For security and governance

Test Onterix against your security model.

Choose one real capability and challenge it with a permission change, protected data, a stale approval, and an interrupted write. Review the observed result and evidence before deciding whether it can advance.

Redacted acceptance report · renewal capability v3.2

Run the failure drills. Record what happened.

This representative review used Maya Chen through Codex, a scheduled renewal agent, Salesforce production-like data, and the approved DLP policy.

  1. 01

    Change a permission

    Remove source access after a successful run.

    Observed result
    The next run omitted the revoked Salesforce opportunity fields and blocked the renewal brief instead of reusing earlier context.
    Evidence and disposition
    SEC-ACPT-01 · Pass · no exception
  2. 02

    Challenge data release

    Introduce restricted data into an otherwise permitted result.

    Observed result
    A private call note remained in Salesforce while Codex received the seven fields approved for the renewal brief.
    Evidence and disposition
    SEC-ACPT-02 · Pass · released derivative retained
  3. 03

    Invalidate an approval

    Change a record, value, recipient, source revision, or policy after review.

    Observed result
    Changing the customer recipient superseded APR-208. The send stopped before delivery and requested a new review.
    Evidence and disposition
    SEC-ACPT-03 · Pass · stale approval refused
  4. 04

    Reconcile an uncertain write

    Submit a Salesforce update, then interrupt the response after the write may have landed.

    Observed result
    Reconciliation found the accepted stage change at revision 1843, recorded the provider result, and did not submit a second update.
    Evidence and disposition
    SEC-ACPT-04 · Pass · one provider mutation

Review output

Reconstruct the test and make the adoption decision.

The review keeps tested identities, source access, rule versions, approvals, execution attempts, reconciliation, results, exceptions, and owners together without exposing secrets.

Read the security architecture
  • Scope · renewal capability v3.2 · two actor classes · Codex and API clients
  • Result · four of four failure drills produced the expected safe behavior
  • Exception · DLP failover runbook needs a named secondary owner by August 5
  • Decision · pilot remains blocked until that exception closes and the drill is rerun

Plan the security evaluation

Bring one real capability and the security requirements it must satisfy.

We will map the failure drills, run them under representative conditions, and leave with observed evidence, owners, exceptions, and a decision.