Trust is built into the architecture
Autonomy boundaries, human approval, audit trails and safe handoff are product capabilities, not post-launch paperwork.
Autonomy has boundaries
The control level follows action risk, evidence quality and the ability to reverse safely.
- 01Signal & context→
- 02Evidence→
- 03Risk class→
- 04Act or approve
Agents may
Search, match, draft and propose the next action.
Human required
Financial, legal and irreversible actions pass an approval gate.
Full audit trail
Evidence, input, decision and outcome are retained for audit.
Data protection
Sensitive fields are minimised, masked or excluded before entering the agent loop.
Quality testing
Scenarios are tested against reference sets, exceptions and explicit stopping criteria.
Safe handoff
Low-confidence work and exceptions go to a human with context and evidence.
We use NIST AI RMF and the GenAI Profile, ISO/IEC 42001 and the OWASP Top 10 for LLM Applications as control references. This does not imply certification.