Default deny
An empty policy grants nothing. Sources, tables, rows, columns, operators, writes, and egress budgets are explicitly scoped for each agent.
Oliver separates deterministic policy enforcement from the reasoning layer agents use to improve. Every agent receives its own policy, every query is constrained before execution, and every action can be attributed and reviewed.
An empty policy grants nothing. Sources, tables, rows, columns, operators, writes, and egress budgets are explicitly scoped for each agent.
Agent Flight Control rewrites the query to include the permitted scope instead of relying on a blocklist to recognize every unsafe query an agent might invent.
Allowed and denied statements are recorded with the rewrite, mask, or clamp applied. Reasoning artifacts and operator history can be preserved separately for review.
Agents may learn from tenant‑scoped reasoning history, but the policy layer does not self‑modify. Policy changes remain subject to the customer’s approval process.
Oliver can run inside your VPC so data, network controls, and keys remain within your perimeter, or as a managed deployment operated with Oliver. Identity integration, encryption requirements, audit retention, data residency, incident response, and regulatory obligations are documented and scoped for each production deployment.
Oliver does not claim a certification merely because a customer requests it. Current controls and required obligations are reviewed directly during security evaluation.