Security follows the decision from source record to action

Client data is isolated, authority is explicit and every model output, approval and external action can be traced to the version and evidence that produced it.

Tenant isolation

Client records, mappings, users, thresholds, endpoints, credentials and model artifacts remain inside the approved tenant boundary.

Explicit authority

Authentication, authorisation, approval boundaries and side-effect permissions are enforced at the service and adapter boundaries.

Controlled data path

Source authority, provenance, freshness, conflicts and classification travel with evidence through the decision path.

Durable audit

Decisions, model versions, approvals, intents, completions and outcomes retain replayable lineage.

Deployment is set by the client’s risk boundary.

Reusable softwareVersioned engine code and contracts remain separate from client records and configuration.
Client environmentContains source connections, identity mappings, roles, permissions, approved model artifacts and deployment settings.
External actionsEvery permitted write requires a named adapter, permission, approval rule and duplicate-prevention contract.
ModelsArtifacts are versioned, scoped, monitored and expired explicitly, with a declared fallback.

Evidence available for procurement and technical review.

  • System architecture, data flows, trust boundaries and service ownership.
  • Access, secrets, dependencies, vulnerabilities, backup, recovery and change controls for the deployment.
  • Model approval, scope, monitoring, fallback, replay and outcome records.
  • Client-specific requirements and accepted exceptions recorded with an owner.

Set the security boundary before implementation begins.

Bring the hosting, access, integration and procurement requirements that govern the decision and its data.

Discuss the decision