AI Roleplay and Employee Data: 12 Questions to Ask Before You Roll It Out

When Rapport demoed live at ATD Demo Day, the single largest cluster of audience questions was not about avatars or scoring. It was about data.

Where does it live, who can see it, and is my employees' practice being used to train somebody's model. Those questions arrive from your security team eventually, so it is cheaper to ask them first.

  September 22, 2026

Key takeaways

Key takeaways
  • Ask about model training first. "We don't train on your data" should appear in the contract, and should explicitly cover downstream model providers.
  • Get retention periods separately for audio, transcripts, and scores. They are usually different numbers, and vendors often quote only the friendliest one.
  • Data residency is a pilot-stage question, not a renewal-stage one. Ask which region before employee data moves.
  • Manager access is a design choice, not a setting. If every learner report lands in a supervisor's inbox by default, adoption suffers and so does honesty.
  • In Rapport: no model training by default, audio and full transcripts not retained long term, US servers with EU and Asia available for enterprise, and learner reports not auto-shared with supervisors.

Why this question lands on L&D instead of IT

Conversation practice generates an unusual data type. A completed e-learning module produces a timestamp and a pass mark.

A roleplay produces a recording of an employee being bad at something, plus a scored assessment of exactly how.

That combination triggers scrutiny that ordinary training tools never attract, and because the tool was sourced by L&D rather than IT, the L&D lead is usually the one asked to answer for it. The questions below are the ones that come up, phrased the way a security reviewer phrases them.

One caveat before the checklist. Vendor postures change. Every Rapport-specific answer in this article reflects statements made during Rapport's ATD Demo Day session. Treat them as the starting point for a conversation with the Rapport team and your own legal review, not as contract language.

Model training and content isolation

Start here, because it is the answer most likely to end an evaluation early.

Question 1: Is our data used to train AI models? The answer you want is no, by default, without a toggle the buyer has to find.

Rapport's position as stated on the call is that there is no data sharing with AI models by default, and customer conversations are processed only to deliver the conversation and the resulting reports.

Question 2: Does that also cover your model providers? This is the follow-up that catches people.

A platform can honestly say it does not train on your data while passing that data to a third-party model that does. Ask for the answer to cover the full chain.

Question 3: Is our content isolated from other customers? Most platforms need your material to make the simulation realistic, which means your product information, scenarios, and rubrics are in the system.

In Rapport this sits in a secure knowledge base that the avatar references during conversation, scoped so that content, rubrics, and scenarios stay accurate and relevant only to you.

Secure knowledge base: the isolated store holding your scenarios, rubrics, and reference content, which the avatar reasons against during a conversation. It does two jobs at once.

It keeps the avatar's answers accurate to your organization instead of improvised, and it keeps proprietary material scoped to your account.

A security reviewer marking up a printed AI vendor questionnaire at her desk
These questions reach your security reviewer eventually. Asking them before the pilot keeps the evaluation on your timeline.

What actually gets stored, and for how long

This is where vague answers do the most damage, because "we don't store your data" is almost never true in the literal sense. Something is stored or the product would not work.

The useful question is what, and for how long.

Question 4: What happens to the audio? Question 5: What happens to the transcript?

Question 6: What persists after the report is generated? Ask all three separately.

Data type
Why it exists
Rapport's stated handling
Learner audio
Drives the live conversation and the avatar's real-time reaction to tone
Processed ephemerally. Not stored long term by default.
Conversation transcript
Required to generate the scorecard and per-criterion feedback
Used to produce the scorecard, then not held long term. Explicit transcripts are not retained by default.
Scoring outputs
Powers the learner report and the cohort dashboard over time
High-level scoring outputs are retained. This is what makes look-back windows and trend views possible.
Account data
Authentication and assignment
Login information and user ID are retained.
Your source content
Scenarios, rubrics, and reference material the avatar uses
Held in the secure knowledge base, used only to drive your scenarios and reports.
Figure 1. The pattern worth looking for in any vendor: the ephemeral things are the sensitive ones, and the retained things are the aggregate ones. If that is inverted, ask why.

Question 7: Can we get longitudinal reporting if the detail is not retained? Yes, and this is the trade-off worth understanding.

Because high-level scoring outputs persist, you can set a look-back window and watch a competency move over months without keeping a library of recordings of employees struggling. That is the right side of the trade for most organizations.

Residency, certifications, and access control

Question 8: Where are the servers? Rapport's servers are US-based, and the company can provision in Europe or Asia for enterprise customers.

The company itself is headquartered in Edinburgh, which occasionally confuses the residency question, so ask about infrastructure rather than offices.

Question 9: What certifications do you hold today, and what is in progress? At the time of the ATD Demo Day session, Rapport was not FedRAMP authorized and described it as under consideration.

If you are in the public sector, in defense, or in a regulated environment with a hard authorization requirement, confirm the current position with the team directly, since this changes.

