Governance is part of the product core.

Controlled autonomy means clear approvals, technical boundaries, and verifiability in a security review.

nordnung.ai — audit.log
> session start — ticket #4821
instance isolation verified
AUDIT: dedicated instance · data center DE
> request credential — exchange
vault injection to approved asset
POLICY: no plaintext passwords in LLM context
> execute action — mailbox permission
approved by admin@customer.com
AUDIT: signature + method call recorded
> kill switch available
session can be stopped anytime

Eight commitments, all verifiable.

Each commitment maps to a control point in the audit log.

  • Hosted in GermanyDedicated instance per customer
  • Instance isolationData & execution separated
  • Credentials in VaultAES-256, approved assets
  • Passwords never in plaintextCredentials engine
  • Audit logIntegrity-checked, per step
  • Kill switchStops instantly
  • EU model routingEU regions only
  • DPA & security reviewReview on request

Approvals inbox

Approvals before anything happens

Every pending action lands in one inbox, sorted by risk. In operating mode 1, no step runs before an admin has approved it.

Try it: approve or reject — just like in the platform.

From 1,348 analyzed support tickets we know: 56% can be fully automated. The decision when that happens stays with a human.

nordnung.ai — approvals-inboxSchematic view · German product UI · demo data

Offene Freigaben (3)

Workflow-SchrittRisiko: Hoch

M365-Benutzer anlegen

Erfordert manuelle Freigabe — ein Admin gibt den Lauf frei, bevor der Schritt ausgeführt wird.

Workflow · Mitarbeiter-Onboarding

Session-ToolRisiko: Mittel

Diagnose-Skript am Arbeitsplatz ausführen

Werkzeug innerhalb einer laufenden Support-Session — Freigabe direkt aus der Inbox, ohne Detail-Sprung.

Gerät · FIN-PC-04

Workflow-SchrittRisiko: Niedrig

SharePoint-Liste lesen

Lesender Zugriff — bleibt zur Nachvollziehbarkeit trotzdem in der Inbox sichtbar.

Workflow · Lizenz-Übersicht

Operating modes

Autonomy is deliberately staged

Operating mode 1

Every relevant action requires approval — for pilots and sensitive environments.

Operating mode 2

After initial approval the agent works within a defined user context; allowed methods stay limited.

Operating mode 3

After initial approval, defined client admin actions are possible — no free shell access.

Data handling

Data flow and providers

  • Intake, controlled execution, and feedback are separate paths — not every piece of information reaches every path.

  • Wrapper actions instead of free code or shell execution; least privilege per agent, scope, and endpoint.

  • Audit and operational data retained only as long as needed for traceability and support — details in DPA and review.

  • Goal: maximum independence from external providers; open-source principles as the strategic core.

Align security review and pilot directly.

Security: Governance, boundaries, and audit logs | nordnung.ai