Security & governance

Governance you can read, ratified, and enforced.

Cockpit's governance is not a promise buried in a prompt. It is a ratified, versioned model that is enforced in the database. That model, the Governance and Data-Handling Model ("Governance 05"), is supreme for every access question across the firm's operating system, including the Portfolio Platform, which supplies scope but never invents policy. One signature, the General Counsel's, binds the whole firm per version.

Row-level security keyed on person, role, and data class. Read-only connectors, denied by provisioning. Zero auto-send on legal, HR, or finance, for everyone, forever. A complete audit trail behind every action.

Safe by construction

The sign-off is the thing that unblocks the build.

Governance 05 is ratified per version, and each version binds every person's agent identically. There is no bespoke rule set for the executive suite and no looser one for operations; the same model governs them all. The ratification is not a formality after the fact. It is the gate: nothing that depends on a governance provision ships until that version is signed. The walls come first, then the product is built inside them.

The walls are not prompts; they are enforced in the database.

Governance and Data-Handling Model 05
Sort by risk first

Four data classes, one handling matrix, every surface.

Before an agent does anything with an item, it sorts that item by risk. Every piece of content lands in one of four data classes, from C0, which is open, through C3, which is the most restricted. The handling matrix that follows from the class binds identically on every surface and for every person. A sensitive matter raised in a Slack message gets the same treatment it would in email. A role profile may only tighten the rules for a given person; it can never loosen them.

C0 · Open

Routine and low-stakes

Ordinary, non-sensitive content: newsletters, logistics, general coordination. Handled with the lightest controls, still logged like everything else.

C1 · Internal

Firm-internal material

Working content that stays inside the firm. Triaged and drafted where safe, with access scoped to the people and roles that need it.

C2 · Restricted

Sensitive and market-relevant

Financial and investor-facing material and other restricted content. Grounded from governed systems, never on an auto-send path.

C3 · Most restricted

Privilege and HR

Attorney-client privileged and HR content, held at the highest sensitivity in a walled store, never drafted or auto-sent, for anyone.

Identical everywhere

Same matter, same rules

The class travels with the content, not the channel. Email, calendar, tasks, and Slack are governed by one matrix, so nothing is safer or looser by virtue of where it arrived.

Tighten only

Roles never loosen

A role profile can add restriction on top of the class; it can never subtract it. There is no configuration that relaxes the floor the model sets.

Enforce in the database

The guarantee is structural, not procedural.

The controls do not depend on the agent behaving well. Access is governed by row-level security keyed on person, role, and data class, so an agent can only ever see rows its caller is entitled to. Privileged and HR content lives in a separate, walled store rather than mixed in with everything else. And connector credentials are simply not provisioned to role tiers that are not granted them, so denial happens by provisioning, not by a policy check that could be reasoned around or bypassed.

Row-level security

Keyed on person, role, class

Entitlement is evaluated in the database on every read. The agent has no path to rows outside its caller's grant, because the rows never leave the store.

Walled store

Privilege and HR, segregated

The most restricted content sits in a separate store behind its own boundary, not commingled with general mail, so a broad query cannot sweep it up.

Denial by provisioning

The credential is never issued

Tiers that are not granted a connector never receive its credential. A denied action fails because the key does not exist, not because a rule said no.

The Connector Access Matrix

Tier by connector by mode, read-only throughout.

Every connector is governed by a grid of role tier against connector against mode. Access is read-only for all tiers. It is enforced in three layers: first by the absence of the credential for tiers that are not granted it, second by runtime gates on each call, and third by the partner system's own permissions. And the datastore query tool always runs under the caller's own access context, never a service key, so it can never see more than the person behind it can.

The untrusted-content wall

Inbound content is data, never a command.

Everything that arrives from the outside is treated as data to be read, never as an instruction to be followed. A prompt-injection wall stands between what arrives and what the agent is allowed to do, so a message that tries to redirect the agent gets read like any other text and acted on by no one. Every tool result carries a data class, and a draft inherits the highest class of its inputs, so sensitivity propagates upward automatically and can never be lost along the way.

