Security

Control belongs
in the architecture.

Afluma treats identity, permissions, visibility and recovery as product requirements for AI-enabled operations.

Security model

Before an agent acts,
the boundary should be clear.

Useful automation starts with explicit scope. High-impact access is not justified by a confident model response or a professional-looking persona.

01 / Least authority

Grant the minimum useful access.

Permissions should be scoped to the task, system, data boundary and time window rather than inherited from a broad persona title.

02 / Inspectable change

Know what changed and why.

Operational work should preserve request context, intended action, accountable owner and a verification step.

03 / Recovery

Design the way back before acting.

Changes that can fail need an explicit recovery or escalation path before automation is expanded.

04 / Disclosure

Do not imply certifications.

Security requirements, data handling and compliance posture must be confirmed for the actual implementation and jurisdiction.

IdentityPermissionVerified action