Docs navigation

Security: Credentials, Authority, and Evidence

Scoped credentials, explicit authority at one gate, and an inspectable record. Security claims must match the coverage of the actual installation.

Published August 9, 2026

Giving an AI operator a useful job also means defining what it can access and what it may do. Figaro’s security model separates credentials, proposal rights, and authority to execute.

Credentials stay scoped

The native system stores service credentials in an encrypted vault and supplies them to authorized integrations server-side. External AI access uses scoped bearer tokens stored as hashes. Ordinary agent and integration credentials support reading and proposing; they do not create approval authority.

Credentials must never fall back from one brand to another. Missing credentials require a named refusal. Each installation’s access paths and tenant isolation need verification before real accounts are connected.

One gate, explicit authority

The current native operator system requires human approval for consequential writes. Powered by Figaro’s authority model permits policy or watchdog resolution only inside an active human-granted envelope. These are deciders at the same gate, not alternative execution routes.

Money movement is denied by default. Bounded exceptions require explicit grants within provider, legal, and platform constraints. Rank, urgency, and good past results do not create authority.

Autonomy stays inside its grant

The goal is less routine supervision with a defensible record. Authority is defined per action class and company. Wider scope requires a human decision informed by evidence. No agent can grant itself more permission. See the current autonomy model and its rollout status.

Keep the evidence inspectable

A decision record links who proposed, who resolved authority, the action taken, and the later result. Corrections are added to the record. Execution correctness, judgment quality, and governance quality are distinct: a favorable business outcome does not excuse crossing an authority boundary.

Confirm coverage before connecting the business

A design principle is not a security attestation. In a managed implementation, the agreed scope must identify the connected systems, permitted actions, access controls, verification evidence, and gaps. The Powered by Figaro mark depends on verified enforcement coverage.

Questions founders ask

Can a connected AI approve its own actions?
Ordinary agent and integration credentials only propose. A policy or watchdog can resolve the canonical gate only with explicit active authority and provenance. Agents cannot grant themselves authority.
Are all action classes already autonomous?
No. The native operator system uses human approval for consequential writes. Broader Powered by Figaro resolution coverage must be verified per installation.
Drafted by the Figaro content seat · edited by Fable · reviewed by Kyle · last updated September 15, 2026