See the platform

Trust architecture

Autonomy is earned one workflow at a time.

Every workflow—payroll, sprint planning, outreach, customer resolution—starts with a defined identity, scope, tools and approval policy. Access is resolved before context is assembled, high-consequence changes remain human-owned, and every action retains an accountable history.

Governance is in the execution path.

It is not a policy document beside the product. It determines which context can be retrieved, which capabilities can be called and which actions require a person.

Tenant boundary

People, records, credentials, files and AI configuration stay scoped to one organization.

Identity first

Human and agent activity resolves to a known actor with explicit role and capability grants.

Every agent has an owner

Each workflow is registered to a named person who answers for what it produces. There is no unowned automation, and no agent acting on behalf of the company at large.

Long-running work stays attributable

A workflow open for weeks accumulates its decisions in the same event log. Ownership, scope and approval history travel with it, and it can be paused or handed over without losing the thread.

Least privilege

The service layer enforces access before data reaches a workspace, answer or tool call.

Approval gates

Sensitive actions remain recommendations until the authorized person approves them.

Evidence attached

Briefs and recommendations retain the sources and company state used to produce them.

Rules are inspectable

Policies and business rules used in a decision stay visible, versioned and attributable—not hidden inside a prompt.

Execution is bounded

Limit tools, records, recipients, spend, frequency, time windows and acceptable impact for each autonomous workflow.

Immutable history

Meaningful changes record actor, time, reason and consequence in an append-only event trail.

Set the autonomy level per workflow, not for the whole system.

Every workflow can start in observation mode, earn a wider scope, or return to approval-only. Its owner can pause execution immediately without removing the history needed to understand what happened.

Autonomy is configured per workflowNot one global on / off switch
01

Observe

Read, join, listen and organize

No external action

02

Recommend

Explain, prioritize and propose

A person decides

03

Prepare

Draft messages, plans, forms or code

Review before action

04

Approve then act

Execute after a named approval

Required checkpoint

05

Act within policy

Complete bounded, reversible work

Escalate exceptions

Identity + scope
Rules + approvals
Budget + rate limits
Pause + rollback
Evidence + replay

One governed path from intent to consequence.

01

Named owner on record

02

Identity + capability check

03

Grounded context + rules

04

Autonomy + approval gate

05

Bounded action

06

Evidence + outcome

Default

No access without an identity

Sensitive action

Recommendation before execution

During execution

Limits enforced; pause always available

After action

Actor, evidence and outcome replayable

Your organization owns the operating boundary.

Authentication and SSO

Configure organization identity and map access to roles and per-person capabilities.

AI providers

Choose and control provider credentials at the organization boundary; the product stays model-agnostic.

Integration credentials

Scope mail, files, code and third-party systems to the workspace that owns them.

Audit and review

Review meaningful human and agent activity through one event history.

Trust — Governance and security in OmniManas