17 free courses — no signup wall
Architect-led enterprise cloud, security & AI
320+ downloadable toolkits — instant delivery
Skip to content

Trust & Governance

Security & governance for agent-led delivery

The posture behind every Citadel engagement — where agents run, how they authenticate and are authorized, how autonomy is bounded, and what happens to your data at exit. Written to be forwarded to your security team.

How we secure and govern the work

Six controls that apply to every agent and every engagement — the same governance model the SIAS catalog is built on.

Where agents run

Agents run in or adjacent to your tenancy, grounded in your corpora — runbooks, ADRs, policies, catalogs. Corpora are tenancy-isolated per engagement, and privileged corpora are isolated per legal domain so one workstream cannot read another.

Identity

Every agent is a first-class principal with its own identity — not a shared service account. Workload identity is attested (SPIFFE/SPIRE), credentials are broker-issued and ephemeral, and there are no static long-lived keys sitting in a config file.

Authorization

Access is purpose-bound and checked on every call. Tokens are minted through OAuth token-exchange (RFC 8693) for the specific task, and a policy decision point (OPA / Cedar) evaluates each action against policy before it runs — not just at login.

Autonomy control

Autonomy is set per agent, per action across three tiers. Read-and-report work runs unattended (T1); writes to systems of record happen within scoped credentials and change windows (T2); anything touching money, people, or legal is draft-only behind named approvers with four-eyes enforcement (T3).

Auditability

Every action is logged and attributable to a specific agent identity. Writes are designed to be reversible, so a review can answer who did what, under which authorization, and how to undo it — the evidence trail a security team needs after the fact.

Data handling & exit

Your corpora and systems of record stay yours. When an engagement ends, grounding data and issued credentials are decommissioned and access is revoked. Specific retention windows, deletion timelines, and the subprocessor list are confirmed in the engagement agreement.

Frameworks

Aligned to the frameworks, honest about the label

Citadel designs and delivers against SOC 2, ISO 27001, HIPAA, FedRAMP, and CMMC control frameworks, and advises teams pursuing them. We do not present ourselves as holding those certifications. Where an engagement requires a certified posture, we deliver against the controls and support your own audit — no framework wordmark on this site is a claim that Citadel is certified in it.

Security review questions

The questions a security team asks before a signature. Send anything not covered here and we will answer it directly.

Where do the agents run, and who holds our data?

Agents run in or adjacent to your tenancy and are grounded in your corpora. Your data stays under your control; Citadel operates against it within the scope and credentials you grant, and corpora are tenancy-isolated per engagement.

Is the deployment single-tenant?

Yes — corpora and agent identities are isolated per engagement, and privileged corpora are isolated per legal domain. One workstream or client context cannot read another.

How are agent credentials managed?

Each agent is its own principal with attested workload identity (SPIFFE/SPIRE). Credentials are broker-issued, ephemeral, and purpose-bound through OAuth token-exchange (RFC 8693). There are no static, long-lived keys.

What stops an agent from doing something it should not?

Two things. Authorization is checked on every action by a policy decision point (OPA / Cedar), not just at login. And autonomy is tiered: anything touching money, people, or legal is draft-only behind named human approvers (T3), with full four-eyes enforcement.

What if an agent gets it wrong on a write?

Writes happen only at T2/T3 within scoped credentials, every action is logged and attributable, and writes are designed to be reversible. A mistake is traceable to a specific identity and authorization, and can be rolled back.

Is Citadel SOC 2 or FedRAMP certified?

Citadel builds and delivers against SOC 2, ISO 27001, HIPAA, FedRAMP, and CMMC control frameworks, and advises clients pursuing them. Citadel does not represent itself as holding those certifications. Where your engagement requires a certified posture, we deliver against the framework and support your own audit.

What happens to our corpora when the engagement ends?

Grounding data and issued credentials are decommissioned and access is revoked at exit. The exact retention, deletion, and destruction terms are set in the engagement agreement so your legal and security teams can review them up front.

Need this in your security review?

Book a call to walk through the controls with a senior architect, or email support@citadelcloudmanagement.com for RFPs and security questionnaires.