Accountable AI and Workflow Governance
An agent needs a person behind it. This article lays out supervised delegation, setup approvals, data masking, and an audit record tied to a named supervisor.
Read articleRedactSure blog
These articles started with questions from security leaders, operators, and buyers. We look at the job first, then work backward into what the agent can see and who has to approve the consequential steps.
Start here
Companies bought AI while the work itself barely changed. These five articles trace the problem from assistant deployments through cross-application workflows and human approval.
An agent needs a person behind it. This article lays out supervised delegation, setup approvals, data masking, and an audit record tied to a named supervisor.
Read articleEmbedded agents work well inside SAP, Salesforce, Workday, and similar platforms. This article follows what happens when a business process crosses the application boundary.
Read articleAssistant licenses can boost individual productivity without changing a business process. This article looks at the shadow use that grows when the approved tool cannot do the real job.
Read articleFour operating models explain why many companies see broad AI adoption and little enterprise-level impact. This is the map for the rest of the series.
Read articleContracts, permissions, encryption, DLP, and firewalls protect important layers. An agent begins at the screen, after those controls have already run.
Read articleFor CIOs and CISOs
IAM, DLP, encryption, and the perimeter still matter. An agent starts reading after most of those controls have done their job. These briefs focus on what appears on screen and who approves the agent's actions.
Agents can read more than a task needs and act without a named person behind the decision. This brief covers the missing render and workflow controls.
Read articleA layer-by-layer review of the security stack, from hardware and identity through the browser screen. It shows where agent visibility and action fall outside the old assumptions.
Read articleA single job often crosses email, portals, ERP, HR, and finance. This brief shows how an agent can follow the work while sensitive fields stay masked.
Read articleBy industry
These are practical examples, from prior authorization and claims handling to school budget transfers. Each one starts with the work people are doing now.
Research, casework, grants, records, and decision support all put useful AI close to sensitive government data. Here is one way to keep that data off the model.
Read articleDistrict staff are already using public AI. A sanctioned workspace can handle budget transfers and administrative drafting while student identifiers stay out of the model.
Read articleOne hail claim can touch ten systems. This brief follows the full job and marks the points where policyholder data needs masking and an adjuster needs final approval.
Read articlePrior authorization, coding, billing, and denials are good automation candidates. They also touch PHI on nearly every screen.
Read articlePCI and tokenization protect card data extremely well. This paper looks at everything else an agent can read across onboarding, disputes, reconciliation, and support.
Read articleEarlier essays
These pieces came before the operating-model series. They cover the original thought experiments, the lethal trifecta, and the case for keeping real data out of the agent's view.
Every tool that let normal people do technical work was dismissed by the people who could already do it. The dismissal was always correct. It always conceded the market.
Read articleA browser agent can have private data, untrusted content, and a way to send information out. This article shows how the work can run while an attacker gets nothing useful.
Read articleThe security model behind RedactSure: data isolation, user control, and policy enforcement for browser agents.
Read articleAn agent can finish a task using consistent placeholders instead of names, account numbers, and credentials. This is the original argument for architectural anonymity.
Read articleA simple test separates the information needed to make a decision from the information needed to carry it out.
Read article