Administration and Security
Coming soon. Backbuild Meetings is a forthcoming part of the workspace. This page states the honest security and administration posture so you can review it before it arrives. It does not claim any protection the product does not provide.
This page is written for the administrator who provisions access and the security, privacy, or compliance reviewer who must approve the tool. It explains how meetings inherit your workspace identity and governance rather than standing up a second silo, who can host and moderate, how external guests are contained, what is logged and isolated, and, plainly, how meetings are encrypted and what is and is not offered around recording and transcription. Where a capability is not yet available, this page says so rather than implying it.
One Identity: Access Follows Your Workspace
After this section you will know that meeting access is not a separate account. Backbuild Meetings is part of the Backbuild workspace, so the people who can use it are the members of your organization, signing in the same way they sign in to everything else. There is no separate conferencing login to provision and no second directory to keep in step.
- Same sign-in. Members reach meetings with the same credentials, multi-factor, and passkeys they use across Backbuild. See Signing In and Account Security.
- Single sign-on and directory provisioning. Where your organization signs in through your identity provider and provisions members from your directory, meeting access is granted and revoked with that same lifecycle. When a person is offboarded from your workspace, their access to meetings goes with it. See SSO and SCIM.
- The people you meet are the people you already have. Inviting by name draws on your organization directory and Backbuild Contacts, not a separate contact list.
How is meeting access granted and revoked? With the rest of the workspace. A member who is provisioned into your organization can use meetings, and a member who is deprovisioned loses access at the same time. You manage it as part of your normal identity lifecycle, not as a separate conferencing admin console.
Who Can Host and Moderate
After this section you will know that hosting is role-governed. Hosting and moderation are governed by the roles you already use in your workspace, so the ability to run a meeting, admit guests, mute, remove, lock, and spotlight is not open to everyone by default. You grant a person the ability to do something only if you hold that ability yourself, which keeps delegation from escalating. The customer-facing roles and permissions model is covered in Roles and Permissions.
Is hosting and moderation role-based? Yes. Who can host and who can moderate is set by your workspace roles, not left to whoever clicks first. This lets you decide, for example, that only certain roles run and control meetings.
How External Guests Are Contained
After this section you will know exactly how far a guest can go. A guest is someone with no Backbuild account who joins a meeting by link. Guests are the convenient way to meet a client or a candidate, and they are contained by design:
- A guest joins one meeting. A guest's access is scoped to the single meeting they were invited to. It is not an account, and it is not access to your workspace, your projects, or your data.
- The waiting room gates them. When a meeting is restricted, a guest is held at the door until the host admits them, so a forwarded link does not put a stranger straight into the room. See The Waiting Room and Moderation.
- The host can remove and lock. A guest who should not be there can be removed, and the host can lock the room so no one else, including that guest, can rejoin.
- A guest appears as a named guest. Other participants can see that the person is a guest, not a member of your organization.
How are external guests identified and contained? A guest shows in the room as a named guest rather than a member, joins only the one meeting they were invited to, and is gated by the waiting room when the meeting is restricted. The host controls entry and can remove a guest and lock the room. A guest never receives access to anything in your workspace beyond that meeting.
What Is Logged and How Meetings Are Isolated
After this section you will know what is recorded for governance and how tenants are kept apart. Meeting management actions are written to your organization's audit trail with the person who performed them, so creating, changing, and ending meetings, and moderation actions, are attributable after the fact. Meetings belong to your organization and are isolated from every other organization on the platform, and each environment your organization runs is kept separate from the others, so a meeting in one never bleeds into another.
What is logged, and who can read it? Meeting management and moderation actions are captured in your organization's audit trail with user attribution, readable by the members of your organization whose role grants access to the audit trail. Backbuild does not expose your meeting activity to other tenants.
Will it behave the same for me as it does in this documentation? Yes. The behavior described here is the behavior you get, and your meetings are isolated to your organization and environment. What is documented as not yet available, such as recording, is genuinely not available, so you are never reviewing against a capability that behaves differently in practice.
Billing: Meetings Draw Your Organization's Credits
After this section you will know how meetings are paid for and where the spend is visible. There is no separate meetings subscription, no per-host license, and no invoice from a conferencing vendor to reconcile. Meetings run on your organization's universal usage credits on every plan, including Free, billed per participant per live minute at the rate the Meetings screen shows (current pricing; the pricing page is the authoritative source for rates and credit packages).
- The organization pays, never the attendee. The whole meeting, external guests included, bills to the organization the meeting belongs to. Attendees are never asked for payment, and a guest is never shown your billing state: if entry is blocked for credit reasons, a guest simply sees that the meeting is unavailable, with no billing vocabulary attached.
