Documentation

Trust · Guide 08

Security and deployment boundaries

Understand what Rulebook protects, what depends on topology, and where enterprise controls remain essential.

8 min read

Pre-release documentation. This guide describes the current product design and evaluation build. Packaging, availability and commercial terms may change before release.

01

Deterministic operation without hidden model dependency

A published Rulepack can serve T0 decisions without a model call. Strict callers must not observe model network activity. T1 to T3 use only the provider and credentials configured by the operator.

  • No model is needed to verify a receipt
  • The T2 executor has no model, network, filesystem or clock access
  • Model use is labelled and recorded
  • Secrets are referenced rather than stored as literals in configuration
02

Authorization layers

Rulebook complements identity, network and data security controls. It uses those systems' signals to evaluate enterprise policy and must not become a bypass around them.

  • Authenticate identities through the enterprise control plane
  • Authorize rulebook and workspace access separately from decision access
  • Keep activity-reading permissions distinct from decision permissions
  • Place the gateway on the only network path to protected tools
03

Boundaries to design for

  • An agent that can reach a tool outside the gateway is not enforced
  • An unconfirmed rule cannot block an action
  • A vague rule with no capability mapping cannot be machine-enforced
  • A human can confirm an incorrect extraction
  • A compromised reviewer account can misuse confirmation authority
  • T1 to T3 content is exposed to the configured model provider according to that provider's terms

Executive briefing

Apply the architecture to one consequential workflow.

Bring one consequential agent workflow. We will map the governing policies and regulations, runtime gate, human authority and auditable evidence path with your team.

Request a briefing