Permissions
Each agent receives defined access to defined systems. A follow-up agent does not get payroll. A reporting agent does not send customer texts. If a system is not on the list for that agent, it stays out.
Trust and security
You are about to let software sit next to some of the most important systems in the company. These are the questions we answer before we connect anything.
Least privilege. Human approval on anything that matters. Logs. Your systems of record stay yours.
Each agent receives defined access to defined systems. A follow-up agent does not get payroll. A reporting agent does not send customer texts. If a system is not on the list for that agent, it stays out.
Sensitive actions can require approval before they run. Anything that spends money, changes a customer promise, or would be awkward to undo defaults to draft-and-flag until you open that path.
Only if you have explicitly allowed that path. The default is no. Drafts, flags, and queues first. Send, charge, or change a promise when you say so.
Agent actions and tool calls can be recorded: what ran, against which record, and who approved it. That is how you review the system instead of guessing.
Credentials are stored separately from the prompts sent to a model. We use official APIs and OAuth where the vendor supports them. We do not leave master passwords in a shared document. Rotation is part of managed operations.
Agents read the systems you authorize. Private or hybrid setups keep more of the work on hardware you control. When a job uses a cloud model, that job's prompt and the context required to complete it are sent to the provider for that request. We do not dump the company into a model.
No. Cortex can only reach the systems and records you approve for a given agent. If a vendor will not let us in, or you do not want that door open, that system stays out.
We do not opt Cortex customer data into provider training. Cloud model providers receive only what that job needs. Whether a provider retains or trains on API traffic is governed by the account and contract used for that deployment. We name the providers in the audit and use business APIs that are not opted into training.
It depends on the deployment. Typical jobs use a small set of model APIs and the software vendors you already run. There is no single Cortex cloud that holds every customer's records. The audit lists who would be in the path for your stack.
Yes. Dedicated hardware you own or control, cloud, or a mix. Routine watch-and-report work can stay on the local machine. A harder reasoning job can still call a cloud model when you want it to.
You own your software accounts, your records, and any hardware purchased for the deployment. Cortex manages the agents, connectors, and the operating environment we install. We do not take over the logins or resell the data.
You own the systems of record. The custom agents, prompts, and routing we build for your operation are part of the engagement. What happens to that work if you leave is covered in offboarding — not locked behind a surprise clause.
Connectors, agent configuration, and logs are kept so we can restore a path if a vendor ships a breaking change or a machine goes down. Shop software, CRM, and books remain the source of truth. We do not become a second copy of the company.
Your CRM, shop software, ads, and books still run. Agents stop. Credentials can be rotated. Configuration and documentation from the deployment go with you so another operator is not starting from a blank page.
If you leave, we revoke Cortex access, hand back documentation of what was connected, and stop managed operations. You keep your software. You keep your data. Agents do not keep a back door.
Used only when a vendor has no usable API and the work still needs to happen. It runs under a dedicated login you authorize, with the same least-privilege rules, logging, and the ability to turn it off. It is not the default.
You can pause an agent, remove a permission, or take a path back to fully human. Managed operations is how we keep that current. It is not a lock-in on your software.
We do not advertise SOC 2, HIPAA, or other certifications we have not completed. Trust on this page is about how the system is designed and operated: least privilege, approval, logs, and ownership. Specific controls for a deployment are written down in the audit and the build plan.
Start with a Free AI Operations Audit. We'll show you what is worth automating, what isn't, and what a practical first deployment could look like.