Start a review

Product security

Define the agent's access and authority.

Useful agents need access to real business systems. Worktree designs that access around a specific workflow: its required context, permitted actions, approval points, exception paths, operating evidence, and removal.

WT

Illustrative control manifestCustomer review workflow

Boundary current

Workflow authority

Read
Customer record · Project status · Approved notes
Prepare
Review brief · Follow-up · Decision packet
Change
Project status after acceptance
Approval gateCommercial exception requires an authorized person.
Waiting
Credential removableException routedMaterial action recorded

Security begins with the job

A secure deployment should answer six plain questions.

The control model follows the work. Before a workflow receives access, the team should be able to explain its purpose, scope, authority, review path, and end state without relying on vague claims about the agent.

  1. 01

    What starts the work?

    The approved request, event, or schedule that opens the workflow.

  2. 02

    What can the agent see?

    The systems and information required for the assigned job.

  3. 03

    What can it change?

    The read, prepare, update, or submit actions included in scope.

  4. 04

    What needs approval?

    The decisions and consequential actions reserved for an authorized person.

  5. 05

    What happens when it is unsure?

    The exception path that stops improvisation and routes the case.

  6. 06

    How is access removed?

    The credential, connection, and retained-data steps at the end of access.

Five control boundaries

Control is a set of explicit decisions.

Security is not one toggle around the model. The workflow combines access, credentials, authority, human review, and removal into a control design that can be discussed before launch and revisited when the work changes.

  1. 01

    Access boundary

    The workflow identifies the applications, records, documents, and communication surfaces the agent needs. Connection to one system does not make every part of that system relevant to the role.

    Systems scoped
  2. 02

    Credential boundary

    Credentials and delegated connections are configured for the agreed workflow. Their ownership, use, and removal should be understandable before production access is granted.

    Access defined
  3. 03

    Authority boundary

    The deployment separates what the agent may read, prepare, update, or submit from the actions that require another person to authorize them.

    Actions classified
  4. 04

    Review boundary

    Known approval points and exception paths keep consequential decisions with the people who own the business policy and outcome.

    Human included
  5. 05

    Removal boundary

    Delegated access can be disconnected. Retained customer data is deleted following a verified deletion request under Worktree's stated data-handling policy.

    Removal available

Sensitive context

Access can be scoped to one authorized execution.

When this control is appropriate to the deployment, sensitive context can be made available for a single authorized agent execution rather than left broadly available to the workflow. The exact design depends on the system, data, and action involved.

01Authorized personRequest verified
Client cellSingle agent executionAuthorized
02Scoped contextAvailable to this run
03Execution endsContext no longer active

Review and recovery

The operating picture should remain understandable.

Relevant evidence makes it possible to review an accepted result, trace an exception, discuss a material change, and decide what needs attention next. The exact evidence retained is defined with the deployment rather than implied as universal surveillance.

See how Worktree manages a launched workflow
Deployment record Evidence current
Request
A known workflow trigger and initiating identity.
Recorded
Context
Relevant sources used by the workflow.
Recorded
Decision
Approval or exception ownership where applicable.
Recorded
Action
The material operation prepared or completed.
Recorded
Change
A recorded update to the workflow or its controls.
Recorded
Known limitationUnstructured attachments still require human review.

Data handling

The public posture, stated directly.

01

Website and deployment inquiries

Deployment inquiries submitted through this site are stored in Supabase. Worktree does not train models on prospect or customer data.

02

Customer workflows

Customer workflow data may be processed with OpenAI when that processing is part of the customer workflow. The relevant systems and handling should be discussed for the proposed deployment.

03

Retention and deletion

Information is retained indefinitely by default and deleted following every verified deletion request. Delegated workflow access can also be disconnected.

04

Claims and evaluation

Worktree does not claim certifications, compliance programs, or security guarantees that are not documented here. A deployment review examines the actual workflow, systems, data, and authority involved.

Controls in practice

Security is designed during implementation and revisited in operation.

Security review

Bring the workflow and the systems it needs to touch.

Worktree can help identify the access, authority, approval, data-handling, and removal questions the deployment must resolve. For a security question or verified deletion request, contact hello@orthg.nl.

Last updated August 21, 2026.