Least privilege
Agents should access only the context and actions required for an approved workflow.
Optimus products are being designed around permissions, data protection, auditability, and human oversight for sensitive workflows.
Discuss your requirements ↗We communicate the controls we are designing toward without claiming certifications or capabilities that have not been verified.
Agents should access only the context and actions required for an approved workflow.
Consequential actions stay open to review and approval, especially in early product stages.
Collect and retain only what a workflow needs, with retention designed to be configurable.
Make it possible to distinguish source data, calculations, AI interpretation, and approved action.
Architect customer data and permissions around clear organizational boundaries.
Use deterministic calculations where precision matters and constrain AI to appropriate tasks.
For consequential financial outputs, the authoritative numbers should come from verified data and deterministic code — not from a language model.
Optimus does not claim SOC 2, ISO 27001, HIPAA, PCI, private-VPC deployment, or zero data retention unless and until each statement is factually established.
As products move from prototypes to live workflows, controls will be documented against the actual architecture, customer requirements, and independent verification.