Security

You choose what Glaux can access and do.

Glaux puts company rules in the path of work. Admins decide which people and teams can use which knowledge, tools, models, and sensitive actions, and when a person must approve the next step.

External customer summaryPolicy check before action
Requested action

Send the summary outside the company workspace.

Before action

Rule applied: approval is required before anything is sent.

AfterwardResult recorded

The activity history records the request, decision, outcome, and policy context that applied.

Controls cover the people and the action.

Security starts with plain boundaries: who is asking, which team they are working in, what source or tool is involved, and whether the next step needs approval.

People

Choose which employees, service accounts, and roles can request governed work.

Teams

Group permissions by workspace or team so access follows how the company operates.

Tools

Make approved connections available only where they belong, with unsafe requests stopped before use.

Models

Set which model and provider choices are available for the work being done.

Sensitive actions

Require approval or stop work before high-impact actions such as external sharing or data export.

Approval and access requests

People can ask without leaving the task.

When work needs access to a source, tool, model, or sensitive action, the request stays attached to the reason for the work. Approvers see the context before deciding.

Access requested

Use customer-success knowledge source

Reason: answer a renewal-risk question with the approved source trail visible.

The user asks for a tool, source, model, or action from the task.The request keeps the reason, workspace, and approver path together.Work continues only when the request is approved or already allowed.

Prevention and evidence are different jobs.

The rule is checked before the action. The record is written after the result. Glaux should not make teams wait for after-the-fact evidence to find out whether an action was allowed.

Before action

Apply the rule

Check identity, workspace, approved source, tool, model, policy, and approval requirements before a governed read or side effect happens.

Afterward

Record the result

Keep the outcome visible through activity history, approval history, and audit-oriented admin views.

Activity history supports admin visibility.

Security and governance teams need to see where controls applied without turning internal secrets or raw configuration into visitor-facing explanations.

Recorded

Activity history

Admins can review what moved ahead, what needed approval, and what stopped before action.

Visible to admins

Admin visibility

Security reviewers get a governance view without exposing secrets, private prompts, or raw internal configuration.

Data and deployment diligence

Inventory first. Guarantees only when approved.

A security review should map the real categories involved: people and groups, approved knowledge sources, tool connections, model choices, skills, automations, approvals, access requests, and activity records.

What we confirm during diligence

Glaux treats deployment, data handling, and evidence sharing as review topics until the approved terms are clear for your environment.

Which deployment boundary applies to your environment?Which retention, residency, deletion, and export terms have been approved?Which security evidence can be shared with your reviewers?
For security teams

Review the controls behind governed work.

Authentication

Service calls are authenticated and versioned before protected Control Tower paths accept them.

Request integrity

Signed Control Tower service requests bind method, path and raw query, request ID, contract version, and body hash, with replay protection.

Isolation

Control Tower owns authorization, approvals, runtime activity, audit, and safe projections while clients can request and display decisions but cannot grant authority.

Redaction

Admin and activity surfaces should expose safe explanations and audit pivots, not secrets, private prompts, or raw credentials.

Audit

Audit-oriented admin views are designed for filtered lookup and controlled export rather than public log exposure.

Standards posture

Alignment language only.

Glaux security posture supports alignment with NIST AI RMF and OWASP agentic, MCP, and agentic skills guidance as design input. Standards are design input here, not proof of third-party review.

Start security diligence