GOVERNANCE & SECURITY
Built for work.
Grounded in trust.
Understand the boundaries, responsibilities and records that keep people in control of the AI workforce.
- Row-levelThe database refuses another company rows, not just the code
- Append-onlyThe audit trail is hash-chained and cannot be edited
- Four eyesNobody approves their own request
Governance
AI autonomy with enterprise control.
Every control here is enforced by the server. Hiding a control in the interface is not security, and UBOSS does not treat it as any.
No self-approval
The person who submits work cannot be the person who approves it. The server refuses it, not the screen.
Four-eyes
Where it is configured, two different people must decide — and the second cannot be the first.
Role and scope
What somebody may do, and how far it reaches. Own work, a team, a department, or the company.
Department boundaries
An action granted in one department does not borrow reach from another.
Approval gates
Consequential steps wait for a decision. Nothing goes live on an approval that was never given.
Versions and audit
Editing a live objective never changes it in place. Every decision is on the record with its reason.
Access control
Six dimensions, one answer.
Effective access is computed, not assumed. Any one of the six can narrow it, and none of them can be widened by a screen.
| Role | Scope | What it permits |
|---|---|---|
| Employee | Own work | Their To-do and the Agents assigned to them |
| Manager | Team / subtree | Assign work, review output, build Agents |
| Head | Department | Approve, and see the department’s work |
| Approver | As granted | Decide what is routed to them |
| Auditor | As granted | Read the record; change nothing |
| Company Admin | Whole company | Administer people, access and settings |
Navigation visibility is not security. A hidden menu item and a refused request are two different things — UBOSS does both, and the second is the one that counts.
Security
Controls we can show you.
What follows is what UBOSS implements. We publish no certification claims on this page — if a certification matters to your review, ask us and we will tell you exactly where we stand.
Tenant isolation
A company’s data is reachable only inside that company’s context. It is enforced at the database, not only in the application.
Role and scope authorization
Every request is checked against the permission and the reach the person actually holds — the interface is never the gate.
Governed connections
An Agent reaches a system through a connection an administrator approved, chosen by identity rather than by pasting a key.
Secrets handling
No credential is entered on a builder screen and none is displayed back. Activation tokens are stored as a hash.
Audit trail
Who did what, when, and why — including refusals. A decision that was blocked is recorded as one.
Human authority
Governed actions wait for a person. No self-approval, and four-eyes where the company configures it.
Session controls
Sessions are bound, revocable and visible to the person they belong to.
Enterprise identity
MFA and enterprise sign-in where a company enables them.
Your workflow.
Inside Chief Agent.
Bring a recurring report, a review process or an operational task. We’ll walk through its people, agents, skills and approvals.
Book a Workflow Demo