The controls are in the product, not in the contract.
Governance that lives in a policy document is a promise. Here the rules are built into the product: who can see what, what every action records, and a check that refuses to let an unproven model make decisions.
In plain termsThe controls are enforced by the software, not left to people remembering the policy.
What is enforced, and where
| Control | Enforced by |
|---|---|
| Tenant isolation | Row-level security in the database, not application filtering |
| Role-based access | Role and workspace checked on every request |
| Single sign-on | OIDC |
| Multi-factor authentication | MFA challenge on login |
| Directory provisioning | SCIM |
| Action audit trail | Every action recorded with the acting user, tenant-scoped |
| Policy and rule governance | Policies and rules are versioned objects, not free text in a wiki |
| Limits and budgets | Per-domain limits and budget ceilings, evaluated by the platform |
| Model promotion gate | Refuses on provenance, divergence, null-baseline and unmeasured-horizon checks |
| Override logging | A human may override a refusal; the override is attributed and recorded |
Tenant isolation in the database. If isolation lives in application code, one missing filter is a cross-tenant leak. We push it into the database so the application’s failure mode is closed, not open.
A gate that can refuse. The promotion gate stops an unvalidated model from reaching production, and its refusals are recorded with reasons. See decision horizon.
Fictional reference world: OgMartWhat the platform is allowed to do, by edition
| Edition | Purpose | Contains |
|---|---|---|
| Demo | Evaluation on a reference world | A built-in simulator and fictional reference worlds |
| Beta | Production-shaped operation without a simulator | Real sources only |
| Enterprise | Regulated, multi-tenant deployment | The full governance surface |
The simulator exists only in the demo edition. A production deployment cannot accidentally run a fictional world, because the edition gate removes the capability rather than the button.
What touches your systems
- Read-mostly. Consuming events and reference data does not require write access to your production systems.
- Explicit actions only. Any write to an external system goes through a named, audited action. There is no background write path.
- Failed events are visible. Ingest failures land in a dead-letter view; they are not dropped silently.
- Reversibility. Actions are recorded with their outcome, so an unintended action is a documented event with a known actor rather than an unexplained change.
Claims discipline
Authority is granted, not assumed
Every automatic action sits inside a grant you wrote, and the conflict gate can withdraw it.
Put your security reviewer in the room
A controls conversation is more useful than a document. Bring the questionnaire.