Layers of control
| Layer | Controls |
|---|---|
| Identity | Who signed in and which organization or operator context applies. |
| Data | Which sources, schemas, records, and fields are exposed. |
| Tools | Which read or write capabilities the agent and plugins receive. |
| Actions | What may run automatically, needs approval, stays human-only, or is denied. |
| Runtime | Where code runs and which network destinations it may reach. |
| Evidence | What the deployment records and where audit material is retained. |
A safe rollout sequence
- Begin with a read-only source and one named operating job.
- Confirm the AI's explanation against the system of record.
- Add an approval-gated action with narrow inputs and limits.
- Review action and audit history before increasing automation.
- Document permanent human boundaries and test that they cannot be bypassed.
Know the compliance boundary
The operator remains responsible for deployment architecture, endpoint security, identity administration, data classification, retention, incident response, and the controls supplied by surrounding infrastructure.