How agents are controlled.
What an agent can reach, what it can change, what record it leaves, and what you would show an auditor. Written for the person who has to sign off, not the person who builds it.
01
Access control
What an agent can reach, and what it cannot.
| Control | How it works | Evidence you receive |
|---|---|---|
| Scope by tenant and namespace | Every agent works inside a tenant and namespace created on purpose, and sees only what its scope holds. | Evidence you receiveThe tenant and namespace configuration |
| Least privilege by construction | Access is scoped by tenant, namespace, and tags, so the narrowest scope is the starting point. | Evidence you receiveThe scope assigned to each agent |
| Credential isolation | No source-system credentials sit in an agent’s context window, prompts, or logs. The keys stay with you. | Evidence you receiveThe publication list: what was copied into Vickee, and from where |
02
Change control and separation of duties
What an agent can change, and who has to approve it.
| Control | How it works | Evidence you receive |
|---|---|---|
| Governed copy | Agents read from a governed copy of curated extracts. The source system is never touched. | Evidence you receiveThe publication list |
| Writeback setting | Outbound writeback is off, or gated by a named approver. Which one is a setting your team chooses, and it is visible. | Evidence you receiveThe writeback setting as configured |
| Deterministic connectors | Data moves through connectors written as plain code. No model sits in the sync path, so the same input shapes the same way every run. | Evidence you receiveThe approval record for any change that landed |
03
Logging and evidence
What record exists after an agent has answered.
| Control | How it works | Evidence you receive |
|---|---|---|
| Cited answers | Every answer names the sources it drew on, so a control can be evidenced from the answer itself. | Evidence you receiveA sample cited answer |
| Per-query log | An exportable log records who or what asked, what was retrieved, which sources were cited, and when. | Evidence you receiveThe log export |
04
Monitoring and review
How you know it still behaves next quarter.
| Control | How it works, set up during the engagement | Evidence you receive |
|---|---|---|
| Continuous evaluation | Evaluation keeps running after launch, past the one-time check. | Evidence you receiveThe evaluation results |
| Review cadence | A scheduled examination of what the system is doing. | Evidence you receiveThe review schedule |
| Route for bad outputs | The people using it can report a bad output to someone who can change the system, and what changed is recorded. | Evidence you receiveThe change record |
05
When it is wrong
Who answers for it, and how far a mistake can reach.
| Control | How it works | Evidence you receive |
|---|---|---|
| Named accountability | Set up during the engagement: one named person is accountable for every consequential decision. | Evidence you receiveThe accountability assignment |
| Bounded blast radius | A misbehaving agent reaches only a read-only knowledge layer. Your ERP never sees it. | Evidence you receiveThe writeback setting as configured |
| Reversible content | Content can be replaced or removed, and the index follows. | Evidence you receiveThe removal record |
Bring your control framework.
Send the questionnaire, the control list, or the questions your auditors asked last time. We will answer each one against what is on this page, and say plainly where the answer is not yet.
Start a conversation