Security

Control access. Isolate execution. Keep evidence.

Agent work can cross repositories, data, tools, and external systems. Latchbox makes the boundaries explicit before execution starts.

policyenforced
identityruntimeevidence

Security model

Controls follow the workflow, not one temporary machine.

The control plane keeps state, policy, and evidence outside the environment where an agent executes.

01

Least access

Declare identity, permissions, network reach, and credentials for each step.

02

Bounded execution

Keep code and tools inside an isolated runtime with budgets, timeouts, and policies.

03

Independent proof

Preserve the record after the environment ends so results remain inspectable.

Control layers

Put a clear boundary around every action.

01

Short-lived credentials

Issue access for the step that needs it, within the scope and time defined by policy.

02

Isolated execution

Run work in an explicit environment boundary with declared network, file, and resource permissions.

03

Human approval gates

Pause before sensitive actions so a person can approve, reject, edit, or redirect the workflow.

04

Live operational control

Inspect tool calls, changes, costs, errors, and decisions. Pause, cancel, retry, replay, or reassign work.

05

Durable evidence

Keep inputs, versions, activity, tests, approvals, errors, outputs, and artifacts outside the sandbox.

06

Deployment choice

Use Latchbox-hosted execution or, with Enterprise, a VPC, customer cloud, or external runtime.

A risk boundary

Let agents move quickly inside the rules.

Policies and human gates define when a workflow can continue automatically and when it must stop for a decision.

01Read repositoryautomatic · scoped
02Change codeisolated · checkpointed
03External writehuman approval required

Deployment options

Choose where execution happens. Keep the workflow portable.

Self-serve

Latchbox-hosted execution

Start with hosted remote environments and bring your own model keys with no surcharge.

Enterprise

Your network and runtime boundary

Use private networking, IP allowlists, customer-managed keys, a VPC, customer cloud, or external runtime.

Identity and evidence

Organization controls

Add SAML SSO, SCIM, roles, policies, audit export, and custom proof retention.

Early access

Bring your security boundary into the workflow.

Tell us about the controls and execution model your team needs.

Get early access