Control who can act. Protect what they can see.
Choose what each service and Agent may do, keep sensitive information masked and record authorised access. Your processes make these choices explicit.
One case. Three access scopes.
Payment service
- Amount
- €8,400
- Buyer
- Alba Distribution
- Contact email
- Masked
AI Agent
- Amount
- €8,400
- Buyer
- Buyer-27
- Contact email
- Masked
Operator
- Amount
- €8,400
- Buyer
- Alba Distribution
- Contact email
- finance@example.com
Illustrative configuration · Access chosen for each participant
Keep sensitive data protected, step after step
Protected values stay masked in execution views. Transforming a value does not silently remove its protection.
When someone needs to inspect a protected value, access is targeted, requires the appropriate permission and is recorded.
Targeted access. A clear record.
- 01
Masked in the activity view
Contact email••••••••••••Sensitive - 02
Targeted access by an authorised operator
- Reason
- Investigate an undelivered invitation
- Field accessed
- Contact email only
alex@example.com - 03
Access recorded
Operator, field, reason and timestamp.
The merchant is notified
Define, enforce, inspect.
Action and data access rights are defined during configuration, enforced during execution and visible when reviewing a run.
Your ERP, providers and Ormuz retain their respective responsibilities. Connecting a system does not give it permission to overwrite every business fact.
Give each Agent only the tools it needs
An Agent analysing a dispute may need to read an invoice and its supporting files. Refunding the buyer is a separate capability, which must be explicitly granted.
Choose the tools available to each activity. Permissions, declared tool risk and access to protected data keep its actions within the boundaries you set.
Analyse a dispute
- Fetch the disputeAllowed
- Read the invoiceAllowed
- Read supporting filesAllowed
- Issue a refundNot granted
Example configuration: each activity has its own set of tools.