Security
Your agents work. Your rules apply.
Every accepted business action passes identity, permission, validation and workflow checks. Review what ORYH controls, what your agent provider controls, and how your company manages access across both.
Identity & authentication
Every action resolves to a verified person or explicit service identity in the correct company.
Authorization
Role and capability checks are evaluated at the durable system boundary for every action.
Data separation
Company identity and data boundaries are enforced independently of agent prompts or memory.
Workflow integrity
Schema validation and legal state transitions reject incomplete or unauthorized facts.
Audit & evidence
Actor, source, business fact, approval, and result remain reconstructable together.
The agent-runtime boundary
Two systems. Two data boundaries to review.
These are separate trust questions. ORYH compatibility proves defined integration behavior; it does not certify the security, privacy, or compliance of the agent product itself.
- Company identity and actor attribution
- Record access and write permission
- Schema and lifecycle validation
- Approval facts and audit history
- Prompt and conversation handling
- Model processing and retention
- Local files and connected tools
- Runtime security and availability
Credential lifecycle
Agent credentials are scoped, revocable, and independent.
- 01
Employee connects a permitted agent through a browser-mediated authorization flow.
- 02
ORYH issues a user- and device-bound credential — no password delegation.
- 03
The agent receives a company-namespaced capability bundle derived from live roles.
- 04
Role and audience changes affect the next capability refresh.
- 05
A lost or retired agent can be revoked without moving company records.
Data handling & compliance
We state current facts only. No SOC 2, ISO 27001, or data-residency claims are made until achieved.
Contact the security team