Security
Security
Any work you hold for approval reaches a client only after a person approves it. That is a human in the loop. These controls apply on every screen, in the phone app and to outside tools that connect to GHOTED.
Approval by a person
- Held work waitsA person approves it before a client sees it.
- Estimates wait for a personA client sees an estimate only after a person approves it.
- The client signs to acceptNothing is billed for work nobody has said is finished.
Permissions
- Three settingsEach kind of work goes ahead, is held for approval or is not allowed.
- Tighter for one jobA single job can be tighter than the company setting, never looser.
- Spending limitsEach company and each job has a spending limit. An agent at its limit stops.
- Connected tools start switched offEvery tool in a connected system starts as not allowed. You turn on each one.
Data and models
- Database in SydneyThe database is in a Sydney data centre.
- Zero data retention for model callsModel calls run under a zero data retention policy.
- Your own connected systemsA tool from your own connected system follows that system’s terms. It is not eligible for zero data retention.
- Your choice of model providerYou bring your own model key. For sensitive information, GHOTED recommends frontier models available under zero data retention terms.
Records
- Agent runsActivity records the agent, the job, the result and the cost of each run.
- DocumentsEvery version is kept, with a fingerprint of the version a client accepted.
- Decisions and change requestsEach one records who raised it, who answered it and when.
Access
- Rules in the databaseEvery read and write is checked against the person signed in.
- Partners work on setupA partner reaches the setup of a company it brought on. It does not reach that company’s client work, documents or keys.
- Clients see their own workA client reaches its own work and nothing else.
- Credentials are encryptedCredentials for your own systems are encrypted with AES-256-GCM. They never appear on a screen or in a log.
Agent identity
No binding global standard for agent identity exists yet. The bodies working on it agree on the architecture, and GHOTED is built to that architecture today.
- An agent is a configured roleYour settings decide which agent does each kind of work. Every run records which agent it was.
- Keys for outside toolsEach key is stored as a hash, carries its own list of permitted tools and can be revoked on its own. A key can also be set to sign its requests.
- Authority for one requestA call on a key borrows the authority of the person who made the key. That authority ends when the request finishes.
- Person, agent and key on every callEvery call from an outside tool records the person, the agent and the key.
- Permissions for each kind of workEach kind of work goes ahead, is held for approval or is not allowed. A single job can be tighter than the company setting, never looser.
- Spending ceilingsSpending is capped for each company and each job. An agent at its ceiling stops.
The work on agent identity is under way in these places, and none of it is an adopted standard yet.
- NIST’s AI Agent Standards Initiative researches agent authentication and identity.
- NIST’s COSAiS project is developing SP 800-53 overlays for single-agent and multi-agent systems.
- An IETF charter for DAWN covers how agents are discovered across organisations.
- A W3C community group is writing specifications for agent identity based on verifiable credentials and decentralised identifiers.
Proof that holds up later
- Signed requestsA key used by an outside tool can be set to sign its requests with Ed25519. Signing is optional for each key.
- What a signature provesOn a key set to sign, the record shows the holder of the key sent the exact request recorded. The portal keeps the signature with the call.
- Checkable without trusting GHOTEDAnyone with the public key can check the record later. They do not need to take GHOTED’s word for it.
- Non-repudiationNon-repudiation means the holder cannot deny sending a request. Six conditions carry it, and the portal meets four.
- The four the portal meetsThe private key exists only on the holder’s machine. The evidence outlives the check. A signature covers one request and no other. A public key cannot be swapped.
- The two the company meetsGive one key to one person or one system, so a signature names somebody. Where a dispute could turn on time, take timestamps from a source both sides accept.
- The version a client acceptedThe portal keeps a fingerprint of exactly what a client accepted.
- Retrieval over your own documentsAgents retrieve passages from your own documents and records. Each search runs under the same database policies as every other read.