Tenant scope
Organization, project, account, environment, and resource ownership are checked explicitly.
Built for trust
You own the cloud. You set the limits. You can stop access at any time.
Your cloud stays yours
UltraInfra uses temporary, customer-controlled access for approved work only.
Checks before change
Clear rules decide whether a change can happen—not a model response.
Organization, project, account, environment, and resource ownership are checked explicitly.
Required sources, freshness, coverage, and version alignment fail closed when incomplete.
Autonomy mode, budget, risk, maintenance windows, entitlements, and safety stops govern eligibility.
Purpose-scoped AWS credentials resolve only for the exact approved operation.
Immutable evidence binds parameters, workflow, policy facts, and evaluation versions.
Expected and actual outcomes determine completion, rollback, abandonment, or escalation.
Straight answers
New actions require a valid connected role and exact-account STS validation. Removing or invalidating that role stops new AWS authority. Offboarding preserves customer ownership and an appropriate sanitized history.
No long-lived IAM user access keys are required for the supported customer connection model. The system assumes a role and receives expiring AWS STS credentials.
Candidate plans may be generated from semantic context, but only versioned action-catalogue operations can reach the independent action evaluator and workflow layer.
Decisions expire or re-evaluate when their bound facts, parameters, authority, or workflow context no longer match. The safe result is to stop rather than reuse stale authorization.
No. Current provider-neutral semantics support observation, recommendation, and planning only. They do not add GCP or Azure credentials, live collectors, or mutation paths.
Start with the cloud you have
Start with visibility. Add autonomy when you are ready.