Workflow examples

Start with the result. Draw the boundary around it.

These are illustrative patterns, not customer case studies. Each one begins with the required result, then identifies the actors, selected capability, authority to avoid, crossings, and evidence that deserve evaluation.

Review the primary workflows

Primary workflows

Evaluate the result and the boundary together.

01Secure + Agentic

Incident response

Required result
Investigate the event, identify the cause, take an approved recovery action, and prepare the incident record.
Actors
Approved responder or AI agent, incident lead, recovery approver, and protected-system owner.
Selected capability
Selected telemetry, evidence, diagnostic tools, models, compute, and approved protected-system actions.
Authority to avoid
Broad production reach, reusable credentials, copied evidence, unrestricted diagnostic endpoints, and open-ended recovery authority.
Crossings
Telemetry and artifact input, diagnostic execution, review, protected-system actions, publication, and recovery closeout.
Evidence
Request, selected resources, policy decision, analysis operations, protected-system actions, crossings, result, and closure.
02Agentic

Protected-data analysis

Required result
Answer a bounded financial, healthcare, scientific, legal, engineering, or business question and prepare a reviewable result.
Actors
Approved analyst or AI agent, data owner, reviewer, and output approver.
Selected capability
Defined data view, approved models and tools, bounded compute, private work state, and allowed result path.
Authority to avoid
Broad storage access, reusable credentials, uncontrolled copies, unrestricted tools or network reach, and automatic publication.
Crossings
Selected data input, model and tool operations, review, artifact publication, approved destination, and closure.
Evidence
Requester, data and execution selection, material operations, review, publication decision, artifact reference, and closure.
03Secure

Third-party maintenance

Required result
Complete approved maintenance during a defined window and return the named system to the required state.
Actors
Approved third-party technician, customer approver, and responsible protected-system owner.
Selected capability
Named service application and target, approved interaction controls, explicit transfer paths, and bounded duration.
Authority to avoid
Standing VPN access, reusable general-purpose accounts, broad network reach, and open-ended file movement.
Crossings
Identity route, clipboard, upload, download, credential use, target changes, and session closeout.
Evidence
Request, approver, route, target, granted capabilities, material actions, crossings, session bounds, and outcome.

Additional patterns

Apply the same discipline to other sensitive work.

04Secure

Restricted or legacy systems

Required result
Let an approved worker use the required system without broad admission to the surrounding environment.
Actors
Approved operator, system owner, and access approver.
Selected capability
Named target, eligible application or protocol runtime, approved controls, and explicit session duration.
Authority to avoid
Surrounding network reach, reusable legacy credentials, native protocol clients on every endpoint, and open-ended access.
Crossings
Target selection, view and control, credential use, clipboard, file movement, and session closure.
Evidence
Authorization, selected target and route, native connection outcome, material actions, explicit crossings, exceptions, and closure.
05Secure

Unmanaged or personal endpoints

Required result
Enter the assigned task through a supported browser without placing native target credentials or protocol clients on the endpoint.
Actors
Approved worker, identity provider, task approver, and protected-system owner.
Selected capability
Browser entry, assigned application and target, allowed controls, and current endpoint requirements.
Authority to avoid
Reusable target credentials, broad network access, local native runtime installation, and unrestricted downloads.
Crossings
Identity assurance, local capture paths, clipboard, transfer, downloads, target actions, and closeout.
Evidence
Entry identity, device and browser context where available, selected work, capability decision, crossings, outcome, and closure.
06Secure + Agentic

Restricted-environment research

Required result
Collect and analyze allowed material, preserve private work, and move only reviewed outputs through approved paths.
Actors
Approved researcher or AI agent, source and data owners, reviewer, and publication approver.
Selected capability
Allowed web resources, selected datasets, analysis models and tools, private work state, and reviewed output path.
Authority to avoid
Unrestricted browsing, broad data access, uncontrolled downloads or clipboard use, and automatic publication.
Crossings
Web collection, selected data input, analysis operations, private review, approved transfer, publication, and closure.
Evidence
Request, approved sources and resources, material collection and analysis operations, crossings, review, publication decision, and final artifacts.

Evidence evaluation

Ask four questions after every workflow.

  1. 01

    Was the intended result completed?

  2. 02

    Which unnecessary authority was avoided?

  3. 03

    Which paths crossed the task boundary?

  4. 04

    Can material decisions and actions be attributed?

Start with the work

Bring the result. Name the authority it should not require.

Share non-sensitive context about the actors, protected systems or data, execution, crossings, outputs, lifecycle, and evidence needs.

Contact SautX