Security
Reduce unnecessary authority. Keep material actions attributable.
SautX security begins with bounded work. The useful questions are who owns authority, where it is enforced, which crossings are explicit, what evidence remains, and which responsibilities still belong to the deployment.
Review the trust modelTrust model
Authority has an owner. Enforcement has a location.
Admin owns durable governance
Identity and authorization relationships, policy, resources, Sites, route selection, capability derivation, lifecycle decisions, and evidence relationships belong to Admin.
User Portal owns approved interaction
The User Portal presents assigned work and current controls. Interface state communicates the decision; it does not become the authority source.
Resource Edge and Site own local validation
The selected Resource Edge checks scoped authority at the point of use and materializes native sessions or execution inside the selected Site boundary.
The protected target keeps its own controls
Native target permissions, hardening, data controls, availability, protocol behavior, and resource-side security remain part of the complete decision.
Enforcement lifecycle
Govern every request from entry through expiry.
- 01
Resolve
Derive the actor, purpose, resource, action, route, time, environment, and request context.
- 02
Validate
Check scoped authority at the selected User Portal, Resource Edge, Site, and protected-resource points required by the workflow.
- 03
Constrain
Make only the current application runtime, credential, view, control, transfer, tool, mount, network route, model, endpoint, duration, output, and related live capabilities available.
- 04
Cross explicitly
Treat clipboard, file movement, private-content inspection, publication, and other boundary movement as separate governed operations.
- 05
Record
Connect material requests, decisions, routes, execution, crossings, outcomes, exceptions, and lifecycle events.
- 06
Expire
End scoped authority, reconcile local sessions and work state, and preserve the evidence required by configured policy.
Evidence and content
Record operational evidence. Inspect content only by exception.
Administrative visibility
Normal administration is metadata-first: requester, decision, resource, route, bounds, lifecycle, crossing, outcome, and relevant artifact references.
Private work
Private Session content and protected-resource data do not become routine Admin-visible content merely because the workflow is governed.
Recording
Recording is a distinct, capability- and protocol-dependent control. Its scope, notification, storage, retention, access, and availability require deployment-specific evaluation.
Transfer and publication
Approved movement is governed separately from execution and inspection. Constraining approved paths does not guarantee that data can never leave through every possible channel.
Shared responsibility
Architecture narrows exposure. Deployment still matters.
Identity providers
Authentication strength, federation, revocation, recovery, device signals, and upstream account governance affect the authority path.
Target permissions
Native accounts, application roles, data permissions, service configuration, and protected-target hardening remain explicit dependencies.
Certificates and secrets
Issuance, storage, rotation, revocation, native credentials, and integration trust require named operational owners.
Site networking
Firewall policy, routes, name resolution, egress, transport behavior, segmentation, and failure handling shape the deployed boundary.
Runtime and endpoint security
Image provenance, inspection, patching, browser integrity, device posture, local capture paths, target hardening, malware controls, and deployment operations remain part of the complete security posture.
Logging and retention
Evidence collection, storage, access, integrity, correlation, retention, and deletion depend on configured policy and the systems integrated with the workflow.
Operating procedures
Approval, break-glass use, incident response, access review, change control, monitoring, recovery, and decommissioning complete the technical model.
Claims and review
Security is contextual. Evidence must be specific.
SautX makes no compliance certification, zero-leakage, universal observability, attack-prevention, or absolute security claim. Conclusions must be tied to the actual product, protocol, runtime, integration, Site, deployment, release, configuration, and operating process.
01Can the person or approved agent complete the defined work?
02What effective authority results when identity, credentials, files, tools, mounts, network routes, applications, endpoints, and output paths are considered together?
03Where are resource and execution decisions validated?
04Which data, clipboard, transfer, inspection, and publication crossings are explicit?
05What happens when the task changes, expires, fails, or closes?
06Which material decisions and actions remain attributable?
Start with the work
Review the deployment. Evaluate the complete boundary.
Contact SautX with non-sensitive context about the workflow, identity path, resources, execution, crossings, lifecycle, deployment, and evidence requirements.
Contact SautX