dont panic
Engineering, test evidence, release documentation and handover. Ongoing operation and improvement where included in the engagement.
Security & AI
We define what AI can access, what it can change and where people must approve. Data handling, infrastructure and operating responsibilities are considered from the start.
See the controls in actionA principle we build around
AI can propose an action.
The system enforces whether it is permitted.
01 · Data flow
Before connecting AI, we agree what information it needs, where it is processed, who can access it and how long it is retained. That review includes prompts, outputs, logs, backups and model-provider terms.
Processing location, retention and training terms checked for the chosen service and configuration.
The full review also covers retrieval stores, activity logs, backups and third-party access.
02 · Control in practice
The same request can be permitted, refused or held for approval, depending on who is asking, which records they can access and the rules for the action.
Illustrative control example
Example request
“Record this customer’s promise to pay.”
One request. Three illustrative authority settings.
System-enforced checks
Who is asking?
Recognised user or service.
Which records can they access?
Customer within permitted scope.
Is this operation permitted?
Requested operation permitted.
What can happen next?
Action permitted.
The request can proceed within the agreed rules.
Action rules Outcome
Agent-facing APIs and MCP interfaces expose defined business actions. Shared services enforce the permissions and rules behind each request.
This managed agent services pattern describes the interface architecture. Ongoing operation and support are agreed separately.
Illustrative behaviour only. No live systems or customer records are connected to this demonstration.
03 · Test and verify
We turn agreed rules into repeatable tests and evaluate AI behaviour against representative cases. We check what the system should allow and what it should refuse before release and again when models, tools or permissions change.
| Example request | Expected system behaviour |
|---|---|
| Update details with the required permission | Permit the update. |
| Access an account outside the caller’s scope | Refuse access. |
| Record the same event twice | Prevent a duplicate. |
Relevant cases also include misleading instructions in retrieved content, consequential changes, retries and unavailable services.
04 · Secure foundations
We define infrastructure as code using Terraform, so changes can be reviewed, reproduced and traced. The design also considers access, secrets, environment separation and recovery.
Start a conversation
Bring the proposed workflow, the systems involved and your security requirements. We’ll discuss the boundaries and what a responsible implementation would need.
Let’s talk about your business