Skip to main content

Security and governance

Narrow access. Control every action.

Friday limits what every source, person, and agent can reach. High-impact actions pause for approval. Every decision stays reviewable.

Minimum scopeHuman approvalEvidence trail
Permission review / workflow 04Enforced

Source scope

Selected accounts only
allowed

External action

Create customer update
approval

Evidence record

Source · decision · outcome
retained

Default rule

Read before acting

Source and workspace controls

Connect deliberately. Scope precisely.

Friday starts from explicit authorization. Workspace owners decide which accounts, sources, and operating scopes become available.

Explicit connections

Sources enter through authorized accounts—not shared credentials or uncontrolled scraping.

Minimum useful scope

Owners choose the tools, accounts, keywords, and operating areas each workflow needs.

Workspace roles

Administrative settings remain separate from ordinary product use.

Audit export

Connection, sync, membership, configuration, and agent activity remain reviewable.

Agent guardrails

Permission narrows before consequences rise.

Agents begin with read-only evidence. Write access appears only where the workflow needs it, and approval sits between suggestion and consequence.

  1. 01DiscoverRead-only

    Verify the constraint without write access.

  2. 02SuggestDraft only

    Prepare the next step without creating an external effect.

  3. 03ApproveHuman gate

    Pause consequential, irreversible, or high-impact actions.

  4. 04ExecuteAllowlisted

    Run only the exact action authorized for the workflow.

  5. 05ReviewEvidence kept

    Preserve the source context, decision, action, and result.

Visible evidence

Know what happened and why.

Every reviewable action keeps the identity, source context, approval decision, execution result, and time of change together.

01 / Actor

Person, service, or permissioned agent

02 / Source

Evidence and connected account used

03 / Decision

Requested action and approval state

04 / Outcome

Result, timestamp, and review status

Latest event / 14:32:08

Customer update approved before external delivery.

Approval recorded

Shared responsibility

Security ownership stays explicit.

Review the deployment boundary
LayerCustomerFriday
InfrastructureCustomer configures and operatesFriday provides deployment guidance
IdentityCustomer defines policy and membershipFriday enforces workspace roles
DataCustomer owns scope and retentionFriday keeps vendor retention at zero
Agent actionsCustomer authorizes boundariesFriday applies tools and approval gates

Exact controls, operating ownership, and review procedures are documented during personalized onboarding.

Security working session · 15 minutes

Bring your requirements. Leave with a control map.

We will define the deployment boundary, source scope, agent permissions, approval gates, audit evidence, and ownership for the first workflow.

Start personalized onboarding Built around your workflow, not a generic tour
  1. 01Verified bottleneck
  2. 02Sovereign deployment
  3. 03Permissioned agent