Data, not commands

Inbound content is parsed as information. Instructions embedded in a message have no authority over the agent's actions.

The injection wall

A prompt-injection wall separates arriving content from the agent's tools, so hostile text cannot cross into action.

Class propagates up

Every tool result carries a class, and a draft inherits the highest class among its inputs. Sensitivity rises with the work, never falls.

Autonomy is earned

Every person starts in shadow mode.

No one is granted reach on day one. Every person begins in shadow mode, where the agent observes and drafts but sends nothing. A cohort advances only after passing measured evaluation thresholds, gauged per surface, and the prompt-injection red-team suite is held at a hard zero: any failure there blocks advancement. Auto-send on legal, HR, or finance is zero, for everyone, forever, no matter how well a cohort performs.

  1. Shadow mode for everyone, first

    The agent watches and drafts while sending nothing. Its judgment is measured against what people actually do, before it is trusted with any reach.

  2. Advancement by measured threshold, per surface

    A cohort moves forward only after clearing evaluation thresholds on a given surface, and only for that surface. Reach is earned one surface at a time.

  3. Red-team suite held at hard zero

    The prompt-injection red-team suite must pass with zero failures. A single failure blocks the cohort; there is no partial credit and no override.

  4. Legal, HR, and finance stay at zero, forever

    Auto-send on legal, HR, or finance is zero for everyone, permanently. No amount of earned trust opens that path; those sends always wait for a person.

Personal data and scope

The agent works the firm calendar, and nothing more personal.

The scope is deliberately narrow. Personal calendars are out of scope; the agent works the firm calendar only, and never reaches into a person's private life. Retention is bounded rather than indefinite. Attorney-client privilege is preserved as a first-class constraint, and HR content is segregated by class into its own protected space. What the agent can touch is defined by role and by the model, not left to discretion.

Out of scope

Personal calendars stay private

The agent works the firm calendar only. A person's private calendar is never in scope and never read.

Bounded retention

Kept only as long as needed

Retention is bounded, not open-ended. Content does not accumulate indefinitely inside the system.

Privilege preserved

Privilege and HR, segregated

Attorney-client privilege is preserved as a hard constraint, and HR content is segregated by its data class into a protected store.

Versioned amendments

Governance evolves only by signed amendment.

The model is not edited in place by whoever happens to be working. It evolves only by signed amendment, from v1.0 through the current version, and each version is signed exactly once by the General Counsel. That signature is what makes a version binding. A channel-surface amendment is currently drafted and unsigned; until the General Counsel signs it, nothing that depends on it ships. The unsigned state is not a gap; it is the gate working as designed.

Signed, once, per version

One signature makes it binding

From v1.0 to the current version, each amendment is signed exactly once by the General Counsel. Without the signature, a version has no force, and the build does not rely on it.

Drafted and unsigned

A channel-surface amendment, pending

A proposed channel-surface amendment is drafted but not yet signed. Everything that depends on it is held until it is; the gate does exactly what it should.

A complete audit trail

What the system did, and why, is always reconstructable.

Every agent action is recorded. The trail captures what the system did and the basis on which it did it, so any action can be reconstructed after the fact, not merely trusted in the moment. Oversight does not depend on catching something as it happens; the record is complete and durable, and it is there whenever the firm needs to look.

Every action recorded

No agent action goes unlogged. The trail spans reads, drafts, and sends across every surface the agent touches.

The why, not just the what

The record captures the basis for each action, so a decision can be examined on its reasoning, not only its result.

Reconstructable after the fact

Oversight can replay what happened at any time. The account is durable and complete, ready whenever the firm needs to review it.

Adopt with confidence

Governance you can hold to a signature.

Cockpit is safe by construction: ratified per version, enforced in the database, and bounded by a model that only tightens by role. Adoption is staged from one pilot, in shadow mode, on one surface, and every step is gated by measured results. When you are ready to see how the rollout unfolds, start here.