# Make authority explicit.

> Design security-agent operations around declared capabilities, bounded connector actions, policy context, specific approvals, and reconstructable execution evidence.

Canonical: https://rangoon.ai/solutions/security/

Status: In active development. Product screenshots are design previews with illustrative data. No general availability is implied.

## Configuration is not authority

Giving an agent a security skill should not silently authorize every operation that skill describes.

### Decision-time controls

The planned model evaluates consequential requests with their target, scope, policy, and expected side effect.

## Review the actual request

Approval designs should name the requesting agent, resource, data, risk, policy, scope, expiration, and supporting evidence.

### No vague grants

The objective is to approve or deny an actual operation rather than an indefinite permission.

## Reconstruct the path

Audit Explorer direction links proposal, effective configuration, policies, approvals, authorization, connector result, receipt, and evidence.

### Preview status

Security workflows and integrations are in active development.


## More information

- [Documentation index](https://rangoon.ai/llms.txt)
- [AI access and policies](https://rangoon.ai/ai/)
- [Source repository](https://github.com/hypler-dev/rangoon)
