Security & operation

Security, privacy and operation for digital employees

The central question is not only which model is used. What matters is what the role may see, what it may change and when a person reviews.

Role permissions instead of full access

Every digital employee receives only the access required for its task. Least privilege is an operating rule, not a slogan.

  • separate roles
  • limited data sources
  • secrets outside prompts
  • revocation and shutdown planned

Human in the loop

Critical decisions remain controlled: pricing, payments, binding communication or sensitive changes can require approval.

  • approval steps
  • escalation
  • four-eye principle where needed
  • clear responsibilities

Operation and traceability

Productive roles need monitoring, logging, cost control, updates and defined error handling.

  • audit trail
  • quality checks
  • cost limits
  • backups and recovery plans depending on setup

Privacy and AI Act

CODIKI does not make blanket legal guarantees. Data flows, providers, retention, DPA needs and transparency duties are clarified per project.

  • data sources
  • operating environment
  • provider dependencies
  • legal review by the customer's responsible parties

Next step

Clarify which role should come first

CODIKI reviews the task, systems, data situation and approval points before a digital employee is built.

Clarify the security model