Operating

Security and compliance

Governance is part of the run rather than a layer added after it.

Every tool action, artifact, approval, and verification result attaches to the operating record. That record is what makes a run auditable: the question "why did the agent do this" has an answer that does not depend on anyone's recollection.

Consequential actions stay behind explicit authority boundaries. Process owners retain control of policy, permissions, review, and the promotion of reusable improvements.

Controls that carry over

Work created by Opulent goes through the same controls as work created by a person. Existing branch protection, document approval, financial authority, data governance, and publishing rules still apply. Opulent does not create a second path around them.

Connecting existing security systems

Connect Opulent to the scanning, monitoring, approval, and audit systems you already run. An outside finding can start an investigation or a remediation run. The run should preserve the source finding, the affected scope, the changes made, the verification evidence, the reviewer, and the final status.

Handling credentials

  • Do not place readable credentials in a prompt or in working files.
  • Credential values are redacted from agent-visible configuration.
  • OAuth handoffs pause the run and are completed by a person.
  • Network policy limits what an unattended run can reach.
  • Tool allowlists limit what it can do when it gets there.