Controls
AI and Agent Controls
What the agents can and cannot do, who approves the sensitive actions, and what record each run leaves.
Scoped Integration Access
An agent can retrieve only from the knowledge sources and call only the tools that a workspace administrator has connected for it. There is no ambient access to systems outside that grant, and each integration is scoped to the permissions it was given rather than to the permissions of the person who connected it.
- ISO 27001 A.5.15 (access control)
- NIST AI RMF MANAGE 2.1
- SOC 2 Confidentiality
Human Approval on Sensitive Actions
Actions that change state in a connected system can require an approver before they run. Sensitive actions are gated by default and the gate is configurable per workspace, so an administrator decides where the agent acts on its own and where a person signs off first.
- ISO 27001 A.5.15 (access control)
- NIST AI RMF MANAGE 4.1
- EU AI Act Art. 14 (human oversight)
Deterministic Execution for State-Changing Operations
Anything that changes state runs through a deterministic flow rather than through free-form model output. The model chooses which flow to invoke and with what inputs; the flow itself is code, with its own validation and its own permissions.
- NIST AI RMF MEASURE 2.6
- ISO 27001 A.8.28 (secure coding)
Agent Run Audit Record
Every agent run produces a step-by-step record of what it retrieved, which tools it called, what it changed and why. The record is available to workspace administrators and is retained with the rest of the workspace audit log.
How it is checked: Produced automatically for every run, and retained with the workspace audit log.
- ISO 27001 A.8.15 (logging)
- NIST AI RMF GOVERN 1.5
- EU AI Act Art. 12 (record-keeping)
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
All controls