Control access throughout an agent session.
Apply configured classification and operation rules to models, tools and destinations as the session handles information.
A session begins with the resources available to the user and process. What remains usable can change as the session encounters more sensitive information.
Classification changes what the session can use.
This example uses an enabled classification policy. A model’s permitted maximum classification must cover the session classification.
Example session 1 · policy enabled
Session classification
Public
The assigned example resources are permitted at Public classification.
| Resource | Operation | Approved information level | Available now |
|---|---|---|---|
| General model | Model | Public | Permitted |
| Restricted model | Model | Confidential | Permitted |
| Public reference | Read | Public | Permitted |
| Project record | Read | Confidential | Permitted |
| Public destination | Write | Public | Permitted |
| Internal record | Read / write | Internal | Permitted |
| Restricted destination | Write | Strictly Confidential | Permitted |
Session classification
Internal
The Internal session can read Public references. Writes to Public destinations are blocked.
| Resource | Operation | Approved information level | Available now |
|---|---|---|---|
| General model | Model | Public | Blocked |
| Restricted model | Model | Confidential | Permitted |
| Public reference | Read | Public | Permitted |
| Project record | Read | Confidential | Permitted |
| Public destination | Write | Public | Blocked |
| Internal record | Read / write | Internal | Permitted |
| Restricted destination | Write | Strictly Confidential | Permitted |
Session classification
Confidential
The general model is blocked. Confidential information cannot be sent to destinations approved only for lower levels.
| Resource | Operation | Approved information level | Available now |
|---|---|---|---|
| General model | Model | Public | Blocked |
| Restricted model | Model | Confidential | Permitted |
| Public reference | Read | Public | Permitted |
| Project record | Read | Confidential | Permitted |
| Public destination | Write | Public | Blocked |
| Internal record | Read / write | Internal | Blocked |
| Restricted destination | Write | Strictly Confidential | Permitted |
Session classification
Strictly Confidential
No enabled model is approved at this level. Execution cannot continue.
| Resource | Operation | Approved information level | Available now |
|---|---|---|---|
| General model | Model | Public | Blocked |
| Restricted model | Model | Confidential | Blocked |
| Public reference | Read | Public | Permitted |
| Project record | Read | Confidential | Permitted |
| Public destination | Write | Public | Blocked |
| Internal record | Read / write | Internal | Blocked |
| Restricted destination | Write | Strictly Confidential | Permitted |
A higher-classification read can raise the session level. Selecting a lower level above starts a new example session.
Lowering the example classification starts a new session.
Model policy
- Permitted model
- The session may use this model at its current classification.
- Blocked model
- The model is not approved for information at this classification.
- No permitted model
- Execution cannot continue until an approved model is available.
Tool policy
- Read
- Whether the session may obtain information from the operation. Read-only operations are not blocked simply because their classification is lower.
- Write
- Whether information from the current session may be sent to the destination. Write-capable operations targeting a lower classification are blocked by this policy.
Classification direction
Within a session, classification can increase when a configured capability returns more sensitive information. It does not decrease again during that session.
This is based on configured classifications, not automatic interpretation of arbitrary text.
Human review
Selected consequential actions can require explicit approval before execution continues.
Execution records
Recorded runs and decisions remain available for inspection.
Configuration boundary
Agantyx controls only the resources and policies configured within the platform. Connected systems continue to enforce their own security boundaries.