Home
Security and governance

Control follows every identity and action.

NelliaOS brings access policy, approval and operating evidence into the workflow itself. Security responsibilities remain explicit across the platform, integrations and deployment.

Roles and resource scope

Role permissions combine with account, queue and record access. Reading, preparing, approving, sending and administering are distinct permissions, evaluated against the current identity and resource.

Security

Authority follows the work

Roles define the starting permissions. Account, queue and resource scope narrow access further. Sending follows the approved outbound policy; approval remains a separate action.

Explore a role

Owner

Organization policy and explicitly granted resources

Authority follows the work: Owner
ReadAllowed within scope
PrepareAllowed within scope
ApproveAllowed within scope
SendAllowed within scope
AdministerAllowed within scope

Owns the organization policy. Actions still follow resource scope, outbound rules and required separation of duties.

Put the operating system to work.

Explore an interactive product walkthrough. Choose a conversation, guide an agent through review or turn a customer signal into a useful next action.

NelliaOSTeam workspace
Interactive walkthrough
Agent workflow
Assigned task

Prepare a response to the site request and assign the next operating step.

The task brings its context.

The agent reads the request and the relevant operating sources within the assigned account boundary.

Permitted context
Conversation

The site request and current task owner

Operating procedure

The handoff and exception procedure

Account policy

Assigned account scope and review rule

Access and data

Define who can work with each resource.

Organization membership and resource boundaries determine access before a workflow reaches a tool or connected account.

Managed identities

SSO, MFA and SCIM connect the platform to the organization's identity lifecycle. Human and agent identities have distinct credentials, delegated scope and revocation paths.

Explore in practice
Connected context
Defined authority
Accountable outcome
Explore the control boundaryMap this into your operation

Roles and resource scope

Role permissions combine with account, queue and record access. Reading, preparing, approving, sending and administering are distinct permissions, evaluated against the current identity and resource.

Explore in practice
Connected context
Defined authority
Accountable outcome
Explore the control boundaryMap this into your operation

Data boundaries and encryption

Tenant separation extends to storage, retrieval and integration credentials. Encryption in transit and at rest supports the selected deployment, with defined key ownership and data-location responsibilities.

Explore in practice
Connected context
Defined authority
Accountable outcome
Explore the control boundaryMap this into your operation
Operational assurance

Make the path to an outcome inspectable.

AI execution and human decisions leave an operating record that the responsible team can review.

Approval and decision history

Policy identifies the actions that require review and the people authorized to approve them. The record connects the proposal, decision, execution and result, including refusals and failed attempts.

Explore in practice
Connected context
Defined authority
Accountable outcome
Explore the control boundaryMap this into your operation

Model and tool controls

Model routing follows the task and its data policy. Evaluations support capability releases, while tool scope and usage budgets constrain the work an agent can perform.

Explore in practice
Connected context
Defined authority
Accountable outcome
Explore the control boundaryMap this into your operation

Auditability and recovery

Operational logs support investigation and service ownership. Incident procedures, backup responsibilities and recovery exercises form part of the deployment's operating plan.

Explore in practice
Connected context
Defined authority
Accountable outcome
Explore the control boundaryMap this into your operation
Talk to Nellia

Review the control boundary with your team.

The governance guide maps identity, data, AI execution and operational responsibility into questions your security and platform teams can use in an architecture review.

Discuss your operation