Security & Multi-Tenancy Architecture
The WorkAgent OS security model is specified with defense-in-depth principles: untrusted content firewalls, canonical action hashing, identity delegation binding, and strict tenant isolation by design. Everything on this page is a design specification — production implementation and verification evidence have not been published.
Strict Authority Hierarchy
System Policy > Tenant Policy > User Prompt > External Tool Data. Untrusted web or email content can never override tenant policies or inject executable instructions.
Delegated Identity Chain
Every run binds: Tenant → User Identity → Agent Identity → Scoped Tool. Agents never execute as unconstrained tenant-wide service accounts.
Zero Credential Context
Third-party OAuth tokens and database passwords reside inside Vault. Model context receives only opaque tool references—never credentials.
Action Integrity Hashing
Human approval binds to a deterministic canonical JSON SHA-256 action hash. Parameter drift between approval and execution forces immediate denial.
Tenant Isolation Across the Complete Stack
Tenant boundaries are designed to be enforced systematically across every data and execution tier: API Gateway, Auth, Query layers, Storage, Cache, and MCP Connectors.
{
"tenant_policies": [
{
"rule": "ALLOW read_email",
"condition": "tenant_match AND mailbox_scope == user"
},
{
"rule": "ALLOW read_project",
"condition": "project_member == true"
},
{
"rule": "REQUIRE_APPROVAL send_email",
"risk_tier": "MEDIUM",
"condition": "recipients.has_external == true"
},
{
"rule": "REQUIRE_APPROVAL create_financial_transaction",
"risk_tier": "CRITICAL",
"approval_type": "ELEVATED_APPROVAL"
},
{
"rule": "DENY cross_tenant_access",
"condition": "ALWAYS"
}
]
}Tamper-Evident Audit Schema
In the design, every high-impact action, human approval, tool invocation, and read-back verification commits a record into an append-only audit ledger. Events are sequentially chained with cryptographic hashes so that retroactive modification is detectable — tamper-evident, not literally immutable.
CREATE TABLE audit_ledger_events (
event_id UUID PRIMARY KEY DEFAULT gen_random_uuid(),
tenant_id VARCHAR(64) NOT NULL REFERENCES tenants(id),
actor_type VARCHAR(32) NOT NULL, -- 'USER' | 'AGENT' | 'SYSTEM'
actor_id VARCHAR(128) NOT NULL,
user_id VARCHAR(128) NOT NULL,
agent_id VARCHAR(64) NOT NULL,
action_id VARCHAR(64) NOT NULL,
tool_id VARCHAR(128) NOT NULL,
canonical_action_hash CHAR(64) NOT NULL, -- SHA-256 of canonical action JSON
policy_version VARCHAR(32) NOT NULL,
risk_score SMALLINT NOT NULL,
approval_id UUID REFERENCES approvals(id),
request_id VARCHAR(64) NOT NULL,
trace_id VARCHAR(64) NOT NULL,
result VARCHAR(32) NOT NULL, -- 'SUCCESS' | 'DENIED' | 'FAILED'
verification_status VARCHAR(32) NOT NULL, -- 'READ_BACK_MATCHED' | 'DISCREPANCY'
prev_event_hash CHAR(64) NOT NULL, -- Sequential Hash Chaining
created_at TIMESTAMPTZ NOT NULL DEFAULT NOW()
);What AI Models Cannot Do — Intended Design Constraints SPEC
The specification treats foundation models as untrusted reasoning engines and defines the structural constraints below. These are intended design constraints — not guarantees of an implemented, invulnerable system. In particular, the model is forbidden from performing any of these authority changes:
By design, policy evaluation occurs out-of-band in deterministic runtime code. The model must never evaluate or grant its own permissions, approve its own actions, or self-authorize elevated scope.
Third-party OAuth tokens, DB passwords, and API keys are intended to live in a dedicated vault. The LLM is designed to receive only opaque tool handles — never raw secrets.