Question 10: How does access work? Rapport supports single sign-on, embeds into an existing LMS as a SCORM compliant package, or can be reached through a private scenario link or the learner portal.

Every route funnels results back to the same cohort view. Teams with regulated workflows should also review financial services and healthcare for sector-specific considerations.

Send this section to your security reviewer

If it raises questions specific to your environment, the team can walk through residency, retention, and access on a call before any employee data moves.

Talk to the team

The question nobody puts on the security form

Question 11: Who sees an individual learner's report by default?

This is not a compliance question, which is exactly why it gets skipped. It is the question that decides whether anyone uses the tool honestly.

The entire value of simulated practice is that an employee can be bad at something privately, repeatedly, until they are not. If every attempt is visible to a supervisor by default, learners optimize for looking competent on attempt one, and you have rebuilt the performance review with worse instrumentation.

Rapport's default is that individual learner reports are not automatically delivered to supervisors. Aggregate scores roll up to the cohort dashboard so trainers can see where the team needs coaching, and learners can export their own report to bring into a coaching conversation on their terms.

Enterprise customers with a documented reason can arrange broader access, but the default runs the other way.

Question 12: Can learners author their own scenarios? In Rapport today, no.

Scenario creation sits with the training team, who assign scenarios out. That is a governance feature as much as a product one, since it keeps the rubrics and reference content under the control of the people accountable for them.

An employee wearing headphones practicing a conversation alone at his desk after hours
Practice only works when it is private. Default report visibility decides whether learners try, fail, and try again.

The 12-question checklist

Copy this into your vendor evaluation. It works for any platform in the category, not just this one.

If you are still building the shortlist, the best AI roleplay platforms covers the field and how to pick the right platform covers the wider evaluation criteria.

Ask this
A good answer sounds like
1. Model training
No, by default, and it is in the contract rather than the FAQ.
2. Downstream providers
The commitment covers our model providers, named in the DPA.
3. Content isolation
Your material sits in a knowledge base scoped to your account.
4. Audio retention
Processed for the session, not retained. Here is the period in days.
5. Transcript retention
Used to generate the report, then discarded on a stated schedule.
6. What persists
A specific, short list. Usually account data and aggregate scores.
7. Longitudinal reporting
Trend views come from retained scores, not retained recordings.
8. Data residency
Named region, with alternatives available before the pilot starts.
9. Certifications
What is held today and what is in progress, stated plainly.
10. SSO and LMS
SSO supported, SCORM compatible, and a link-based fallback.
11. Manager visibility
Individual reports stay with the learner unless you change it.
12. Authoring control
Scenario creation sits with the training team, not every learner.
Figure 2. Questions 11 and 12 are the two that rarely appear on a standard security questionnaire and most often determine whether the rollout works.
L&D and IT colleagues reviewing an AI roleplay rollout plan together at a conference table
Run the checklist with L&D and IT in the same room, before any employee data moves.

Frequently asked questions

Is AI roleplay training data used to train AI models?

It depends on the vendor, which is why it is the first question. In Rapport there is no data sharing with AI models by default, and conversations are processed only to deliver the conversation and reports.

Ask for this in the contract and ask whether it covers downstream model providers.

Does AI roleplay software record and store employee audio?

In Rapport, audio and explicit transcripts are not stored long term by default. They are processed to produce the report, and what persists is login information, user ID, and high-level scoring outputs.

With any vendor, ask for retention periods per data type, since the answers usually differ.

Where is AI roleplay data stored?

Rapport's servers are US-based, with Europe or Asia available for enterprise customers. Confirm the region before a pilot if you have GDPR or internal transfer restrictions.

Can managers see individual employee roleplay scores?

In Rapport, individual reports are not automatically delivered to supervisors. Aggregate scores roll up to a cohort dashboard, and learners can export their own report for a coaching conversation.

Enterprise customers can arrange broader access where there is a documented reason.

Is Rapport FedRAMP authorized?

At the time of Rapport's ATD Demo Day session, no, and the team described it as under consideration. Confirm current status directly if you have a federal requirement.

Does AI roleplay work with single sign-on and our LMS?

Yes. Rapport is SCORM compatible and embeds into an existing LMS, and also supports private scenario links and a learner portal with single sign-on.

Results reach the same cohort view regardless of route.

What is a secure knowledge base in AI roleplay?

The isolated store holding your scenarios, rubrics, and reference content, which the avatar references during a conversation. It keeps responses accurate to your organization and keeps proprietary material scoped to your account.

Where to go next

The session these answers came from is recapped in our ATD Demo Day recap. If you are earlier in the process, AI role play training covers the fundamentals and how to design an AI roleplay scenario covers what you will actually be uploading.

For the measurement layer, see completion rates are not readiness. Full terms are in the privacy policy and terms of service.

Get the security conversation out of the way early.

Bring your reviewer's list. The team can cover retention, residency, access control, and what your DPA would actually say before you commit to a pilot.

Ask your questions See the platform