📋

Report-Only Mode

Agents start in report-only mode — they observe, classify, and draft. No live write or send action occurs until an operator explicitly approves the output. Your operations stay visible before they become actions.

🔐

Approval-Gated Workflows

Every workflow output sits in an approval queue. Agents cannot bypass the gate. Operators review the draft, context, and risk summary — then decide. Approved, rejected, or revision-requested actions are all logged.

🚫

No Silent Production Patching

Cliphorium agents do not autonomously modify production systems. If a remediation or update is recommended, it is staged as a draft and surfaced for your review. Your production environment requires your sign-off.

🛡️

Scoped Access

Each agent is granted the minimum access required for its defined workflow. Read access is separated from write access. Agents cannot escalate their own permissions or access systems outside their configured scope.

🗂️

Audit Trail

Every agent action, approval decision, and workflow event is written to a structured audit log. Your operations lead or decision maker can review the full history of what was seen, drafted, approved, and executed.

🔑

Credential Handling

Credentials and API keys required for agent workflows are handled through scoped secrets, read-only access where possible, and customer-specific configuration. They are not intentionally exposed in public pages, logs, or shared across customer contexts.

🔎

Security Review Agent

The optional Security Review Agent runs scheduled read-only scans of your configured scope. Findings are surfaced as a draft report — nothing is remediated until your security lead or owner reviews and approves.

🧩

Context Isolation

Customer contexts are designed to remain separate across deployments. Agent workflows, data, credentials, and audit trails are scoped to each customer environment so work from one deployment is not mixed with another.

Escalation Routing

High-risk flags or ambiguous scenarios are automatically escalated to the designated decision maker. Agents do not resolve uncertainty by acting — they surface it for human judgment first.

Security Questions?

If you have specific security requirements, compliance questions, or want a scoping session for your stack, book a free audit call. We review your environment before any agent is deployed.

Book Security Scoping Call