Security · Governance

Governance is the product, not the paperwork.

SenseMesh exists to make enterprise information consumable by machines — which only works if every definition, product and answer is owned, classified and traceable. This page covers the control model, provenance guarantees and deployment posture.

100%

Lineage-traced answers

0

Ungoverned agent paths

3

Deployment models

24/7

Audit event capture

01Access controls

Who — human or agent — can see what

Access is governed at the level of meaning, not just storage. Agents are principals with scopes, exactly like people.

01

Role- and domain-scoped access

Permissions attach to domains, entities and intelligence products — not just tables. A user or agent sees only the products their role and domain assignment allow.

RBACdomain scopingproduct-level grants
02

Sensitivity classification

Every column, entity and derived product inherits a sensitivity class from discovery forward. Classification travels with lineage, so downstream products cannot silently declassify data.

inheritancePII detectionmasking policy
03

SSO and directory sync

Enterprise identity providers connect via SAML and OIDC, with SCIM provisioning for joiners, movers and leavers. Agent identities are first-class principals with their own scopes.

SAML / OIDCSCIMagent identities
04

Policy-as-code guardrails

Consumption policies — what an agent may query, join or export — are versioned code reviewed like any other change. Every evaluation against policy is recorded.

versioned policyquery guardrailsexport controls

02Data provenance

Every answer can be walked back to its sources

Provenance is captured at each stage — registration, lineage, authorship and decision — so trust is verifiable rather than asserted.

Source registration

Each connected system is registered with owner, connection mode and read scope. Nothing enters the mesh unregistered.

Field-level lineage

Every attribute in every intelligence product traces to concrete source fields, transforms and freshness windows.

Definition authorship

Business definitions carry named owners and approval history. Changes are versioned and attributable.

Decision lineage

Answers returned by the assistant or an agent cite the exact products, definitions and sources used — replayable end to end.

An agent that cannot cite its sources is a liability. Every SenseMesh answer ships with the lineage to defend it.

03Tenant isolation

Multi-tenant by design, isolated by default

Tenants are separated at data, semantic and runtime layers. No shared definitions, no shared caches, no cross-tenant inference.

Data layerisolated
  • Per-tenant storage partitions
  • Tenant-scoped encryption keys
  • No shared query caches
Semantic layerisolated
  • Per-tenant meaning graphs
  • No cross-tenant definitions
  • Scoped connector credentials
Runtime layerisolated
  • Tenant-tagged audit events
  • Isolated agent execution contexts
  • Per-tenant retention policy

Control coverage across reference deployments

Policy evaluation coverage100%
Lineage completeness96%
Classified attribute coverage93%

04Deployment security

Runs where your data is allowed to live

SenseMesh deploys in the model your regulators and architecture teams require — without giving up the governance plane.

Managed cloudsupported

SenseMesh-operated, regional isolation, data residency selectable per tenant.

Customer VPCsupported

Deployed into your cloud account; compute and storage never leave your boundary.

Air-gappedsupported

Fully disconnected operation for regulated estates, with offline model and connector bundles.

Need architecture review or pen-test evidence?

We walk security teams through the control model and share assessment artefacts under NDA.

Contact security team