Security & governance

Control who can act. Protect what they can see.

Choose what each service and Agent may do, keep sensitive information masked and record authorised access. Your processes make these choices explicit.

Invoice INV-1042

One case. Three access scopes.

Payment service

Amount
€8,400
Buyer
Alba Distribution
Contact email
Masked
Allowed actionCollect payment

AI Agent

Amount
€8,400
Buyer
Buyer-27
Contact email
Masked
Allowed actionAssess the discrepancy

Operator

Amount
€8,400
Buyer
Alba Distribution
Contact email
finance@example.com
Allowed actionReview the exception

Illustrative configuration · Access chosen for each participant

Protected data

Keep sensitive data protected, step after step

Protected values stay masked in execution views. Transforming a value does not silently remove its protection.

When someone needs to inspect a protected value, access is targeted, requires the appropriate permission and is recorded.

Case diagnostic

Targeted access. A clear record.

  1. 01

    Masked in the activity view

    Contact email••••••••••••Sensitive
  2. 02

    Targeted access by an authorised operator

    Reason
    Investigate an undelivered invitation
    Field accessed
    Contact email only
    alex@example.com
  3. 03

    Access recorded

    Operator, field, reason and timestamp.

    The merchant is notified
Illustrative example · Email classified as sensitive in this process.
Complementary controls

Define, enforce, inspect.

Action and data access rights are defined during configuration, enforced during execution and visible when reviewing a run.

DesignRuntimeObservability
AuthorityDeclaredEnforcedVisible
ClassificationTypedPropagatedMasked
Agent toolsGrantedBoundedTraced
Protected accessRight requiredTargetedAudited
Authority
Integration never redefines who owns the fact.

Your ERP, providers and Ormuz retain their respective responsibilities. Connecting a system does not give it permission to overwrite every business fact.

Agent guardrails

Give each Agent only the tools it needs

An Agent analysing a dispute may need to read an invoice and its supporting files. Refunding the buyer is a separate capability, which must be explicitly granted.

Choose the tools available to each activity. Permissions, declared tool risk and access to protected data keep its actions within the boundaries you set.

Agent activity

Analyse a dispute

  • Fetch the disputeAllowed
  • Read the invoiceAllowed
  • Read supporting filesAllowed
  • Issue a refundNot granted
Expected resultAn assessment to inform the next step.

Example configuration: each activity has its own set of tools.

Public contracts

Connecting a service does not mean giving it access to everything.

Choose the access each service needs and retain control over protected information.