache License 2.0 four years after release). About 1,170 automated tests run against a fake Maximo. Your own code review is welcome.
Recommended first step: in a test environment (free), rehearse the whole flow — load, fix with AI, diff report, commit — and check the diff report and the write log.