Skip to content
OpenMethods

Security & governance

Governance in the flow of work.

Controls only matter where execution happens. In OpenMethods, identity, permissions, data scope, approvals, audit, residency, and retention are properties of the workflow itself — enforced identically whether an AI agent or a human agent is doing the work.

Control map

Controls mapped to execution steps

Each step of a governed workflow carries its own controls. This is the map security reviewers work from.

  1. Step 01

    Identify

    • Customer verification to a declared assurance level
    • Operator authentication and role resolution
    • Assurance level recorded on the interaction
  2. Step 02

    Scope

    • Field-level data scope per workflow step
    • Role-based masking before context reaches an agent or model
    • Short-lived credentials issued per execution
  3. Step 03

    Decide

    • Policy evaluated before options are presented
    • Approval and segregation-of-duties gates
    • Threshold checks against live customer and account data
  4. Step 04

    Commit

    • Transactional write-back per system of record
    • Compensation behavior on partial failure
    • Confirmation before the interaction closes
  5. Step 05

    Evidence

    • Immutable run record with workflow and connector versions
    • Retrieval and write logs attributable to user and step
    • Exportable evidence for internal and external review

Claims discipline

What we will not claim until it is verified

OpenMethods publishes security and compliance statements only from an approved claims registry with a named internal owner. The following statements are under review and are deliberately not asserted on this site.

  • Verification required · owner: CISO

    Certification

  • Verification required · owner: General Counsel

    Data use

Request current documentation, certifications, and contractual terms directly from our security team during a security review.

Questions

What security reviewers ask

Does an AI agent hold standing credentials to our systems?

No. Credentials are scoped and short-lived, issued per workflow execution, and constrained to the operations the reviewed workflow exposes.

Can we restrict which fields a workflow may retrieve?

Yes. Data scope is declared per workflow step through context contracts, and masking is applied by role before context reaches an agent or model.

What evidence exists after an automated action?

An immutable run record links the retrieved context, the decision path, the approvals applied, the committed writes, and the workflow and connector versions involved.

Where is data processed and retained?

Residency and retention behavior are configured with your security team. We do not publish blanket statements before they are verified for your deployment.

Start here

Start a security review.

Bring your control requirements and we'll walk through data scope, credentials, approvals, audit evidence, residency, and retention against a real workflow.