Govern the AI Workers you build, buy, or deploy — with customer-controlled identity, authority, human oversight, and evidence.

Code of Conduct

Governed AI should protect people and remain accountable.

Scaled Agents is built around human responsibility, authorized purpose, bounded action, privacy and security, evidence, and the ability to pause or stop work when authority or safety conditions are missing.

Our Commitments

Good conduct must be connected to enforceable governance.

These commitments guide how Scaled Agents designs AI Worker governance and how customer-managed deployments should define ownership, authority, review, evidence, and lifecycle controls.

Protect people

Place human safety, dignity, rights, and well-being ahead of speed, convenience, or autonomous completion.

Keep humans accountable

Name accountable human owners and reviewers. AI Workers may recommend, route, or prepare evidence; they do not become final accountable authorities.

Operate for an authorized purpose

Restrict each AI Worker to a defined business purpose, approved scope, permitted actions, and explicit destinations.

Prevent and contain harm

Deny, pause, contain, or escalate activity when requested conduct is unsafe, malicious, unlawful, deceptive, discriminatory, or outside authority.

Protect data and systems

Apply least privilege, data minimization, approved connectors, secure handling, and clear privacy and security boundaries.

Preserve evidence and truth

Record material decisions, sources, uncertainty, approvals, denials, and lifecycle events without fabricating evidence or hiding failures.

Require review for consequence

Route sensitive, uncertain, externally visible, irreversible, or consequential work to qualified Human Review.

Remain controllable

Maintain pause, disable, rollback, suspension, revocation, recovery, and retirement paths appropriate to the AI Worker's risk.

Improve through evidence

Use monitored outcomes, incidents, evaluations, exceptions, and remediation records to strengthen controls over time.

Prohibited Conduct

Some activity must not proceed.

Scaled Agents should block or escalate requests involving malicious or harmful conduct, including activity outside the AI Worker's approved purpose or authority.

Harm, abuse, and exploitation

  • Violence, exploitation, or facilitation of serious harm
  • Harassment, discrimination, coercion, or abusive targeting
  • Unlawful surveillance or unjustified invasion of privacy
  • Unsafe action without the required qualified human review

Deception, intrusion, and control bypass

  • Fraud, impersonation, fabricated evidence, or deceptive manipulation
  • Malicious cyber activity, credential theft, or unauthorized access
  • Unauthorized data or intellectual-property extraction
  • Self-approval, authority expansion, control bypass, or evidence tampering
Fail-closed expectation Missing ownership, scope, authority, evidence, data classification, tool permission, approval, or rollback capability should cause a pause, block, evidence request, or Human Review—not an optimistic assumption.

From Commitment To Control

The conduct standard follows the same governed control chain.

Public commitments become meaningful when identity, authority, review, action, evidence, monitoring, and lifecycle response remain connected.

Agent Registry
Passport
Tool & Connector Registry
Toll Gate
Human Review
Runtime Permit
Action Broker
Evidence
Monitoring
Lifecycle Response
Customer-managed operating boundary The public website explains the control model. Actual runtime configuration, identity, data, integrations, enforcement, evidence custody, incident response, and production decisions remain specific to each customer's approved deployment and accountable owners.

Assurance Readout

Snapshot as of September 22, 2026.

Scaled Agents operates in production. This assurance snapshot is intentionally bounded: a local deterministic runner exercised twelve abstract scenario families without a model, network, connector, customer data, interaction with a customer production system, or external action. All expected synthetic outcomes were observed.

MeasureObserved resultEvidence boundary
Composed scenarios executed12 / 12Public-safe abstractions in one deterministic local run
Expected outcomes observed12 / 12Fixture-defined mock outcomes; not customer operation
Unsafe allowances in prohibited scenarios0Limited to the included scenario set
Unauthorized executions0No external action path existed in this run
Applicable Human Review routes7 / 7Expected routing outcome in the synthetic manifest
Required record-family manifest completeness12 / 12Manifest references only; canonical runtime records were not materialized
Automatic replay0No denied or escalated item was automatically replayed
Repository-tested synthetic industry templates8 / 8Healthcare, financial services, insurance, manufacturing, retail, public sector, energy and utilities, and human resources; separate supporting coverage with zero protected industry executions

Result digest: sha256:3b2e888f867c517059dee935dc7d94c78055bb502412f580eff3c74c90f99417

What this snapshot does not demonstrate The eight industry templates were repository-tested, not executed as protected industry runs. This snapshot does not establish universal harm prevention, detection of every malicious request, deployed non-bypassability, customer evidence custody, operational effectiveness over time, model behavior, live connector enforcement, legal approval, compliance, certification, security authorization, audit assurance, or authorization for a specific customer deployment or production action.

Scenario Coverage

Twelve executed public-safe scenarios.

COC-01 · Approved drafting

Allow bounded low-risk drafting from approved sources.

COC-02 · Malicious cyber request

Deny unauthorized destructive activity without dispatching an action.

COC-03 · Prompt injection

Block untrusted embedded instructions and route material risk for review.

COC-04 · Sensitive-data export

Block export to an unapproved destination and require accountable review.

COC-05 · Consequential decision

Require a qualified human to make the final consequential decision.

COC-06 · Authority expansion

Deny scope widening or excessive redelegation and revoke unused authority.

COC-07 · Authorized human stop

Pause multi-step work and preserve the containment path.

COC-08 · Connector uncertainty

Record an uncertain timeout outcome and do not replay automatically.

COC-09 · Evidence integrity

Pause and escalate attempted evidence alteration, omission, or fabrication.

COC-10 · Material drift

Pause affected scope and require reassessment after material drift.

COC-11 · Severe-harm request

Deny the prohibited request without dispatching an action.

COC-12 · Repeated false refusal

Escalate excessive control friction without weakening safety.

Human Accountability

AI Workers do not approve their own conduct or authority.

Accountable owners

Business, technical, security, privacy, risk, legal, compliance, audit, and operational owners make the decisions applicable to their environment and responsibilities.

Review and challenge

People must be able to inspect evidence, challenge a recommendation, deny or restrict work, require remediation, and pause or retire the AI Worker.

Publication Record

Point-in-time public readout.

Published and last reviewed: September 22, 2026

Suggested citation: Scaled Agents, “AI Code of Conduct & Assurance,” September 22, 2026.

This page is a public, evidence-bounded derivative of controlled governance and test artifacts. It does not expose internal prompts, scoring logic, customer records, confidential evidence, or proprietary enforcement detail.