20.0Access Profiles

Least privilege, derived from intent.

An Access Profile is a least privilege boundary for an agent, derived from a plain description of its job. Describe what the agent is for, and Xybern proposes the set of actions it should and should not be allowed to take.

Describe the job, get the boundary

20.1

You write what the agent is meant to do in plain English. Xybern derives an allowed and disallowed action set, plus guardrails, so the agent starts from least privilege rather than full access.

  • Allowed and disallowed actions proposed from intent
  • Guardrails suggested alongside the action set
  • Reviewed and edited before anything is enforced

Shadow, then enforce

20.2

Run a profile in shadow to watch what the agent would have been blocked from doing, without affecting live work. When the boundary looks right, switch it to enforce and actions outside the box are blocked or escalated.

  • Shadow mode surfaces would-be violations safely
  • Enforce mode blocks or escalates out-of-box actions
  • Boundaries are checked at the intercept, pre-execution

Least privilege that keeps up

20.3

As an agent's job changes, its profile can be re-derived from the new description, so the boundary tracks the work instead of drifting toward over-permissioning.

More in Authorisation & Charter.

Related capabilities on the same authorisation layer. Every one is enforced before an action runs and sealed to the Provenance Vault.

1.0Intent Contracts

Approve the plan once, enforce every step.

Learn more
2.0Mandates & Charter

Outcome-based rules, compiled for you.

Learn more
3.0Risk Verdict

A signed verdict, not a mystery score.

Learn more
4.0Rules

The audit view of what is in force.

Learn more

See Access Profiles in your workflow.

Put one workflow behind Xybern and watch every agent action authorised, and sealed to the vault.