Skip to content

Data movement and approval gates

The Data Movement view documents permitted flows between an agent, governed connection, resource and destination. Approval Gates identify actions that require a bound human decision. Together they make authority understandable before Gateway evaluates a live request.

For each flow, document source, destination, purpose, data classification, affected people, geography, retention and permitted action. Include indirect movement through model providers, plugins, queues, logs and generated attachments.

Do not infer permission from technical connectivity. A reachable destination is not an approved destination. Restrict sensitive and regulated data to the minimum fields and period needed, and test redaction and egress controls.

Require approval when the action is high-impact, irreversible, external, financially material, privilege-changing, broad, production-facing or otherwise outside routine bounded authority. Specify the approver role, decision context, expiry and conditions.

An approval must refer to the same agent, action, resource, target, environment and request context that will execute. Generic standing consent should not be used where transaction-level review is required.

The requester or policy submitter cannot satisfy an independent approval requirement for the same authority. Runtime Policy Approvers can inspect assigned policy context and approve or reject; they cannot draft or edit policy through that role. MFA and step-up verification apply to sensitive decisions.

  • Every material ingress and egress path is represented.
  • Data classification and geographic restrictions are current.
  • External recipients and subprocessors are identified.
  • High-impact actions have an appropriate approval gate.
  • Approval is request-bound and time-bounded.
  • Denial, timeout, withdrawal and dependency failure stop execution.