STAGING — DRAFT CONTENT — NOT INDEXED — NOT PRODUCTION
Trust and Control

Governance isn't a disclaimer here. It's the product.

Client separation

Every client receives a separate Workspace identity and segregated data environment. No client can access another client's data.

Access controls

Permissions are granted per client, system, workflow and action type - never globally. The permission ladder (Observe, Analyse, Recommend, Draft, Request approval, Execute, Verify, Report, Escalate) governs every action.

Data retention

Client data is retained only as long as the engagement requires, per the terms agreed at onboarding.

Encryption

Data is encrypted in transit and at rest across the platform's storage and communication layers.

Model-provider handling

Model calls are routed through approved providers under standard data-processing terms - client data is not used to train third-party models.

Audit logs

Every execution has an initiating user or agent, a timestamp, a scope, and a result. Audit logs cannot be edited by standard users.

Human approval

High-risk actions - publishing, spend changes, mass communications, pricing changes, regulated copy - always require explicit pre-approval. Never autonomous.

Independent verification

Agent-claimed completion is never accepted as proof. A separate verifier checks the actual target-system state before anything is marked "Verified." Failed or ambiguous verification becomes a tracked exception, not a silent gap.

Incident response

Defined escalation owners and a documented incident process apply to any exception or failure.

Kill switch

Michael or Amira may independently disable client-agent execution at any time, without needing anyone else's sign-off.

Cross-border data issues

Cross-border data handling considerations are tracked as an open item for legal review before any paying client engagement - not glossed over.

Regulated vertical controls

AHPRA, TGA, National Law, and NDIS compliance gates are productised platform features for relevant clients, not generic boilerplate.