Explicit authority
Agents act through allowlisted actions and permission boundaries. Connecting a system does not grant unlimited power.
Relsor coordinates AI work inside explicit permission, approval, tenant-isolation, and evidence boundaries — so agents act with authority you can see and control.
Principles
Constrained authority, human control, and inspectable results — built into Relsor’s operating model.
Agents act through allowlisted actions and permission boundaries. Connecting a system does not grant unlimited power.
Consequential and outbound actions can require human approval. Rejection blocks execution.
Supported product workflows enforce tenant boundaries so company work stays inside the authenticated organization.
Jobs, approvals, artifacts, and orchestration lineage remain visible where supported — not hidden behind opaque autonomy.
Results return with inspectable evidence in Mission Control so operators can review what ran and why.
Integrations carry clear maturity labels. Foundation or connectable paths are never presented as equally live.
Execution model
Owner intent moves through the AI CEO and specialists on allowlisted tool paths. Approval gates interrupt the graph when required. Evidence returns to Mission Control.
Owner intent
A person states the outcome
AI CEO
Coordinates and delegates
Specialist agent
Owns the domain task
Governed tool path
Allowlisted actions only
Approval when required
Graph can pause
Evidence returned
Visible in Mission Control
Connecting an integration does not automatically authorize every agent or every action. Available work depends on permissions, assignment, and the maturity of each connection path.
Control
Humans keep authority over consequential actions. Agents do not receive an open-ended mandate.
Agents operate inside explicit permissions. Available actions depend on role, assignment, and the connected integration — not on an open-ended mandate.
When an action requires approval, the workflow waits for a human decision. Supported orchestration pauses while approval is pending.
Rejected approvals do not execute. Policy and budget gates fail closed when checks cannot be satisfied.
Budget and spend controls apply when configured — including gated paid-media foundations. Silent unlimited spend is not the product model.
Isolation
Supported product workflows enforce tenant boundaries. Authenticated sessions carry tenant and role claims; execution and stored work stay scoped to that organization. Cross-tenant access is denied in the product model.
Visibility
Operators can inspect what ran — without exposing hidden chain-of-thought or internal implementation detail.
Operators can inspect job status and approval decisions for work that ran through the governed path.
Where workflows produce artifacts or citations, those outputs remain inspectable alongside the job.
Multi-step runs can expose handoff references and orchestration lineage so you can follow how work moved between agents.
Mission Control surfaces delegated work, waiting approvals, and evidence without requiring you to guess what the AI did.
Boundaries
Credentials stay out of handoffs. Provider access depends on what you connect and grant.
Agent handoffs carry bounded context and references — not credentials or secret material.
Downstream agents receive the context required for the assigned task, not an unrestricted dump of tenant secrets.
External provider access depends on connected integrations and the permissions granted for that connection.
External actions remain on governed tool paths where supported. Integration maturity labels describe what is live versus foundation-ready.
Secrets
Integration credentials are encrypted at rest. Secrets are redacted from logs and client responses. Access uses authenticated sessions with role and tenant claims.
Organizations with specific security, architecture, or procurement questions can review them with Relsor during enterprise planning.