Security and human control

The agent’s authority is designed—not assumed.

Every deployment is designed around separate customer accounts, tenant isolation, least privilege, approvals, audit history, limits, escalation, and a kill switch.

← Back to home
01

Separate and least privilege

Customer accounts and credentials are kept separate. Access is scoped to the minimum data and actions required, with negative cross-tenant tests before deployment.

02

Approval and operating limits

Approval queues show the exact action and consequence. Spending and usage caps, a maximum of three retries, uncertainty thresholds, and human escalation stop unsafe loops.

03

Kill switch, audit, and rollback

Append-only audit history records decisions and actions. Incidents pause the affected deployment, preserve evidence, roll back reversible writes, validate the system of record, and require named approval to resume.

04

Always prohibited

Agents cannot freely move money, issue refunds, change credentials, make legal commitments, provide binding quotes, delete records, or take destructive actions.