Skip to content
Splashgain

The permission line

Signed before go-live, not discovered after

Acts alone

Routine, low-risk or reversible work.

  • Reminders and status updates
  • Tagging, sorting and routing work
  • Reports and summaries
  • Deleting data already past your retention period

Drafts for approval

Anything touching money, contracts or a promise.

  • Replies that commit your organisation
  • Payments, refunds, discounts and quotations
  • Contract terms and letters to a regulator

Never does

Decisions that belong to a person.

  • Credit, hiring or disciplinary decisions
  • Legal advice or statutory orders
  • Anything outside the line you signed

The controls

What a reviewer can check

A record of every action

Each step can be traced and exported.

  • The input, the sources used and the action taken
  • Who approved it, and when
  • Exportable for your auditors

A boundary for your data

Your cloud or ours; your rules either way.

  • Deployed in your cloud account or on a CERT-IN certified stack
  • Residency and retention rules you set
  • Never used to train a public model

Limits on what it can touch

Access to each system is granted, not assumed.

  • Every system rated before it is connected
  • Read-only unless writing is required
  • Permissions listed in the go-live sign-off

Answers with sources

Every answer shows where it came from.

  • Answers cite the document or record used
  • “I don’t know” is an allowed answer
  • Unclear cases handed to a named person

Proof the job ran

Silent failures are caught, not discovered weeks later.

  • Health monitoring on every scheduled run
  • An alert when a job runs but produces nothing
  • A monthly report on the agreed metric

A named owner and a way back

Someone is accountable, and changes can be undone.

  • A named owner on each side
  • Rollback to the previous version
  • On Agent Partner, source code and IP transfer to you

Questions reviewers ask

Before you sign off

Who decides what an agent may do alone?

You do, in writing, before go-live. By default anything touching money, contracts or a customer promise is drafted for a person to approve.

Is our data used to train AI models?

No. Your data never trains a public model. Agents run in your cloud or ours, under your retention rules.

Can we see what an agent did last month?

Yes. Every action is logged with its input, the sources used and the approver, and the log can be exported for your auditors.

What happens when the agent is unsure?

It says so. Unclear answers and unusual cases go to a named person with the context attached, rather than being guessed.

Does this make us DPDP compliant?

Compliance under India’s Digital Personal Data Protection Act stays with your organisation. The agents are set up to support it: limited access, retention rules you set, logged actions and data kept where you decide. Review the configuration with your data protection lead.

Which certification do the products hold?

Eklavvya and DocuExprt are CERT-IN certified under the MeitY empanelment scheme.

Bring your security questionnaire.

Walk through the approval line, the logs and the data boundary with the engineers who build the agents.

Book a governance review

Or call +91 95525 86428

Book a demo

See it running on your process