Governance Controls: Super Admin, Storage, Retention (Full Transcript)

How Super Admin, Private Storage, and retention policies support enterprise compliance—plus who should approve each setting and why.
Download Transcript (DOCX)
Speakers
add Add new speaker

[00:00:03] Speaker 1: Enterprise controls give you the governance layer that IT, security, and legal need before approving a company-wide rollout. We've covered that admin access doesn't equal meeting access. If someone sets privacy to only owner, regular admins can't see it. That's by design. Super Admin bypasses all meeting privacy restrictions. Every meeting is visible, regardless of individual settings. Only owner meetings, private channels, everything. It also unlocks moving any meeting to any channel, editing any meeting, API access to all workspace data, and webhooks for all meetings. Super Admin is enterprise-only, requires a signed legal agreement with Fireflys, and needs Fireflys team approval. You can't just toggle it on. When do you need it? Compliance teams that must review any conversation, legal holds where you can't risk missing data, security investigations, or audits. For most admins, regular admin access is enough. By default, Fireflys stores meeting data – audio, video, transcripts – in Fireflys-managed cloud infrastructure. Private Storage lets you change that. With Private Storage, data is stored in your own cloud environment – AWS S3 or Google Cloud Storage. You control the location, access policies, and retention. This matters for data residency. If legal says all data must stay in the EU, Private Storage makes that possible. Use it for data residency, compliance mandates like HIPAA or FERPA, or security policies that require data in company-controlled infrastructure. Private Storage is enterprise-only and requires your team to set up and maintain the cloud storage. Talk to IT and security before enabling. Data retention controls how long Fireflys keeps meeting data. By default, meetings are retained indefinitely until someone manually deletes them. Auto-delete removes meetings after a set period – 30, 60, 90 days – you choose. After that, audio, video, transcripts, and summaries are permanently deleted. No recycle bin, no recovery. Before enabling, answer three questions. What do regulations require? Some industries mandate minimum retention. What does legal need for litigation holds? What does the business need? Historical meeting data can be valuable for training and reference. This isn't a decision to make alone. Involve legal, compliance, security, and business stakeholders before turning auto-delete on. If you're using Private Storage, you may manage retention there instead, through S3 lifecycle policies or GCS retention rules. Coordinate with IT to avoid conflicting configurations. Not every setting is yours to decide alone. IT should own private storage, API configurations, and identity integrations. Security should weigh in on super admin requests, audit requirements, and access policies. Legal should approve data retention, compliance notifications, and privacy defaults. Leadership should sign off on workspace-wide policies and budget decisions. The best rollouts happen when admin, IT, security, and legal align before configurations go live, not after someone raises a concern. Document who approved what and why. Review annually as regulations, team size, and business needs evolve. A simple approval matrix helps. Super admin needs security and legal approval. Private storage needs IT and security setup. Data retention needs legal and compliance sign-off. Next, the Analytics Dashboard.

ai AI Insights
Arow Summary
Enterprise controls provide governance for company-wide rollouts, distinguishing regular admin access from meeting access. Meeting privacy settings can restrict admins; only Enterprise Super Admin can bypass all privacy restrictions to view, move, edit any meeting and access all workspace data via APIs/webhooks, and it requires an enterprise plan plus a signed legal agreement and vendor approval. By default, meeting data is stored in Fireflys-managed cloud infrastructure; Enterprise Private Storage allows storing data in the customer’s AWS S3 or Google Cloud Storage for data residency and compliance needs, with the customer managing setup and maintenance. Data retention defaults to indefinite, with optional irreversible auto-delete after set periods; decisions must consider regulations, legal holds, and business value, and retention may also be controlled via S3/GCS policies when using Private Storage. Effective rollouts require alignment and an approval matrix across IT (storage, APIs, identity), Security (super admin, audits, access policies), Legal (retention, notifications, privacy defaults), and Leadership (workspace policies and budget), with documentation and annual reviews.
Arow Title
Enterprise Governance: Super Admin, Private Storage, and Retention
Arow Keywords
enterprise controls Remove
governance Remove
admin access Remove
meeting privacy Remove
Super Admin Remove
compliance Remove
legal hold Remove
security investigations Remove
audits Remove
Private Storage Remove
data residency Remove
AWS S3 Remove
Google Cloud Storage Remove
HIPAA Remove
FERPA Remove
data retention Remove
auto-delete Remove
S3 lifecycle policies Remove
GCS retention rules Remove
approval matrix Remove
Arow Key Takeaways
  • Regular admin rights don’t automatically grant access to private meetings; privacy settings can restrict visibility by design.
  • Enterprise Super Admin can see and manage all meetings and data, but requires enterprise eligibility, legal agreement, and vendor approval.
  • Private Storage moves meeting data to customer-controlled AWS/GCS to satisfy residency, compliance, or security mandates, but requires IT/security ownership and maintenance.
  • Default retention is indefinite; auto-delete is irreversible and must be decided with legal/compliance/security/business input.
  • When using Private Storage, coordinate retention between Fireflys settings and S3/GCS lifecycle/retention rules to avoid conflicts.
  • Use a documented approval matrix: Super Admin (security+legal), Private Storage (IT+security), Retention (legal+compliance), and review policies annually.
Arow Sentiments
Neutral: The tone is informative and policy-focused, emphasizing risk management, compliance requirements, and cross-functional approvals without expressing strong positive or negative emotion.
Arow Enter your query
{{ secondsToHumanTime(time) }}
Back
Forward
{{ Math.round(speed * 100) / 100 }}x
{{ secondsToHumanTime(duration) }}
close
New speaker
Add speaker
close
Edit speaker
Save changes
close
Share Transcript