One user, one permission boundary.
Map SSO identity, groups, roles, source ACLs, and service principals before retrieval or action.
Trust center
Review the identity, permission, data, model, tool, and evidence boundaries that must be resolved before production access.
Control plane
Governance follows the request from identity to retrieval to reasoning to action. Every boundary can apply policy, stop execution, request review, and preserve evidence.
Map SSO identity, groups, roles, source ACLs, and service principals before retrieval or action.
Classify, mask, exclude, regionalize, and retain enterprise data according to purpose and policy.
Set task-level model policies, prompt controls, fallback routes, cost limits, and restricted-use rules.
Use tool allowlists, field scopes, confidence thresholds, human approvals, and bounded credentials.
Retain the request, identity, context, citations, model route, policy result, approvals, and action outcome.
Assurance status
S/Runtime is presented here as an enterprise architecture and design-partner platform. This public site does not claim independent certification, authorization, or production suitability for a regulated environment.
Architecture, control model, solution patterns, and an illustrative product simulation.
Data flow, source and model boundaries, control ownership, retention, incident paths, and evaluation scope.
Generally available, configurable, pilot, and planned capabilities must be recorded in the engagement scope.
No certification, ATO, compliance attestation, or third-party assessment is represented by this website.
Agent threat model
Agent security extends beyond model safety. These are design requirements to validate in a pilot threat model, not blanket guarantees that every deployment has already implemented them.
Treat retrieved content and tool output as untrusted; separate system policy from content and evaluate suspicious instruction patterns.
Track source authority, freshness, ownership, conflicting evidence, and retrieval coverage before context is accepted.
Authorize memory writes separately from reads; scope personal, team, and enterprise memory with retention and deletion rules.
Keep credentials outside model context, delegate narrow scopes, validate parameters, and re-authorize consequential actions at execution time.
Restrict destinations, network paths, objects, fields, rates, and action sequences; use idempotency and compensating workflows where possible.
Provide pause, revoke, disable, escalation, and incident paths with accountable owners and preserved evidence.
Request-to-action evidence
Data and model boundary
These are required design decisions for an engagement. Provider, region, retention, deletion, support-access, and model-training terms are not implied by the public preview.
Define what is indexed, embedded, cached, streamed at query time, or left only in the source.
Record approved providers, prompt contents, regional routes, retention terms, and restricted-use policy.
Set retention by artifact, deletion propagation, backup handling, legal holds, and evidence minimization.
Limit and record support access, privileged operations, emergency paths, and customer revocation.
Name reporting contacts, severity paths, recovery ownership, evidence preservation, RTO, and RPO targets.
Attach dates, scope, exceptions, owners, and expiration to every assessment or control artifact.
Control alignment
These are control-mapping and evidence workflows, not claims of certification. Final applicability and assurance depend on your deployment, contracts, processes, and audit scope.
Applicability, control ownership, evidence sufficiency, and audit conclusions remain the responsibility of the customer and its qualified assessors. Read the public-site privacy boundary.
Architecture session
We will map the context, systems, decisions, controls, actions, and success measures together.