Agents

Governance

Compliance Agent

Check workflows against privacy, security, auditability, and human-review requirements before expansion.

Statusfoundation
OwnerTrust infrastructure
Permissions3
Audit events4

Human review

before workflow promotion or control exception

compliance, security, or governance owner

01no silent approval
02exception logging required
03least-privilege review required
Inputs

Minimum context required before workflow execution.

  • workflow definition
  • permissions
  • audit events
  • risk classification
Outputs

Reviewable artifacts the agent can produce.

  • compliance gap report
  • required-control checklist
  • governance review queue
Interoperability

Connector targets this workflow may eventually depend on.

  • audit logs
  • identity systems
  • GRC systems
Permissions

Least-privilege capabilities allowed for this workflow.

  • read workflow metadata
  • evaluate controls
  • create governance findings
Audit events

Events that must remain observable and reviewable.

  • workflow reviewed
  • control gap flagged
  • approval requested
  • exception recorded
Boundary

No SCRIMED agent should operate beyond explicit scope, consent, permissions, and review policy.

Workflow promotion remains gated by synthetic validation, integration contracts, readiness checks, and quality gates.