Security posture

Least privilege is a product decision

Understand the tenant, credential, release, data-lifecycle, and access boundaries behind a managed AI Employee.

Direct answer

Foundry security begins with role-level least privilege: isolated customer state, scoped credentials, separated public and operational systems, controlled releases, limited support access, and revocable authority.

Inside the system

Built around the work that matters

Every capability is tied to a role, a boundary, and a reason to exist.

01

Tenant boundaries

Customer identity, memory, state, secrets, evidence, and connectors are designed as customer-specific assets.

02

Scoped credentials

The employee receives only the accounts, permissions, and duration needed for its approved job.

03

Release provenance

Production changes should be traceable to a version, source, checks, and approval path.

04

Public/private separation

This marketing site cannot access operational tenant, fleet, backup, incident, or secret data.

Common questions

What buyers ask next

01What is an AI Employee?

An AI Employee is a named, role-based digital worker with a defined mission, connected business systems, documented authority, approval gates, operating memory, and measurable work. It is designed around a job—not around an open-ended chat window.

02Does an AI Employee replace human authority?

No. Cloud Radix defines what the AI Employee may do, what requires approval, and what it is prohibited from doing. Humans retain authority over consequential business decisions.