Page guideGuided mode

AI & agents

Configure and use governed AI while preserving human control, evidence and auditability.
Recommended next action: Confirm provider readiness, evidence and approval boundaries before using generated output.
Page-guide progress0/3 · 0%
Page guide progress 0 percent
OPSIQO Guard · AI Governance Center

Control what every Cortex agent may do

Organization settings can tighten an agent below its hard safety cap, never expand it beyond the code-defined boundary.

Governed AI foundation

Provider readiness, active governed prompt and active model profile for this organization.

Checking…
Checking governed AI configurationNo credential values are exposed to the browser.
Loading agent governanceReading effective policy without exposing model credentials or sensitive evidence.

Safe Execute readiness

V7.18 keeps Execute expansion evidence-gated rather than adding authority because an action merely looks convenient.

Mark my direct notifications read

Low-risk, self-scoped, permission-rechecked, capped, audited and delegated to the authoritative notification service.

enabled
Exact allowlist match

Safe execution rejects any routed action other than notifications.mark_visible_read.

implementation pass
Permission recheck

notifications.read is rechecked inside the executor before the authoritative service is called.

implementation pass
Direct-user scope

The authoritative notification service mutates only unread records explicitly targeted to the signed-in uid.

implementation pass
Shared-role isolation

Role-wide/shared notifications are not marked read by the self-service Execute action.

implementation pass
Bounded mutation

The action uses a hard batch cap of 100 records per command.

implementation pass
Consequential firewall precedence

Consequential employment patterns are evaluated before the safe Execute route.

implementation pass
Authoritative domain service

The command layer delegates to the notification service rather than writing Firestore directly.

implementation pass
Two-user isolation

Verify in emulator/UAT that one user cannot change another user’s direct or role-wide notification state.

browser UAT required
Retry and reconciliation

Exercise network interruption/retry and confirm the UI reconciles with authoritative notification state.

browser UAT required
Accessible execution feedback

Verify completion/error status is announced without unexpected focus movement.

browser UAT required
Multilingual execution feedback

Verify the action and receipt remain understandable in English, French, Spanish and Arabic.

browser UAT required
Change my interface language

Potentially low-risk self-service, but V7.17 does not enable another Execute action until V7.16 Execute behavior is UAT-proven.

hold for UAT
Change my accessibility appearance preferences

Potentially low-risk self-service, but requires explicit UAT evidence before entering the Execute allowlist.

hold for UAT

V7.19 still does not add a second Execute action. No dependency-backed multi-user/browser UAT evidence was supplied for promotion, so expansion remains on hold even though candidate preference actions are technically reversible.

Safety invariants

Observe

Permission-scoped reads only.

Recommend

Evidence-backed suggestions; human decides.

Prepare

Drafts and plans stop at review/confirmation.

Execute

Only code-registered low-risk actions can ever reach this level; current agent hard caps remain below unrestricted execution.

Shadow Mode lets administrators compare what an agent would prepare with the actual human workflow before granting broader operational authority.