- Entry requires balance; a live meeting is never interrupted. Starting or joining a live meeting requires available credits, and members are told plainly when the balance blocks them. Once people are connected, balance exhaustion never cuts them off; credits gate the door, not the room.
- Spend is attributable. Meetings usage appears as its own category in the billable usage breakdown on the Billing & Usage screen, alongside your other metered usage, so a reviewer can see exactly what meetings cost the organization and when.
- Scheduling and records are not metered. Only live meeting time draws the meeting rate. Invitations are ordinary email against your outbound allowance, and viewing your meetings list costs nothing.
How do I budget for meetings? From the two numbers on the Meetings screen: the per-participant-minute rate and your balance. Multiply expected participants by expected minutes for the month, and watch the Meetings usage category on the Billing & Usage screen through your first busy month to size from real numbers. Credit packages are available on every plan, and unused credits roll over per the credits guide.
Encryption: the Honest Posture
After this section you will be able to answer the encryption question accurately. This is the question reviewers scrutinize most, and the one where an overclaim is worse than a limitation, so here is the plain statement:
- Encrypted in transit. Meeting audio and video travel over encrypted real-time connections, and the signaling that sets up a call travels over TLS. Your media is not sent in the clear.
- Not end-to-end encrypted. Backbuild Meetings does not currently offer end-to-end encryption, where only the participants' devices can ever decrypt the media. Do not represent Backbuild Meetings as end-to-end encrypted. If end-to-end encryption is a hard requirement for a specific meeting, this surface does not meet it today.
- Data at rest. Meeting records and anything you keep from a meeting, such as a whiteboard, are stored with the same encryption at rest as the rest of your Backbuild workspace.
State this exactly as written when you brief a reviewer. Encryption in transit is real and standard; end-to-end encryption is not offered for meetings today.
Recording, Transcription, and Consent
After this section you will know precisely what exists so you can set policy. This is the area where honesty matters most for a compliance reviewer, because a recording of a meeting can carry regulated data and legal consent obligations.
- Cloud recording is not part of the first release. Backbuild Meetings does not save a recording of a meeting at launch. There is no stored recording to retain, access, or produce, so you do not need a recording-retention policy for it yet.
- Transcription is not available at launch. Meetings are not transcribed, and no transcript is produced or stored. When transcription arrives, it will run on universal usage credits, billed per minute of use; treat it as unavailable until this documentation says otherwise.
- When recording arrives, it will be visible. If and when recording becomes available, a meeting that is being recorded will show a clear on-screen indicator to everyone for the duration, so participants know, and consent can be handled to your policy. This documentation will be updated with the exact access and retention behavior at that time.
Is there recording, and who can access recordings? Not at launch. Backbuild Meetings does not record or transcribe meetings in the first release, so there are no stored recordings or transcripts to access. When recording is added, it will be signposted to every participant while active, and the access and retention details will be documented before you rely on them. Until then, plan on the basis that meetings are not recorded.
Retention and Deletion
After this section you will know what is kept and how to remove it. A meeting itself is a record in your workspace: its title, its schedule, and who took part. Deleting a meeting removes it, and a live meeting is ended first and then deleted. A whiteboard created in a meeting is a Backbuild Docs object in your workspace, so it follows the same retention, sharing, and deletion controls as your other documents, and you remove it the same way. Because no recording or transcript is produced at launch, there is no separate media artifact to locate and delete.
What are the retention and deletion controls, and where does meeting data live? Meeting records live in your organization's workspace under your tenant isolation and are deleted when you delete the meeting. A whiteboard is a document in your workspace and is retained and deleted like any Backbuild Docs object. With no recording or transcript at launch, meeting media is not stored, so there is nothing further to retain or purge.
Frequently Asked Questions
Is Backbuild Meetings end-to-end encrypted or encrypted in transit? Encrypted in transit. Media and signaling are encrypted on the wire, and data you keep is encrypted at rest. It is not end-to-end encrypted, and you should not describe it as such.
Do meetings meet our regulated-data requirements? Judge it against the honest posture on this page: encrypted in transit but not end-to-end encrypted, no recording or transcription at launch, role-governed hosting, per-organization and per-environment isolation, audit-logged management actions, and guest access scoped to a single meeting. If your obligation requires end-to-end encryption or a controlled recording pipeline for a given meeting, that is not available today.
Can I set an organization-wide default so every meeting uses the waiting room? A host turns on the waiting room and can lock a meeting per meeting, and who may host and moderate is governed by your workspace roles. Treat the waiting room as the default-safe habit for every meeting that is not fully open. See The Waiting Room and Moderation.