SECURITY & GOVERNANCE
Connected intelligence.
Control stays with you.
Scoped access. Explicit approval. A traceable action.

BEFORE WE CONNECT
Agree the boundaries.
Access, data, and responsibilities are agreed for your engagement.
Access
- Read-only access wherever the workflow does not require writing.
- Least privilege by default: access is scoped to the specific data a workflow needs, not to whole systems.
- Credentials are created, held and revocable by you. You can withdraw TAG’s access without TAG’s cooperation.
- Role-based access on TAG’s side, so an individual’s access ends when their involvement does.
Data
- Your data stays within the environments agreed in advance. Moving it anywhere else is a change that requires your approval.
- Encrypted in transit and at rest across the platforms TAG operates on.
- Personal data is minimized: a workflow receives the fields it needs and not the record around them.
- Retention and deletion are agreed per engagement, in writing, including what happens at the end of one.
AI boundaries
- No uncontrolled uploads to public models. The providers in scope are named, and changing one is a documented decision.
- Model and provider boundaries are explicit: which model sees which data, for which task, under which terms.
- Deterministic logic is preferred wherever it is sufficient. A model is used when judgment is genuinely required, not by default.
- Prompt content is treated as data, never as instructions from a trusted source.
Evidence and oversight
- Source lineage: every figure traces back to the system and record it came from.
- Audit logging of what the layer read, recommended, and did.
- Incident handling with a named contact and an agreed notification path.
- Measurement after the fact, so a claimed outcome can be checked rather than believed.