Agentic AI · Governance
How we govern AI agents
Every agent we deploy runs inside the same six controls. This page explains each one and who owns it on your side.
Owner: process owner
Approval gates
Actions above a risk threshold wait for a named approver. We set thresholds for each workflow with the person who owns the process.
Owner: IT security
Role-based permissions
Each agent has its own identity with the least access it needs. An agent never acts as a person.
Owner: data protection officer
Data boundaries
We define what each agent may read, write and send, and block everything else by default.
Owner: risk and audit
Audit logs
Every prompt, decision, tool call and approval is recorded and kept for your retention period.
Owner: operations
Rollback and stop
Any step can be reversed where the target system allows it, and any run can be stopped at once.
Owner: CISO
Model provider controls
Approved models, hosting regions and retention terms are fixed for each deployment. We configure providers so your data is not used to train shared models.
Take this to your security review
The security pack includes our full AI governance policy and control mappings, shared under NDA.