IrisKey.ai™ security
Access is checked before work begins.
8ORA.AI decides how a job should be done. IrisKey.ai™ is designed to decide whether the proposed action is allowed to use the relevant data, system or environment. Keeping those decisions separate prevents a tool from granting itself permission.
The principles this rests on
Rules that do not bend under pressure.
The risk to an AI authority model is rarely an attack. It is the reasonable-sounding change: let the system that scores capabilities also approve them. These principles exist so that change cannot be made quietly.
-
Selection is not authorisation
That a capability is best equipped for a job says nothing about whether it may act, on what data, in which environment. The two decisions are made by two systems, and only one of them is an authority.
-
Authority before autonomy
The authority decision comes before the action, not as an audit afterwards. An action that was never permitted is not an incident to be reviewed later — it is an action that does not happen.
-
Denial cannot be argued with
No confidence score, benchmark result or recommendation from any source can turn a denial into permission. There is no route by which performing well earns wider access.
-
Revocation is a first-class action
What was granted can be withdrawn — for a worker, a capability, an environment or an integration — without dismantling the rest of the workforce.
-
Evidence is the output, not a by-product
What was requested, what was selected, what was decided and what was done should be inspectable afterwards by the organisation that owns the work.
-
No provider is trusted by default
Every capability reaches the business through the same boundary. Swapping one model or provider for another changes who executes and changes nothing about who decides.
This page describes the security model and the boundary between the two systems. It does not describe implementation detail, and no certification or compliance status is claimed here.
Talk to 8ORA.AI
Which process should work better?
Tell us where work repeats, time is lost or knowledge disappears. We'll look at what could improve, what a sensible first step would be and how the result could be measured.
Protected by IrisKey.ai™ — Authority before autonomy.