Accounts and access
Secure sessions, email verification, optional TOTP MFA, five workspace roles and tenant-scoped authorisation.
Security claims should be inspectable. This page separates product controls, evidence boundaries, operational checks and work that still requires independent assurance.
AgentRiskLayer does not treat a questionnaire answer as technical proof. Each evidence class remains visible and separately labelled.
What the customer says exists.
What code, configuration or connected systems show.
Where a supported exposure or control weakness remains.
What an authorised controlled test reproduces.
What a live policy allowed, denied or paused.
Who approved the exact high-impact action.
Who owns the fix and what changed.
Whether the same risk remains controlled.
Proceed, hold or do not deploy—with limitations.
These are product controls, not claims of certification. Exact implementation and operational status should be checked against the current release and readiness evidence.
Secure sessions, email verification, optional TOTP MFA, five workspace roles and tenant-scoped authorisation.
Versioned policies screen prompts, outputs and tool calls before an application acts.
High-impact approval is server-issued, expiring, bound to the complete action and consumed once.
Hosted Guard evidence records decisions, rules and digests rather than raw prompts, outputs or tool arguments.
Reports, Inspector bundles and controlled test artifacts include hashes or signatures where appropriate.
Production readiness, health, protected metrics, database backup controls and documented restoration procedures.
Different workflows need different data. The boundaries below prevent one broad claim from hiding important differences.