Humetry
Security and control

The model supplies reasoning. The platform decides what it may do.

A worker that writes to your ERP is trusted the way a new hire is trusted: with a defined identity, scoped permissions, supervision that lifts in stages, and a record of everything it did. The controls below are enforced by the platform on every action, not by the model's good judgment.

intent · idempotency key write sent timeout status check written re-read verified not written: retry, same key
Where the system supports it, every write carries an idempotency key or a transaction identifier. A timeout after a write triggers a status check before any retry. The resulting document state is re-read and recorded; a case is complete only when that re-read matches the intent.
Verification
01

The write protocol

Where the system supports it, every write carries an idempotency key or a transaction identifier. A timeout after a write triggers a status check before any retry. The resulting document state is re-read and recorded; a case is complete only when that re-read matches the intent.

02

Checks that do not trust the model

Numerical validation and rule enforcement use explicit logic. Model conclusions are checked against source documents and system state before they become actions. Agreement between two agents is not proof of correctness.

03

Reversal is a business process

Reverting a procedure version does not reverse a transaction already committed in your system. Correction follows the proper reversal, compensating entry or authorised recovery, with its own audit history.

The identity, drawn as a key's bitSpecimen: the accounts payable worker's identity
reads writes Purchasing records Goods receipts Supplier master Open items Supplier invoicescreate · park · release Credit memo requestscreate, approval-routed Payment runproposal · run · medium Bank releasereserved: no cut Supplier bank detailsreserved: no cut
Your administrators provision one integration identity per worker. Each scope its remit needs is a column: a read it holds is a cut above the shoulder, a write it holds is a cut below, lit and limited to the actions in the service description, and a scope your policy reserves is no cut at all: the key does not turn there. Tested outside production and accepted before live execution.
Authority
04

An identity you provision

Workers act through an integration identity your administrators create, with read access to what the remit needs and write access limited to the actions in the service description. Tested outside production and accepted before live execution. Never unrestricted production access.

05

Authority enforced in code

A worker holds exactly the authority you delegate, the way you delegate it to a person in the role today. Approval requirements, thresholds and reserved decisions are rules the platform checks before any write; a learned preference cannot grant a transaction right. Credentials are held outside any prompt and never appear in a worker's context.

06

Evidence, not instructions

Invoices, remittances, emails and portal messages are treated as evidence. Text inside them that reads as an instruction cannot change a worker's permissions, its rules or its next action.

One case's record, append-only, each entry chained to the lastSpecimen: case AP-004437 of the sample week
14:12:03 worker read purchase order 4500018231, receipts 5000091102 567b3dfd39
14:12:09 worker read supplier 100482 master, open items 079d237a49
14:12:40 worker write invoice 5100022719 created and parked · key 7f3a…c1e0 f312c273ee
14:12:58 worker timeout write acknowledged late · status check before any retry 278ca2d168
14:13:01 worker status invoice 5100022719 present · no retry f08e999e16
14:13:22 worker decision requested coding 6410-US01 · evidence: 12 prior invoices dbde278537
16:02:11 owner@client approved coding 6410-US01 dad7f08ab7
16:02:14 worker write invoice 5100022719 released · key 7f3a…c1e0 4fbf293245
16:02:19 worker verified document re-read · state matches intent a01c33e4ef
16:02:20 worker closed case AP-004437 · evidence pack sealed 456c46a876
evidence pack sealed and signed · exportable · yours
Every read, write, approval, intervention and incident is on an append-only log, each entry carrying the digest of the one before, so nothing can be removed or reordered without breaking the chain. Each closed case carries a signed evidence pack. The log is exportable, and your work records are yours if the engagement ends.
The record
07

One environment per client

Your records, procedures and lessons are isolated in your own environment. Nothing is pooled. A lesson learned on your engagement stays on your engagement; general method improvements carry no client data.

08

An append-only record

Every read, write, approval, intervention and incident is on an audit log you can export. Each case carries a signed evidence pack. Your work records are yours if the engagement ends.

09

Data handling and processing location

Model selection, processing location, retention and any third-party service are agreed at deployment and written into the service description. For clients in the European Union and the United Kingdom, in-region processing and self-hosted models are available. Humetry trains no models on client data.

10

Assurance for your security review

A security review precedes any write access. Humetry provides its security policy, the control description for each engagement, the audit-log export, and the insurance and attestation documents a review asks for. Independent attestation of the controls is on the company's launch path and will be stated here on the day it is obtained and nowhere before.

Security policy →

Start a conversation

Tell us where the work sits today, the systems it runs in and the volumes. We come back with a scope, a pilot proposal and a date. We reply from a named person.