Any mutation with Risk Score > 50 is specified to halt the execution DAG until a human provides a hash-bound approval. The model cannot approve its own high-risk actions.
The model cannot widen a tool's schema, grant new tool permissions, or treat external content as an authority source. External data may inform, never authorize.
The model cannot modify, redact, or suppress audit events, nor change tenant or platform security policy. Audit events are designed to be append-only with sequential hash chaining — tamper-evident.
Agents are restricted to predefined, schema-validated MCP tool interfaces — no shell access. Tenant isolation is designed to be enforced at the PostgreSQL RLS and storage layer, not by the model.
Data Residency Design ROADMAP
The roadmap targets tenant-designated hosting regions to support GDPR, CCPA, and industry-specific sovereignty mandates, plus isolated multi-tenant and single-tenant VPC deployment options. No region or residency guarantee is deployment-verified today — see the residency matrix in the Trust Center.
Threat Model & Proposed Controls
The threats, controls, detections, and recovery paths below are specification design targets. No control listed here has been verified against a production deployment or third-party penetration assessment.
| Threat | Surface | Proposed Control | Detection | Recovery |
|---|---|---|---|---|
| Prompt injection (direct) | User prompt / chat input | Authority hierarchy (System > Tenant > User); policy evaluation outside model context | Policy-decision audit events; anomalous tool-plan patterns | Deny action; revoke session; forensic audit review |
| Indirect injection via tool content | Emails, docs, web pages retrieved as context | Untrusted content firewall; external data treated as information, never authority | Quarantine flags on embedded instructions; refusal telemetry | Drop tainted context; re-plan without untrusted instructions |
| Compromised user account | Delegated identity chain (Tenant → User → Agent) | Scoped delegation, short-lived sessions, approval gates on high-risk writes | Impossible-travel / anomalous run telemetry; approval audit | Suspend identity; revoke sessions; replay audit ledger |
| Compromised agent | Agent identity & tool scope | Per-agent scoped tools; agents cannot expand scope or self-approve | Out-of-scope tool invocation attempts logged to audit | Suspend/revoke agent identity; rotate bindings; incident review |
| Malicious tool / connector | MCP tool gateway & connector registry | Schema validation, allowlisted tools, tenant-scoped credentials | Schema violations; unexpected response shapes in traces | Disable connector; rotate credentials; reconcile affected runs |
| Credential theft | OAuth tokens / API keys | Vault-isolated credentials; zero raw secrets in model context | Vault access audit; anomalous connector auth failures | Rotate credentials; invalidate tokens; scope review |
| Replay of approvals or requests | Approval grants & API surface | Hash-bound approvals with expiry; idempotency keys; nonce binding | Hash mismatch on recompute; duplicate idempotency key rejection | Reject replayed request; audit incident; invalidate grant |
| Approval tampering | Canonical action payload between approval & execution | Canonical JSON SHA-256 action hash bound to approval; recompute before dispatch | Recomputed hash mismatch halts execution | Abort execution; escalate to approver; audit the divergence |
| Cross-tenant access | PostgreSQL, vector store, cache, object store | RLS bound to session tenant_id; tenant-scoped namespaces and prefixes | Planned cross-tenant retrieval attack test suite; query audit | Deny at storage layer; security incident process; tenant notification |
| Data exfiltration | Tool writes, memory export, logs | Egress-scoped tools; sensitivity classification gates; approval for external sends | DLP-style egress audit events; unusual volume telemetry | Block egress path; rotate credentials; forensic trace review |
| Model provider compromise | External LLM inference path | Model-agnostic adapter; minimal-context delivery; no credentials in prompts | Provider anomaly notices; output schema deviation monitoring | Fail over to alternate model/provider; invalidate affected context |
The Dynamic Risk Scoring Engine
The specification defines a normalized quantitative score that is evaluated before execution. This is an illustrative scoring model — policies, tenant configuration, and scope checks can still deny low-scoring actions:
Execution paused. Canonical JSON SHA-256 action hash locked until authorized user sign-off.