Security and Human Control

Bounded operational responsibility, never unrestricted autonomy.

Coda operates inside explicit customer-approved authority, coverage and service boundaries. High-impact, irreversible or insufficiently observable actions remain approval-gated or prohibited.

Control model

Six boundaries protect the operating relationship.

01

Identity and delegation

Every consequential action identifies the principal, role, purpose, scope and expiry.

02

Action boundaries

Actions are classified as observable, approval-gated, bounded autonomous or prohibited.

03

Human sponsorship

A named customer authority approves the mandate and retains veto over consequential changes.

04

Isolation

Operating credentials, environments and tools are separated by guild, customer and purpose.

05

Rollback and compensation

Autonomous remediation is limited to actions that are reversible or explicitly compensatable.

06

Evidence preservation

Decision, authority, action and outcome records remain available for inspection and replay.

Graceful degradation

When controls weaken, autonomy contracts.

NORMAL

Bounded autonomy

Approved actions execute inside the operating contract.

DEGRADED 1

Read-only mode

Observe and investigate without production mutation.

DEGRADED 2

Human-supervised mode

Every consequential action requires named approval.

CONTAINMENT

No execution

Revoke authority, preserve evidence and initiate incident response.

Customer control
Coda responsibility
Approve mandate and service boundary

Customer defines the business and risk envelope.

Operate within the approved envelope

Coda does not expand its own authority.

Name sponsors and approvers

Human accountability stays explicit.

Preserve escalation and evidence

Coda presents decisions with inspectable context.

Control data residency and access

Customer requirements shape deployment architecture.

Apply least privilege and isolation

Access remains scoped to the operating purpose.