Security and AI safety
Onam Operations is designed on the assumption that a model can be fooled. The controls that protect your cloud sit in code, in the call path.
Tenant isolation at every layer
Your data never crosses to another customer — in a query, a cache, an agent’s memory, the context assembled for a model, a model call, an event, or a log line. Each layer is isolated and tested on its own, because one mechanism covering everything is one bug away from a breach. Identity and organisation come only from the platform gateway, never from a request body.
Zero-trust agents
An agent is an untrusted principal. It has an identity on every call; its scope is verified on every call; it cannot change its own definition, permissions, level or model; escalating to another agent transfers no authority; and it can be disabled in seconds without a deploy.
Prompt injection
Text in your cloud — resource tags, object keys, policy descriptions, finding titles, commit messages — can be written by an attacker. Onam Operations treats all of it as untrusted:
- Structured tool output only. Free text from the estate travels in designated fields, never spliced into instructions.
- Instruction and data separated. Untrusted content is delimited and labelled as data.
- Detection. Known patterns are quarantined and logged; the investigation continues without them.
- Authorisation after the model — the decisive control. Whatever the model was persuaded to attempt, the policy engine and tool gateway check it against the agent’s declared scope, in code.
- No new instructions through tool results. Tool output cannot introduce tools, skills or instructions.
The first three reduce the chance an injection succeeds. The last two mean that when one does, nothing happens.
Groundedness
Every factual claim cites the skill, tool, query and rows behind it. Resource, finding and account identifiers must come from a tool result. When an agent cannot ground a claim it says so — “unable to verify” is a designed answer.
Models
All inference goes through one model gateway: approved models only, in the region agreed with you, one customer’s data per call. Today it routes to Amazon Bedrock in-region. Customer data is never used to train or fine-tune a model. Agents that propose or act fail safe rather than fall back to a weaker model.
Runaway protection
Every agent level has ceilings on tool calls and time, every task a cost ceiling, and repeated identical calls are detected and stopped. When a ceiling is reached, the task stops and reports what was spent and what is left undone.
Execution sandbox (on the roadmap)
When execution is offered, changes will run in an isolated namespace holding the only write credential: default-deny egress allowlisted per action, a short-lived role scoped to the target, one action per container, a hard time limit, and every call captured as evidence.