SECURITY & GOVERNANCE — FOR THE CISO, THE AUDITOR, AND THE CFO AT 11PM

Why letting agents near a ledger isn't insane.

Because they're never actually near it. Agents don't hold write access to the ledger — every write, from any actor, goes through the same governed gateway your controllers use, with the same dry-run, the same lanes, the same immutable trail. This page proves it instead of claiming it.

AUTONOMY IS EARNED, NEVER GRANTED

Every agent climbs the same ladder.

An agent starts blind and earns each rung with evidence. You promote it; you can demote it in one click. No agent skips a rung — including ours.

RUNG 1
Observe
Reads real documents, proposes nothing that leaves the sandbox. Its proposals are scored against what your team actually did.
GATE: ACCURACY EVIDENCE, REVIEWED BY YOU
RUNG 2
Recommend
Proposals flow into approval lanes. A human signs every single one. The agent's job is to make signing take seconds.
GATE: SUSTAINED LANE APPROVAL RATE
RUNG 3
Execute within thresholds
Auto-posts inside limits you set — amount, vendor class, exception type. Everything else still waits for a signature.
GATE: YOUR THRESHOLDS, WIDENED BY YOU ONLY
RUNG 4
Autonomous, monitored
Runs the volume work with full audit rows and live monitoring. Any anomaly demotes it back down the ladder — instantly, by you or by policy.
DEMOTION: ONE CLICK, ANY TIME
THE ARCHITECTURE ARGUMENT

One gateway. No side doors.

HUMANS
Controllers, accountants, CFO
AGENTS
LLM, code, hybrid — all of them
THE GOVERNED GATEWAY
typed transactions · dry-run · risk lanes · RBAC + entity scoping
THE LEDGER
immutable rows · double-entry · schema-per-organization isolation

There is no API that skips the middle box. A compromised agent can propose garbage — and garbage fails dry-run, lands in a lane, and leaves a trail. That is the whole argument.

THE DUE-DILIGENCE LIST

Controls, stated plainly.

ONE WRITE PATH
Agents never write directly. Every write — human or agent — goes through the governed gateway: typed transaction, dry-run, lane, audit row.
RBAC + ENTITY SCOPING
Every actor, human or agent, is scoped to the entities and transaction types it may touch. A UK billing agent cannot see the EU payroll ledger.
IMMUTABLE AUDIT ROWS
Who proposed, what the dry-run checked, who approved, what posted. Append-only; corrections are new entries, never edits.
ENCRYPTED CREDENTIALS
Bank and system credentials stored with AES-256-GCM; agents receive scoped, expiring access — never the keys themselves.
OAUTH 2.1 + API KEYS
Modern authentication for humans and machines; MCP access uses the same identity and scoping model as everything else.
SCHEMA-PER-ORGANIZATION
Each organization runs in its own database schema. Isolation is structural, not a WHERE clause.
CERTIFICATIONSWe show badges only for audits we've passed. Ask us where we are in the process and we'll show you the roadmap and the evidence — not a logo wall. Today that means: Artifi's own SOC 2 attestation is on the roadmap, not yet held; Anthropic holds SOC 2 Type II for the AI layer we build on.

Bring your security questionnaire.

A session with our team and yours — architecture, isolation, the gateway, and the audit trail, answered line by line.

Book a security review