# Security

## Trust comes from boundaries you can see.

lilis is designed around explicit access, human approvals, and a complete record of the work it prepares.

## The operating principles

- **Least necessary access**: Connections and permissions should match the work the organization has chosen to enable.
- **Human approval for outbound work**: Prepared communication remains reviewable before it is sent. The one exception is an optional instant acknowledgment, off by default, sent from a fixed template we write.
- **Evidence and history**: Sources, proposed actions, decisions, and outcomes remain correlated.
- **Organization boundaries**: Workspace information belongs to the organization context where it was created.

## Access and people

Workspace membership and roles provide the starting point for deciding who can see and change information. More granular policy checks can build on the same decision point as the product expands.

## Approval and autonomous work

The approval state is part of the work record. If an action is allowed to run without a fresh approval in the future, it still needs the same complete artifact, evidence, and outcome history.

## Operational trust starts with a clear handoff.

The source, prepared action, decision, and outcome stay together so the person responsible can see what changed and who decided.

## Questions for your review

Security requirements vary by business and connection. We can walk through the data involved, the access boundary, and the operational controls before a connection is enabled.

## Bring us the hard questions.

We will answer specifically and tell you when a control is planned rather than present today.

- Talk to us
