Skip to content

Useful autonomy.
Explicit responsibility.

Agents need enough authority to finish useful work. Their humans need a clear understanding of what can happen, what needs a decision, and how to stay in control.

Our approach to trust.

These are product and deployment principles. Specific controls, integration support, and operational commitments are confirmed for each deployment.

01

Know who is acting

A persistent agent identity connects responsibility to its human owner. Access should be attributable to an agent or person, rather than shared through an anonymous session.

02

Make authority explicit

Define the systems, files, budgets, and actions available to an agent. Context and location make an interaction relevant; they do not grant new permissions.

03

Keep consequential decisions clear

Present what will change and the evidence behind it when a human decision is required. Pausing work, narrowing access, and revoking authority belong in the same experience.

04

Choose the operating boundary

Discuss where data and work history live, which services can be used, and how updates, retention, and recovery fit your environment.

Review the details
before you depend on them.

For a security review, bring your requirements for access, data location, model providers, retention, recovery, and human oversight. We will work through the scope and evidence with you.

Our legal documents are published as drafts pending review before general availability.

Make a review specific
to the work.

A useful security conversation connects requirements to actual information flows and actions. These are questions for scoping a deployment, not claims of certification or guaranteed controls.

01

Trace a representative assignment.

List the information the agent reads, the services that receive it, the credentials involved, and the records produced. Include model providers and connected tools. Ask which parts can be demonstrated in the proposed environment and which remain a requirement to implement.

02

Review the change in authority.

Work through granting access, changing an owner, withdrawing a permission, and stopping an assignment. Establish how actions already in progress are handled. A stop request should not imply that an external action which already completed has been reversed.

03

Agree on the evidence and responsibilities.

Identify who can inspect activity, which records are retained, who handles incidents, and how recovery is tested. Request deployment-specific documentation rather than relying on the general product narrative. Operational commitments should be explicit in the relevant agreement.

Start with your requirements.

Make the human responsibilities and the operating boundary part of the first conversation.

Discuss security