RedactSure blog

What should an AI agent be allowed to see and do?

These articles started with questions from security leaders, operators, and buyers. We look at the job first, then work backward into what the agent can see and who has to approve the consequential steps.

Start here

The enterprise AI operating-model series

Companies bought AI while the work itself barely changed. These five articles trace the problem from assistant deployments through cross-application workflows and human approval.

For CIOs and CISOs

Where the current security stack stops

IAM, DLP, encryption, and the perimeter still matter. An agent starts reading after most of those controls have done their job. These briefs focus on what appears on screen and who approves the agent's actions.

By industry

Government, schools, insurance, healthcare, and payments

These are practical examples, from prior authorization and claims handling to school budget transfers. Each one starts with the work people are doing now.

Earlier essays

How we arrived at this architecture

These pieces came before the operating-model series. They cover the original thought experiments, the lethal trifecta, and the case for keeping real data out of the agent's view.