PATTY SECURITY & GOVERNANCE

Safe AI is not a matter of censoring its answers.

It is the design of who may see what, which actions they may take, and how the result can be proven.

Patty does not reduce AI safety to tone or a forbidden-word list. We connect identity and authority, data boundaries, tool use, human approval, and execution evidence as one operating system. As AI takes on more work, organizational control must grow with it.

Request a security and governance review
Our position

Governance must operate at the moment of execution—not remain in a policy document.

Publishing an AI usage policy does not reveal which data reached a model, which system an agent changed, or who approved that authority. Once AI moves beyond retrieval to sending messages, deploying code, or updating a business system, retrospective logs are insufficient.

Our principle is straightforward: narrow risky actions before execution, let permitted actions proceed within their scope, and preserve decisions and outcomes as evidence people can understand. Governance is an operating mechanism for trustworthy speed.

Default deny
Data, tools, and actions that were not explicitly delegated are unavailable.
Least privilege
Authority is limited to the target, action, time, and budget the work requires.
Risk-based approval
People are called at irreversible or high-impact boundaries—not for every click.
Evidence first
Allow, deny, execute, and fail events remain reconstructable in one chain.
The chain of governed execution

Authority and evidence remain connected from a request to a real-world action.

A plausible model response is not execution authority. Each step inherits the preceding scope and pauses when broader permission is required.

  1. Who made the request?Identity

    Distinguish people, service accounts, and AI agents, then bind them to organization, role, and session.

    actor · organization · session
  2. What work was entrusted?Delegated authority

    State purpose, target, allowed actions, validity, and whether redelegation is permitted.

    purpose · scope · expiry
  3. What may the actor see?Data boundary

    Provide only data allowed by sensitivity, residency, business context, and field-level scope.

    classification · residency · fields
  4. How may it be processed?Model and tools

    Select allowed models, versions, connectors, and tool capabilities through policy.

    model · version · tool
  5. Is human judgment required?Approval

    Obtain an accountable decision for external transfer, high-risk change, overspend, or other defined boundaries.

    approver · reason · validity
  6. What actually changed?Execution

    Perform only the approved action against approved targets in an isolated execution environment.

    action · target · before/after
  7. What proves the outcome?Execution evidence

    Join the request, policy decision, approval, result, and time into a reviewable record.

    decision · outcome · timestamp
Eight control disciplines

Managing the model alone does not manage the AI system.

Trust emerges when organization, data, models, tools, people, and operations work together.

01

AI inventory and risk classification

Inventory models and agents by workload, impact, autonomy, and data sensitivity.

02

Human and non-human identity

Identify people, agents, and service accounts and connect each action to responsibility.

03

Delegation and least privilege

Issue purpose-, target-, action-, and time-bounded grants instead of broad permanent access.

04

Data protection and sovereignty

Apply purpose, minimization, sensitivity, retention, residency, and deletion requirements at runtime.

05

Human oversight and approval

Let people approve, stop, or reverse consequential decisions without creating approval fatigue.

06

Model, tool, and supply-chain integrity

Control versions, plugin provenance, change history, allowlists, and unexpected code execution.

07

Provenance and reviewable evidence

Preserve links among inputs, sources, policy decisions, approvals, execution, and artifacts.

08

Continuous evaluation and recovery

Repeat monitoring, red teaming, incident response, evidence preservation, recovery, and improvement.

Threat model for the agent era

When AI uses tools, the attack surface extends beyond the prompt.

Failure includes exploitation of goals, context, authority, tools, and trust between agents—not only an unusual answer.

01Goal and prompt hijackingHidden instructions in a document or page redirect the original objective.
Prevent

Separate trust boundaries · protect system instructions · restrict actions

Detect

Goal drift · anomalous tool calls

Recover

Stop session · discard tainted context · review again

02Excessive agency and tool misuseAn agent assigned to read attempts external transfer or data mutation.
Prevent

Separate capabilities · least privilege · high-risk approval

Detect

Policy denials · call patterns · budget anomalies

Recover

Revoke authority · undo change · determine impact

03Privilege escalation and confused deputyAn agent abuses another user’s authority or a redelegation path.
Prevent

Strong identity · purpose-bound grants · redelegation control

Detect

Actor-authority mismatch · abnormal path

Recover

Revoke credentials · block delegation chain · investigate

04Poisoned context, memory, or supply chainBad memory, a plugin, or a model change persistently distorts later decisions.
Prevent

Provenance labels · version pinning · supply-chain allowlist

Detect

Integrity checks · regression evaluation

Recover

Restore safe version · isolate memory · reevaluate

05Abuse of inter-agent trustOne agent’s false claim or authority propagates to another.
Prevent

Mutual identity · non-transferable authority · message schemas

Detect

Chained calls · broken accountability

Recover

Isolate workflow · reconstruct state · involve owner

06Unexpected code execution and cascading failureGenerated code or tool failure spreads to adjacent systems and agents.
Prevent

Sandbox · network boundary · staged commit

Detect

Execution observation · outcome validation · stop conditions

Recover

Checkpoint · rollback · emergency stop

07Human overreliance and approval automationA convincing summary is approved without inspecting evidence or impact.
Prevent

Evidence, diff, and impact first · independent review

Detect

Rubber-stamp patterns · abnormal review time

Recover

Revisit decision · notify impact · improve approval policy

Evidence, not promises

Auditors and work owners should understand the same execution at different depths.

