For the teams that
read the fine print.
A live audit ledger, a policy gate that sits on the action path, role-enforced retrieval, isolated runtimes, and per-team budgets that fire before the call leaves the platform.
Every action,
forensically captured.
An immutable record your auditor will read end-to-end. Streams live to your SIEM.
Audit ledger · thread #4f2e
StreamingGuardrails on
every action.
Role checks, data scope, PII, budget, approval — evaluated before execution. Not in a doc, not on a wiki, on the rail itself.
Policy gate
live evaluationRole check
Finance Analyst → allowed
Data scope
business_unit = finance
PII guardrail
redacted 12 emails on output
Budget cap
$0.04 of $25 daily
Approval
manager: tim.lou
Action allowed
send · gmail.draft
Inherited from your directory. Always.
Roles, business units, manager hierarchy, team membership — all sourced from your IdP. We never become an alternate identity store. When a user leaves, their access leaves with them on the next sync.
Controls in this layer
- Entra ID and Okta supported out of the box
- Manager-led ownership inferred and surfaced
- No bypass keys, no internal admin override
- Sign-in activity captured for dormant detection
Bounded by design.
When an agent runs code, drives a browser, or opens a development session, it lands in an isolated runtime. Per-invocation isolation. No persistent state. No shared credentials. No internal network reach unless you grant it.
Controls in this layer
- Per-invocation isolation, no leftovers
- No inherited platform credentials
- Hard execution budget per run
- Per-org sandbox tenancy on enterprise
Stays where it lives.
EmployeeX retrieves under role from your existing data stores. We don’t copy your data into a private vector index by default. If you opt into indexing for performance, content stays inside the residency you choose.
Controls in this layer
- Australia, Europe, and US residency options
- AES-256 at rest, TLS 1.2+ in transit
- Per-tenant data isolation
- BYOK and customer-managed keys on enterprise
Cost, governed.
Every model call hits a per-team budget. Caps fire before the call leaves the platform. Finance sees real allocation per team, per profile, per channel — not a surprise invoice at month end.
Controls in this layer
- Per-team monthly budgets, hard or soft caps
- Per-profile cost attribution
- Per-channel cost reporting
- Pre-flight budget check on every request
For the teams that read the fine print.
SOC 2 posture, governance policies per profile, evals against datasets, drift alerts. The same trail your security team will audit, your operations team can read.
Controls in this layer
- SOC 2 Type II posture (in progress)
- Configurable governance policies per profile
- Eval datasets and drift alerts
- Tenanted deployments per business unit
Bring your security team to the call.
30 minutes on a sandbox tenant. SOC 2 posture, residency, encryption, isolated runtimes, the audit ledger live, the policy gate evaluating in real time. Every question they’ll ask — answered on screen.
Want a deeper look?
Bring your security team. We'll walk through the audit ledger, the policy gate, and the residency options on a sandbox tenant of your choice.