Security

Automation should not create a new security problem.

Giving an AI service unrestricted access to company systems is not a strategy. New automation should follow the same security principles expected of established business technology.

Least privilege

Systems and services receive only the access required for the task, not blanket access because it is convenient.

Clear data boundaries

Understand what information leaves your environment, which services process it and why that access is necessary.

Human control

Where decisions carry commercial, financial, safety or security consequences, automation can prepare the work without silently taking responsibility for it.

Controlled integration

Work with existing identity, access and security controls rather than bypassing them to make an automation easier to build.