Trust · architecture and assurance

Authority should survive scrutiny.

Lagstyr is being built so consequential agent work remains explainable, bounded, verifiable, and owned by the company—including when the model is wrong or the vendor is unreachable.

Load-bearing commitments

Control is architectural, not a policy paragraph.

These principles shape the product design and are exercised in the implemented foundation. They do not imply current customer availability.

Deterministic authority seam

Probabilistic agents reach consequential writes only through typed, policy-enforced action paths. The agent cannot choose its own risk tier or approvers.

Stable identity and provenance

Company records preserve the entity, source, actor, causation, correlation, history, and confidence needed to reconstruct why work happened.

Verified effect

An accepted proposal is not proof of success. Idempotency, receipts, readback, and reconciliation establish what the owning system actually did.

Governed self-change

Prompts, models, skills, schemas, policy, rubrics, and governance change through proposal and approval. No agent silently expands its own powers.

Customer-controlled runtime

The intended BYOC model isolates by deployment. The company record remains in infrastructure the customer controls, rather than a vendor multi-tenant data plane.

No vendor on the authority path

No licence check, vendor heartbeat, mandatory telemetry, vendor-held runtime credential, or inbound management endpoint is intended to block company operation.

System boundaries

Specialist systems keep specialist truth.

Lagstyr does not claim authority it should not own. The ledger remains authoritative for accounting; payroll for pay; CRM for pipeline; repositories for code. Lagstyr holds the management record that connects their work.

Lagstyr authority

Management context

Mandates, evidence, decisions, approvals, obligations, agent actions, effects, conflicts, measures, and outcomes.

External authority

Specialist facts

Accounts, payroll, customer pipeline, purchase orders, payments, communications, code, deployments, and tickets remain with their owning systems.

Derived, never sacred

Projections and summaries

Search indexes, brain pages, embeddings, summaries, and model outputs can be rebuilt. They do not silently outrank authoritative records.

Current assurance position

Strong internal discipline. No borrowed badges.

The foundation includes automated tests, clean-room journeys, security-oriented design gates, mutation and property testing, audit-ready records, governed erasure, legal holds, and enterprise identity paths. That is not the same as external assurance.

Present

Engineering assurance

Deterministic contracts, fail-closed paths, least-authority seams, test-exercised reference journeys, security checks, mutation testing, and operational evidence artefacts.

Before availability

Deployment evidence

Provisioned installation, restore and failure drills in that environment, observed capacity, support operation, upgrade evidence, and live end-to-end integration proof.

Not claimed

Independent certification

No independent penetration test, SOC 2 report, ISO/IEC 27001 certification, ISO/IEC 42001 certification, formal high-availability claim, or production customer reference.

Security claims will be updated when evidence changes. Until then, this page is intentionally narrower than the product ambition.

Report a security concern.

Email security reports to [email protected] with the subject prefix [SECURITY]. We publish a machine-readable security contact as well.

Security contact