AI and Agent Controls
Scoped Integration Access
An agent can retrieve only from the knowledge sources and call only the tools that a workspace administrator has connected for it. There is no ambient access to systems outside that grant, and each integration is scoped to the permissions it was given rather than to the permissions of the person who connected it.
Framework requirements this speaks to
- ISO 27001 A.5.15 (access control)
- NIST AI RMF MANAGE 2.1
- SOC 2 Confidentiality
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
Need the evidence behind this?
Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.