Authority with boundaries
Distinguish the requesting user, executing agent, and connected tool. Define the scopes each action needs and the actions that require approval.
Identity map · permission inventory · approval rules
SECURITY & GOVERNANCE
Build security decisions into the lifecycle. Define who and what can act, the evidence required, and the people accountable when conditions change.
AN EXPLICIT CONTROL MODEL
Make the boundary visible before the action happens.
Identity & purpose
Scope & approval
Allowed operation
Constrained access
Illustrative control model. Place review and enforcement at the boundaries that matter to your workflow.
DESIGN · RELEASE · RUNTIME
Distinguish the requesting user, executing agent, and connected tool. Define the scopes each action needs and the actions that require approval.
Identity map · permission inventory · approval rules
Review untrusted instructions, tool misuse, sensitive information, poisoned context, and unexpected recovery paths against the actual design.
Threat register · control owner · verification evidence
Trace each criterion to a versioned evaluation result, review decision, or an explicitly accepted exception.
Evaluation matrix · release record · exception conditions
Connect observed behavior to the relevant permission, policy, and operational owner. Record the action taken and the remaining risk.
Execution trace · event record · containment decision
Define where knowledge comes from, what an agent may retain, who can access it, and when retained information should expire.
Source provenance · access policy · retention rules
Bring changes to tools, skills, models, memory, and the harness back through the appropriate review before promotion.
Change record · updated evaluations · owner approval
EVIDENCE, NOT GUESSWORK
Connect the requirement, design decision, access boundary, evaluation, and release approval. Keep the reasoning available when the workflow changes.
Explore security & governanceCHANGE REVIEW AGENT / RELEASE 0.3
DOCUMENTATION WITH ACCOUNTABILITY
Connect requirements, design specifications, evaluations, approvals, change records, and maintenance SOPs.
For GxP workflows, map documentation to your intended use, quality system, validation approach, and responsible reviewers. A generated document is an input to that process; the review and decision remain accountable.
Get the release review packSTART WITH INTENTION
Start with a bounded workflow. Define the evidence. Bring the right controls into every stage.