Skip to content

Governance and Security

Trust nothing by default, and record everything that happens anyway.

Zero secret exfiltration

Agents never hold secrets. On credential creation you pass a temporary placeholder that is resolved at runtime, so the model never receives the real value. A prompt injection cannot leak what the agent never received. In the self-hosted build a sidecar proxy intercepts outbound requests and substitutes the reference with a value fetched from the secret store.

Credential injection in six steps. The agent sends a request holding only a
placeholder, so it never held the real credential. The injection proxy resolves
the placeholder against the secret store, calls the external tool with the real
secret, and passes the response back. The swap happens outside the agent, so a
prompt injection has nothing to
leak.

Dynamic skill creation

AgentZ can generate a reusable skill out of a workflow you already ran, so the second person to need that job does not rebuild it.

Tool-level permissions and approval gates

Roughly 6% of teams want full automation. The rest want to confirm before an action runs, so the default is to suggest a next step rather than remediate automatically. See Connecting Integrations for the three permission levels.

Workspace-level compute delegation

An Enterprise feature.

Coming soon

This section will cover what an admin delegates, and who receives it.

Audit logs and observability

Every tool call, memory read and model response is recorded with a deterministic replay id. An auditor can replay any run exactly as it happened. Egress is recorded by domain, port and protocol, allowed or blocked, so nothing leaves without a record.