Raw logs are ingredients. Begin with who did what, why, and with what result; descend to technical fields and source records when the review demands it.

EXECUTION RECEIPTILLUSTRATIVE · COMPLETED WITHIN APPROVED SCOPE
Verifiable execution summary

Nature of this exampleThis synthetic receipt demonstrates the evidence structure. It is not a record of a real customer, person, production environment, or production execution.

A synthetic procurement-role scenario requests 12 purchase-order drafts. A fictional team-owner approval and sensitive-field exclusion policy allow draft creation only; the ERP source remains unchanged.

Actor
Fictional role: procurement operator / human
Delegated authority
Read orders + create drafts / 30 minutes
Policy decision
Allow / P-PO-014 / 3 fields excluded
Data class
Internal work / supplier bank data excluded
Model and tool
illustrative-private-model:v4.2 / ERP draft connector:v8
Approval
Fictional role: procurement owner / draft only / 14:32 KST
Execution
purchase-order.draft.create / 12 records
Outcome
12 drafts / 0 source changes / 0 errors
Time
Illustrative time 14:31:08–14:32:41 KST
View technical fields and integrity identifiers
trace_id
trc_8f2a…4c19
authority_id
del_0137…b28e
input_digest
sha256:53b7…e20a
policy_bundle
procurement-kr@2026.08.4
runtime
private-seoul-02
outcome_digest
sha256:94e1…72df
Human authority

People do not merely apply the final stamp; they define, supervise, and own the boundary.

Effective human oversight calls for judgment where it matters and presents the context, impact, and alternatives needed to decide.

  1. 01Authorize

    Define which goals, data, tools, and budgets AI may use.

  2. 02Supervise

    View normal work through outcomes and focus on drift, failure, and high-risk requests.

  3. 03Intervene

    Stop, narrow, reassign, revoke authority, and roll back immediately.

  4. 04Investigate

    Reconstruct identity, evidence, policy, approval, and outcome at the time of decision.

  5. 05Own

    Preserve the owner and acceptance decision even when AI proposed the action.

Translate regulation and standards into operating language

Requirements should connect to controls and evidence—not decorate a checklist.

Obligations vary by role, industry, deployment, and applicability. We map them to inventory, impact assessment, transparency, oversight, records, monitoring, and response.

Important distinctionThis section describes readiness and control mapping. Mapping is not legal advice, a conformity assessment, certification, or a guarantee of complete compliance. Applicability and adequacy must be determined with the organization’s legal, privacy, security, and audit owners.

Deployment boundaries

The same control principle is implemented differently depending on where data and execution live.

Deployment is not a simple security ranking. Control placement and evidence retention follow data class, network conditions, operating responsibility, and recovery requirements.

01

Public cloud

A boundary that may include managed infrastructure and external model APIs

  • Tenant and key separation
  • Data minimization before transfer
  • Provider, region, and retention review
Evidence to retainRequest path · provider · region · retention decision
02

Enterprise private

Enterprise VPC, dedicated account, or internal infrastructure

  • Enterprise IAM
  • Private network and dedicated keys
  • Internal SIEM and audit storage
Evidence to retainEnterprise identity · network path · control decision
03

Sovereign environment

A boundary reflecting jurisdictional data and operator requirements

  • Local data, keys, and operation
  • Approved supply chain
  • Jurisdiction-specific policy bundle
Evidence to retainResidency · operator · export decision
04

Disconnected network

An internet-isolated or tightly connected network

  • Local model and tool allowlist
  • Offline policy and time validation
  • Reviewed import, export, and evidence sync
Evidence to retainPackage origin · local execution · export approval
Continuous assurance

An evaluation passed once cannot guarantee safety tomorrow.

Models, data, tools, attacks, and work change. Trust is managed as a repeated capacity to observe, validate, respond, and recover.

01

Evaluate

Test representative work, failure conditions, Korean instructions, and authority boundaries by version.

02

Red team

Probe prompt injection, escalation, exfiltration, tool misuse, and cascading failure.

03

Observe

Monitor denials, approval bypass attempts, cost or latency anomalies, goal drift, and result quality.

04

Respond

Prepare stopping, isolation, revocation, evidence preservation, impact analysis, and notification.

05

Recover

Return to a safe version or checkpoint and replace tainted context and credentials.

06

Improve

Feed incidents and near misses back into policy, evaluation, approval criteria, and product design.

Research and public work

Materials for teams that want to inspect the principles more deeply.

DARI and Patty’s security work explore how these principles can be implemented and tested. The product name does not precede the doctrine, but technical reviewers can inspect the basis.

OPEN PROTOCOL RESEARCHDARI — open protocol research joining delegated authority to execution evidence

Research on connecting identity, delegation, policy decisions, and action outcomes in a verifiable flow.

Content provenance and execution provenance

C2PA is an important open standard for the origin and change history of digital content. Execution provenance additionally asks who used which authority and policy to invoke a tool and what changed in a real system. The concerns are related but not identical.

Begin with the flow in which your AI actually sees, decides, and acts.

We will map the models, data classes, tools, approval boundaries, and deployment environment to the controls and evidence your organization needs.

Request a security and governance review