Answers for the person
who signs the risk assessment.
Identity, access, residency, auditability and agent behaviour — written plainly, because a security review should not require a discovery call.

Photo · Security team, operations centre
Six things reviewers
always ask.
Identity
Your own tenant at [org].karos.cloud, set once and locked. SSO, passwordless or password, plus email OTP and an authenticator code.
Access control
A Capability × Role matrix is the source of truth. Owner ⊃ Super Admin ⊃ Admin ⊃ Member ⊃ Viewer, enforced identically in UI and API.
Data residency
Built and hosted in Canada by a Calgary team. Your data does not leave the region to be processed.
Auditability
Every create, edit, transfer and approval logged with actor, timestamp and portal. Agent actions are logged as the user who asked.
Agent behaviour
The agent inherits the requester's permissions, drafts rather than submits, and is write-blocked on certificates, objectives and hiring.
Cost control
AI credits capped per organisation and per employee per day, so an agent cannot generate unbounded spend.
The matrix, not a
marketing summary of it.
An abridged view of the org-scope permission matrix. The full capability list is shared under NDA during the review. Karos AI resolves through this same matrix.
| Capability | Owner | Super Admin | Admin | Member | Viewer |
|---|---|---|---|---|---|
| Complete org setup | ✓ | – | – | – | – |
| Billing & subscription | ✓ | – | – | – | – |
| Transfer ownership | ✓ | – | – | – | – |
| Delete or close org | ✓ | – | – | – | – |
| Manage system config | ✓ | ✓ | – | – | – |
| Manage AI credits | ✓ | ✓ | – | – | – |
| Invite & manage people | ✓ | ✓ | ✓ | – | – |
| Manage groups | ✓ | ✓ | ✓ | – | – |
| Publish announcements | ✓ | ✓ | ✓ | – | – |
| Create & edit portal records | ✓ | ✓ | ✓ | ✓ | – |
| Use Karos AI | ✓ | ✓ | ✓ | ✓ | – |
| Read permitted records | ✓ | ✓ | ✓ | ✓ | ✓ |
Questions we get
from security teams.
Do you train models on our data?
No. Your content answers your questions. It is not used to train shared models.
Which model do you use?
Model selection is engine-agnostic and confidential. Organisations see credits, never provider or raw cost.
Can we restrict which portals the agent reaches?
Yes. Restricting a portal for a role restricts it for the agent acting as that role.
What happens when someone leaves?
Access is revoked at role level, the record retained for audit. Ownership transfer is a separate owner-only action.
Do you support SSO?
Yes — SSO, passwordless and password, set at the organisation level.
Where do we send a questionnaire?
[email protected]. We complete standard questionnaires during cohort onboarding.
See it running on
your own data shapes.
Thirty minutes in a working environment configured for your sector. Live in under a day.