Govern the AI Workers you build, buy, or deploy — with customer-controlled identity, authority, human oversight, and evidence.

Security

Put security controls between AI intent and enterprise action.

Scaled Agents™ connects identity, least privilege, Human Review, action-time authorization, controlled execution, monitoring, and evidence across the AI Worker lifecycle—so teams can govern what an AI Worker may do, under which conditions, and with whose accountability.

Governed Action Path

Security follows the action from identity to evidence.

The licensed, customer-managed AI Worker Control Plane is designed to keep standing eligibility separate from action-time authority. In an implemented customer environment, missing ownership, scope, approval, policy, evidence, or a safe execution path should cause the action to pause, block, or escalate.

1. Passport

Define the AI Worker’s human owner, purpose, approved scope, permissions, prohibited actions, risk tier, lifecycle, and review obligations.

2. Toll Gate & Human Review

Evaluate policy, data, tool, cost, autonomy, destination, and consequence before higher-risk work can continue.

3. Runtime Permit

Issue short-lived, scoped authority for one eligible action only after current identity, policy, approval, and evidence checks pass.

4. Action Broker

Mediate approved execution through the governed path and deny direct, substituted, stale, or out-of-scope requests.

5. Evidence

Record decisions, execution receipts, exceptions, lifecycle events, and outcomes so accountable reviewers can reconstruct what happened.

Security Control Model

Four control themes cover the AI Worker lifecycle.

The architecture connects AI Worker records, Model & Provider Dependency Records, tool permissions, data boundaries, runtime decisions, monitoring, and incident paths without treating a draft record as approval.

Identity and least privilege

Bind each AI Worker to a human owner, approved purpose, risk tier, permitted actions, resources, destinations, and lifecycle. Broader capability never creates broader authority.

Data, model, tool, and retrieval boundaries

Classify data, review providers and dependencies, constrain retrieval sources, allowlist tools and actions, validate parameters, and keep secrets and restricted content out of public or unauthenticated paths.

Action-time authorization

Recheck Passport, policy, Human Review, evidence freshness, tool authorization, destination, and revocation state before issuing a scoped Runtime Permit and brokered action.

Monitoring, containment, and evidence

Capture non-secret decisions and receipts, detect drift or misuse, and preserve pause, disable, revoke, rollback, incident, recovery, and audit-reconstruction paths.

Framework mapping uses NIST AI RMF and NIST CSF 2.0 as anchor lenses, with other relevant security and AI governance themes used for evidence organization. Mapping does not certify compliance or validate a customer environment.

Scaled Agents™ Security

AI Agent Control Fabric

Models generate intelligence; the control fabric governs action. It connects identity, approved scope, Human Review, policy gates, Runtime Permits, brokered execution, and evidence around customer-selected models, tools, data, and systems.

Capability is not authority. Every consequential action needs a current, reviewable path.

Control outcomes

  • Clear ownership
  • Governed access
  • Human oversight
  • Traceable evidence
  • Revocation path
Scaled Agents Customer-Managed Control Boundary diagram showing AI worker onboarding, Agent Passport assessment, Discovery Gateway, runtime governance, customer enterprise applications, optional Governance Intelligence SLM, and external connectors outside the customer-managed environment.
Identity, approved scope, tool boundaries, data limits, human approval, evidence, auditability, and revocation controls around AI worker activity.

Agent Passport

Records owner, purpose, scope, permissions, risk, lifecycle, evidence, and review obligations for each AI Worker.

Agent Registry

Maintains the governed inventory, risk tier, access boundary, dependencies, tool permissions, data classification, and lifecycle state.

Evidence Stamps

Preserve review decisions, policy checks, access outcomes, execution receipts, exceptions, and lifecycle events.

Policy Toll Gates

Apply policy and accountable Human Review before sensitive, high-impact, externally visible, or consequential actions.

Boundaries

What this page does and does not claim.

What it covers

High-level security posture, least privilege, identity-centric access, data boundaries, human approval, evidence, and readiness expectations for governed AI workers.

What remains customer-specific

Identity, access control, tenant isolation, logging, secure artifact storage, production controls, and deployment architecture must be reviewed for each customer environment. Users should seek qualified legal review and qualified expert review before relying on customer-specific security, privacy, or compliance documents.

What is not claimed

No legal advice, regulatory conclusion, compliance accreditation, security attestation, formal audit opinion, production use, or customer risk acceptance is claimed.

Public preview - Materials support readiness planning and do not authorize production use.