Enterprise security

Give agents work. Never unchecked authority.

Delegate separates what an agent can reason about from what it can reach, change, spend, and reveal — with people at every consequential boundary.

Defense in depth

Security, built in layers.

Explore the layers that contain agents, limit their authority, protect credentials, and preserve a record of what happened.

01 Contain

Every agent starts inside a boundary.

Each agent works in an isolated workspace surrounded by layered controls. Network access, tools, permissions, and credentials remain separate decisions — granting one never silently grants the others.

  • Isolated workspace for each agent
  • Outbound connections pass through threat-intelligence-filtered egress
  • Network access can be allowlisted, approval-gated, or disabled
02 Limit

Authority can only get smaller.

User roles define who can view, delegate, approve, and administer. Separately, an agent can act only where its own permission ceiling overlaps with the authority of the person delegating the work. New destinations, credentials, skills, and consequential actions can stop for approval.

  • Custom user roles and agent permission ceilings stay separate
  • Least privilege is enforced per agent and per delegator
  • Approval gates sit in the flow of work
03 Broker

The credential never enters the conversation.

Secrets are encrypted, write-only after entry, and kept outside prompts, files, logs, and transcripts. When an approved tool needs one, the broker adds it to the outbound request and scrubs sensitive material from the response before the agent receives the result.

  • Credentials are granted to a destination and operation
  • Agents never need to read or repeat secret values
  • Rotation and revocation stay with authorized people
04 Record

Every consequential action leaves evidence.

Full audit logs record every platform-mediated action: what happened, who or what did it, and what came back. Role changes, workspace commands, approvals, and costs remain attributable instead of disappearing into an AI transcript.

  • Every human and agent action inside Delegate shares one chronology
  • Approvals preserve the request and decision
  • Costs remain attached to the work that incurred them
Your data

Know where the work goes — and when it leaves.

Delegate separates durable work records from captured evidence and keeps model access, retention, and deletion visible for review.

01 Store

The work record and the evidence behind it.

Delegate stores the account, board, message, file, usage, and audit data needed to operate the service. Credentials are handled separately as brokered secrets.

02 Process

Through the deployment and providers you choose.

Agent requests can be sent to the selected model provider. Tool calls can reach only destinations permitted by the workspace network policy.

03 Retain

Durable work stays. Captured evidence has a clock.

Core work records remain until changed or deleted. Browser captures and file snapshots from work streams default to 90 days and can be configured from 1 to 3,650 days.

04 Delete

Removal follows the same team boundaries.

Deleting a team removes its team-scoped database records and associated storage folders. Artifact cleanup is queued and retried so a temporary storage failure does not silently abandon deletion.

Exact model-provider data use, infrastructure subprocessors, backup retention, and residency depend on the deployment and are confirmed during data-processing and architecture review.

Open the trust center
Known risks. Concrete controls.

Built for the questions your security team is already asking.

The control model addresses the AI risks identified by OWASP and follows the least-privilege, continuous-governance approach used by NIST and the Cloud Security Alliance. This is design alignment, not a claim of certification.

Risk The reviewer’s question Delegate’s control
Prompt injection Can untrusted content turn into authority? Instructions do not grant tools, network reach, permissions, or credentials. Those boundaries are enforced outside the model.
Excessive agency Can an agent do more than its job requires? Per-agent permission ceilings, delegator limits, approval gates, and human sign-off constrain what can happen.
Sensitive disclosure Can a prompt or transcript leak a reusable key? Secrets remain behind a brokered boundary and are not placed in agent context, logs, or work artifacts.
Invisible behavior Can we reconstruct what happened? Full audit logs preserve every platform-mediated action, decision, role change, workspace command, and attributed cost.
Next up · enterprise identity

Bring the identity controls your IT team already expects.

These controls are on our roadmap and are not available yet.

Coming soon

SAML-based SSO

Connect Delegate to the identity provider your organization already governs.

Coming soon

Passkeys

Use phishing-resistant login without reusable passwords.

Coming soon

Multi-factor authentication

Require an additional factor for sensitive accounts and administrative access.

Your boundary. Your choice.

The control plane can live where your policies require.

Use our managed service, place Delegate inside your cloud, or run it on premises. Deployment location does not have to become the argument that stops the project.

Delegate cloud

Managed by us

The fastest path to production. We operate the platform while your team sets agent, data, network, approval, and spending policy.

Your cloud

Deployed in your GCP or AWS environment

Keep the enterprise control plane inside the cloud boundary, accounts, and operational model your organization already governs.

On premises

Operated inside your environment

A containerized deployment keeps the application and database where policy requires them, including environments without a public marketing surface.

Enterprise deployment scope, infrastructure ownership, and operating responsibilities are defined during architecture review.

The short answers

Start the review with the hard questions.

Security teams should not have to reverse-engineer a sales claim. These are the boundaries we expect you to test.

Can an agent see the credentials assigned to it?

No. Secret values are write-only after entry. The credential broker adds them only to an approved outbound request and removes sensitive material before the response returns to the agent.

Can we block or approve outbound network access?

Yes. Workspace egress can use approved destinations, require approval for a new destination, or be disabled when the work does not need a network connection.

Does an agent inherit all of a user’s access?

No. User roles and agent ceilings are separate. Effective agent access is the overlap between the agent’s configured ceiling and the authority of the person delegating the work.

What does the audit trail capture?

Delegate records every platform-mediated human and agent action, including work-stream activity, approvals, role changes, workspace commands, and cost attribution.

Can Delegate run inside our environment?

Yes. Enterprise deployments can run in your GCP or AWS environment, or as a containerized on-premises deployment. Delegate is also available as a managed cloud service.

Bring your architecture diagram

Let your security team try to break the model.

We’ll walk through permissions, secrets, network paths, evidence, and the deployment boundary with them.