1. Passport
Define the AI Worker’s human owner, purpose, approved scope, permissions, prohibited actions, risk tier, lifecycle, and review obligations.
Security
Scaled Agents™ connects identity, least privilege, Human Review, action-time authorization, controlled execution, monitoring, and evidence across the AI Worker lifecycle—so teams can govern what an AI Worker may do, under which conditions, and with whose accountability.
Governed Action Path
The licensed, customer-managed AI Worker Control Plane is designed to keep standing eligibility separate from action-time authority. In an implemented customer environment, missing ownership, scope, approval, policy, evidence, or a safe execution path should cause the action to pause, block, or escalate.
Define the AI Worker’s human owner, purpose, approved scope, permissions, prohibited actions, risk tier, lifecycle, and review obligations.
Evaluate policy, data, tool, cost, autonomy, destination, and consequence before higher-risk work can continue.
Issue short-lived, scoped authority for one eligible action only after current identity, policy, approval, and evidence checks pass.
Mediate approved execution through the governed path and deny direct, substituted, stale, or out-of-scope requests.
Record decisions, execution receipts, exceptions, lifecycle events, and outcomes so accountable reviewers can reconstruct what happened.
Security Control Model
The architecture connects AI Worker records, Model & Provider Dependency Records, tool permissions, data boundaries, runtime decisions, monitoring, and incident paths without treating a draft record as approval.
Bind each AI Worker to a human owner, approved purpose, risk tier, permitted actions, resources, destinations, and lifecycle. Broader capability never creates broader authority.
Classify data, review providers and dependencies, constrain retrieval sources, allowlist tools and actions, validate parameters, and keep secrets and restricted content out of public or unauthenticated paths.
Recheck Passport, policy, Human Review, evidence freshness, tool authorization, destination, and revocation state before issuing a scoped Runtime Permit and brokered action.
Capture non-secret decisions and receipts, detect drift or misuse, and preserve pause, disable, revoke, rollback, incident, recovery, and audit-reconstruction paths.
Framework mapping uses NIST AI RMF and NIST CSF 2.0 as anchor lenses, with other relevant security and AI governance themes used for evidence organization. Mapping does not certify compliance or validate a customer environment.
Scaled Agents™ Security
Models generate intelligence; the control fabric governs action. It connects identity, approved scope, Human Review, policy gates, Runtime Permits, brokered execution, and evidence around customer-selected models, tools, data, and systems.
Capability is not authority. Every consequential action needs a current, reviewable path.
Control outcomes
Records owner, purpose, scope, permissions, risk, lifecycle, evidence, and review obligations for each AI Worker.
Maintains the governed inventory, risk tier, access boundary, dependencies, tool permissions, data classification, and lifecycle state.
Preserve review decisions, policy checks, access outcomes, execution receipts, exceptions, and lifecycle events.
Apply policy and accountable Human Review before sensitive, high-impact, externally visible, or consequential actions.
Boundaries
High-level security posture, least privilege, identity-centric access, data boundaries, human approval, evidence, and readiness expectations for governed AI workers.
Identity, access control, tenant isolation, logging, secure artifact storage, production controls, and deployment architecture must be reviewed for each customer environment. Users should seek qualified legal review and qualified expert review before relying on customer-specific security, privacy, or compliance documents.
No legal advice, regulatory conclusion, compliance accreditation, security attestation, formal audit opinion, production use, or customer risk acceptance is claimed.