IrisKey.ai™ security

Authority before autonomy.

8ORA.AI decides what is best equipped to do a job. IrisKey.ai™ decides whether it is allowed to. Keeping those two decisions in two systems is the point — a selection engine that can also grant itself permission is not a control at all.

Powerful AI needs authority.

Choosing well and being allowed to act are two different questions, and they must not be answered by the same system. 8ORA.AI answers the first. IrisKey.ai™ answers the second.

8ORA.AI

Determines what is best equipped to do the job.

  • Finds and evaluates capabilities
  • Selects per job, not per subscription
  • Assembles and scopes digital workers
  • Orchestrates the work end to end

IrisKey.ai™

Determines whether it is authorised to do it.

  • Identity and verification
  • Authorisation, denial and approval-required
  • Revocation of what was previously permitted
  • Evidence of what was decided and done

Request to evidence

  1. Business request Work the organisation needs done
  2. 8ORA.AI — Select What is best equipped for this job
  3. IrisKey.ai™ — Authorise Whether it may act at all
  4. Digital worker The scoped worker that carries it out
  5. Action The thing actually done
  6. Evidence The record left behind

8ORA.AI builds the toolbox. IrisKey.ai™ controls the key.

Selection is not authorisation. A capability may be the fastest, the most capable and the best suited available — and still not be permitted to touch a given system, dataset or environment. Nothing 8ORA.AI concludes can turn a denial into permission.

The principles this rests on

Rules that do not bend under pressure.

The risk to an AI authority model is rarely an attack. It is the reasonable-sounding change: let the system that scores capabilities also approve them. These principles exist so that change cannot be made quietly.

  • Selection is not authorisation

    That a capability is best equipped for a job says nothing about whether it may act, on what data, in which environment. The two decisions are made by two systems, and only one of them is an authority.

  • Authority before autonomy

    The authority decision comes before the action, not as an audit afterwards. An action that was never permitted is not an incident to be reviewed later — it is an action that does not happen.

  • Denial cannot be argued with

    No confidence score, benchmark result or recommendation from any source can turn a denial into permission. There is no route by which performing well earns wider access.

  • Revocation is a first-class action

    What was granted can be withdrawn — for a worker, a capability, an environment or an integration — without dismantling the rest of the workforce.

  • Evidence is the output, not a by-product

    What was requested, what was selected, what was decided and what was done should be inspectable afterwards by the organisation that owns the work.

  • No provider is trusted by default

    Every capability reaches the business through the same boundary. Swapping one model or provider for another changes who executes and changes nothing about who decides.

This page describes the security model and the boundary between the two systems. It does not describe implementation detail, and no certification or compliance status is claimed here.

Talk to 8ORA.AI

What could an AI workforce do inside your business?

Tell us what your organisation does. We'll look at where digital workers, specialist AI capabilities and organisational intelligence could create measurable value.

Protected by IrisKey.ai™ — Authority before autonomy.