Every AutomatedAgents team ships with permission-scoped agents, human approval gates, and tenant-isolated infrastructure. Controls exist before the sales call, so your security review confirms what's already live.
These aren't aspirational — they're enforced by the deployment layer every team runs on.
Every agent declares a job card with its exact permission surface. A certification gate verifies the agent's tools match the card before the team goes live — stripped terminals, no surprise capabilities, no lateral movement.
Irreversible actions — money movement, deletes, public posts, trades — route through approval. An autonomy broker enforces the tier you set per agent. The agents suggest; you approve.
Each customer runs on a dedicated server with its own agents, memory bus, and integrations. No shared infrastructure between tenants, no cross-customer data paths.
Each control below is part of the deployed system, not a promise on a slide.
Every agent has a declared permission surface verified before go-live. Customer-facing agents run with restricted tooling: no terminal, no file writes, no code execution — messaging and domain tools only.
Enforced at deploymentTrivial actions run automatically. Irreversible actions require human approval. You set the autonomy tier per agent, and the broker enforces it on every action.
broker.pyTeams are reachable by text via Twilio — but only from approved numbers. Access is default-deny: unauthorized senders cannot reach agents or trigger actions.
Default denyAgent system definitions include anti-injection guardrails so external content — emails, web pages, tickets — can't redirect an agent outside its role.
Built into agent definitionsA synchronous orchestrator ticks across the team, validating every agent reported in and checking shared budgets before jobs fire. Actions are logged and traceable.
Mesh orchestratorAgents share a structured memory bus with handoff schemas — scoped to the team and tenant. Agents start each session knowing what the team already decided, with no cross-tenant bleed.
MnemosyneTrading teams enforce fixed loss caps, trailing drawdown limits, and concentration limits — and a kill switch halts all new orders the moment a limit breaches. Risk limits are structural, not aspirational.
Trading teamsStructured playbooks govern how work flows through the team — request-to-handoff, safe feature changes, incident response, weekly ops reviews. Agents know their evidence boundaries and when to escalate.
OMH governance layerWe'd rather tell you exactly where we are than let you discover it mid-procurement.
AutomatedAgents is not yet SOC 2 or ISO 27001 certified. We're building toward SOC 2 Type I/II as the first certification, because that's the framework US buyers actually ask for.
Our security and compliance contact responds directly — no ticket black hole.