Is the agent allowed to act?
Access controls answer who can use which tool—and within what limits.
Identity, tool access and action scope are table stakes for any agent platform. Company Brain adds the control access platforms cannot see: whether the knowledge behind an already-authorised action is still current and approved.
THE TWO CONTROLS
TWO SEPARATE JOBS, RUN TOGETHER
Access control decides whether an agent is authorised. Knowledge control decides whether what it is about to say is still true. Company Brain runs the second job alongside your existing access-control platform—not instead of it.
Access controls answer who can use which tool—and within what limits.
Knowledge controls answer whether the guidance is current, owned and released for use.
Execution controls answer whether the model and provider are approved for this workload, inside its cost and quality boundary.
The agent has permission, current knowledge and an approved execution path.
✓One isolated production environment is deployed into infrastructure you provide and control. In the standard configuration, document content and inference stay inside that environment; a premium hosted model is optional and off unless you enable it.
Source credentials are encrypted before they reach the database, with cryptographic separation per source. Production start fails closed rather than use a key ring that could leave credentials unrecoverable.
Governance-critical changes are written to an append-only, hash-chained record. The chain can be verified on demand and reports the sequence where a break is detected.
No knowledge reaches a published state without cited, hash-verified evidence and a named reviewer's decision. The deterministic grounding checks sit on one release path.
The deployment boundary, internal test evidence and an explicit list of what is not certified live on the full security and deployment page—including what Company Brain manages, what the customer still controls, and where independent certification is still planned rather than held.
See security & deployment →