Security · Governance
Governance is the product, not the paperwork.
SenseMesh exists to make enterprise information consumable by machines — which only works if every definition, product and answer is owned, classified and traceable. This page covers the control model, provenance guarantees and deployment posture.
100%
Lineage-traced answers
0
Ungoverned agent paths
3
Deployment models
24/7
Audit event capture
01Access controls
Who — human or agent — can see what
Access is governed at the level of meaning, not just storage. Agents are principals with scopes, exactly like people.
Role- and domain-scoped access
Permissions attach to domains, entities and intelligence products — not just tables. A user or agent sees only the products their role and domain assignment allow.
Sensitivity classification
Every column, entity and derived product inherits a sensitivity class from discovery forward. Classification travels with lineage, so downstream products cannot silently declassify data.
SSO and directory sync
Enterprise identity providers connect via SAML and OIDC, with SCIM provisioning for joiners, movers and leavers. Agent identities are first-class principals with their own scopes.
Policy-as-code guardrails
Consumption policies — what an agent may query, join or export — are versioned code reviewed like any other change. Every evaluation against policy is recorded.
02Data provenance
Every answer can be walked back to its sources
Provenance is captured at each stage — registration, lineage, authorship and decision — so trust is verifiable rather than asserted.
Each connected system is registered with owner, connection mode and read scope. Nothing enters the mesh unregistered.
Every attribute in every intelligence product traces to concrete source fields, transforms and freshness windows.
Business definitions carry named owners and approval history. Changes are versioned and attributable.
Answers returned by the assistant or an agent cite the exact products, definitions and sources used — replayable end to end.
An agent that cannot cite its sources is a liability. Every SenseMesh answer ships with the lineage to defend it.
03Tenant isolation
Multi-tenant by design, isolated by default
Tenants are separated at data, semantic and runtime layers. No shared definitions, no shared caches, no cross-tenant inference.
- Per-tenant storage partitions
- Tenant-scoped encryption keys
- No shared query caches
- Per-tenant meaning graphs
- No cross-tenant definitions
- Scoped connector credentials
- Tenant-tagged audit events
- Isolated agent execution contexts
- Per-tenant retention policy
Control coverage across reference deployments
04Deployment security
Runs where your data is allowed to live
SenseMesh deploys in the model your regulators and architecture teams require — without giving up the governance plane.
SenseMesh-operated, regional isolation, data residency selectable per tenant.
Deployed into your cloud account; compute and storage never leave your boundary.
Fully disconnected operation for regulated estates, with offline model and connector bundles.
Need architecture review or pen-test evidence?
We walk security teams through the control model and share assessment artefacts under NDA.