Security and governance

Control what AI can do. Review what it did.

Give each team access to the information and tools its work needs. Keep professional judgement in the workflow, with records that help you understand what happened.

Discuss security options
Data and deployment

Choose where the work runs.

A managed workspace or a dedicated setup: start with the information you handle and the environment your organisation needs.

Counso Cloud

Environment
A workspace managed by Counso.
Setup
Choose the team, sources and access for a first workflow.
AI models
Administrators select the models available in the workspace.

Private deployment

Environment
Your organisation's own cloud environment.
Setup
Plan hosting, network access and operations with your team.
AI models
Model options are agreed around the environment and data requirements.

When an agent uses an external AI model, relevant text is sent to that provider to produce a response. Hosting location and provider data terms are part of your deployment review.

Access

Decide who can use what.

Set access around the people, clients and work involved.

Roles and groups

Use Admin, Manager and Member roles. Assign permissions to groups so access follows the team.

Company sign-in

Use your existing identity provider with SAML. Sync people and groups with SCIM where configured.

Restricted spaces

Limit sensitive knowledge to the people who need it. Agents work within the access of the person using them.

Model access

Administrators choose which AI models are available to the team.

Connected tools

Select the tools each agent needs and review the permissions granted to each connection.

External sharing

Administrators decide whether Mini Apps can be shared outside the organisation.

Agent actions

Check the action before it happens.

For work that changes client records or sends information outside the firm, agree who reviews the proposed action and what they must check.

An agent proposes updating a client record.

01

A proposed action

Which record will change? What information will be sent?

The responsible person, connected tool and access scope are shown.

02

Person, tool and scope

Who is responsible? Is this the right tool and the right access?

A person can proceed, revise or stop a proposed change.

03

A person's decision

Review the effect before proceeding.

Records and audit

Keep a record you can review.

When Audit Logs are enabled for the workspace, authorised users can review significant activity in time order.

What happened

  • Agent runs, changes and tool calls
  • Scheduled tasks and triggers
  • Members, roles and space permissions
  • Connections, sign-ins and conversation access

Who was responsible

Agent and tool events identify whether a person or AI started the action, and on whose behalf. Access to the audit log is also recorded.

Filter by time, person and action. Export records as CSV or stream them to your own monitoring system where configured.

Runtime safeguards

Review actions at the moment they matter.

Our approach is informed by SAFR's focus on authorisation, human oversight and records at the point an AI agent acts. We can map the controls available in your workspace to your own review requirements.

SAFR is an industry white paper published under MAS's BuildFin.ai initiative. It is not regulatory guidance. Counso is not affiliated with or endorsed by MAS.

Documents for review

Documents for your security review.

Request a data processing agreement, or send us your security questionnaire and logging requirements. We will provide information relevant to your proposed deployment.

Discuss security options