Open governance framework · v1.3 · Practitioner-led · not an accredited standard, certification, or regulatory requirement · seeking shadow-evaluation partners
Home/Platform/Enterprise Workflow

TrustLayer · Module 05

Enterprise Workflow

Governance that lives outside your identity, access, and monitoring stack is governance nobody follows.

The operational surface

Agent governance fails in practice for unglamorous reasons: a separate login nobody has, an approval that happens in a chat thread, an alert that never reaches the security team. This module is about removing those failure modes.

SSO

Single sign-on

Federated authentication through your existing identity provider. No standalone credential set to provision, rotate, or forget to deprovision.

RBAC

Role-based access control

Distinct roles for registering an agent, approving scope, reviewing a failed control, and reading evidence. Registering is not approving.

APPROVALS

Approval workflows

Scope grants, renewals, and exceptions move through a recorded approval path with a named approver and a timestamp — not an email thread.

INTEGRATIONS

Integrations

Connections into the voice platforms, ticketing, and GRC tooling your teams already operate, so findings land where work happens.

SIEM

SIEM export

Control decisions and audit events stream into your security monitoring stack as first-class events, correlatable with everything else.

POSTURE

Revocation & posture

Revoke an agent’s authority immediately across the registry and the gateway, with the revocation itself recorded as evidence.

Separation of duties

The person who deploys an agent should not be the only person who can widen its scope. RBAC and approval workflows exist so that delegated authority has a reviewable provenance: who requested it, who approved it, against what business justification, and when it expires.

That provenance is what an auditor is actually asking for when they ask how an agent got its permissions — and it is the part that is hardest to reconstruct afterwards if it was never captured.

Escalation has to reach a person

EIT-01 in the open framework requires that a caller’s request for a human be honored. The operational equivalent inside the platform is that a failing control reaches a named reviewer with the authority to act — not a dashboard nobody has open. Escalation paths, review queues, and ownership are configured per agent and recorded alongside the finding.

Development status: TrustLayer is being built with design partners and is not yet generally available. Capabilities on this page describe the intended enterprise surface, not shipped features.

Related

What the enterprise surface governs.

TrustLayer by NHID-Clinical is in active development. It is not an accredited standard, a certification, or a regulatory compliance guarantee. The open framework it enforces remains free under CC BY 4.0 and is never gated behind a plan.