Governance isn't a disclaimer here. It's the product.
Client separation
Every client receives a separate Workspace identity and segregated data environment. No client can access another client's data.
Access controls
Permissions are granted per client, system, workflow and action type - never globally. The permission ladder (Observe, Analyse, Recommend, Draft, Request approval, Execute, Verify, Report, Escalate) governs every action.
Data retention
Client data is retained only as long as the engagement requires, per the terms agreed at onboarding.
Encryption
Data is encrypted in transit and at rest across the platform's storage and communication layers.
Model-provider handling
Model calls are routed through approved providers under standard data-processing terms - client data is not used to train third-party models.
Audit logs
Every execution has an initiating user or agent, a timestamp, a scope, and a result. Audit logs cannot be edited by standard users.
Human approval
High-risk actions - publishing, spend changes, mass communications, pricing changes, regulated copy - always require explicit pre-approval. Never autonomous.
Independent verification
Agent-claimed completion is never accepted as proof. A separate verifier checks the actual target-system state before anything is marked "Verified." Failed or ambiguous verification becomes a tracked exception, not a silent gap.
Incident response
Defined escalation owners and a documented incident process apply to any exception or failure.
Kill switch
Michael or Amira may independently disable client-agent execution at any time, without needing anyone else's sign-off.
Cross-border data issues
Cross-border data handling considerations are tracked as an open item for legal review before any paying client engagement - not glossed over.
Regulated vertical controls
AHPRA, TGA, National Law, and NDIS compliance gates are productised platform features for relevant clients, not generic boilerplate.