← Resources

Security and governance

Governing autonomous infrastructure agents

Governed autonomy allows agents to operate independently inside explicit customer boundaries while preserving attributable decisions, revocable authority, verification, and recovery.

Govern the decision, the authority, and the outcome

An approval dialog alone is not governance. The system must establish that the evidence is sufficient, the action is semantically applicable, current policy permits it, the exact authority is available, and the outcome will be verified.

Use autonomy modes to make trust progressive

Teams should be able to begin with observation and explanation, advance to recommendations or approvals, and enable independent execution for action classes they trust. Modes must change authorization—not merely change the interface label.

  • Observe: understand the environment without mutation authority.
  • Recommend: produce evidence packets and counterfactual plans.
  • Approve: execute only after an authorized reviewer accepts the exact plan.
  • Autonomous: execute eligible actions inside configured scopes and thresholds.

Make stopping a first-class behavior

Expired evidence, changed parameters, missing coverage, stale policy, budget breaches, active safety stops, verification failure, or a conflicting operation should stop or re-evaluate the action before mutation continues.

Common questions

Can customers revoke UltraInfra access?

Yes. Customer-owned cloud connections should use revocable roles and temporary credentials. Disconnect and offboarding must stop new actions without requiring the customer to surrender ownership of their runtime.

Primary references

Turn operational evidence into verified improvement.

Start with visibility. Add autonomy when you are ready.

Privacy controls

Your choice applies to this website and the UltraInfra portal. You can change it at any time.