The operational surface
Agent governance fails in practice for unglamorous reasons: a separate login nobody has, an approval that happens in a chat thread, an alert that never reaches the security team. This module is about removing those failure modes.
Single sign-on
Federated authentication through your existing identity provider. No standalone credential set to provision, rotate, or forget to deprovision.
Role-based access control
Distinct roles for registering an agent, approving scope, reviewing a failed control, and reading evidence. Registering is not approving.
Approval workflows
Scope grants, renewals, and exceptions move through a recorded approval path with a named approver and a timestamp — not an email thread.
Integrations
Connections into the voice platforms, ticketing, and GRC tooling your teams already operate, so findings land where work happens.
SIEM export
Control decisions and audit events stream into your security monitoring stack as first-class events, correlatable with everything else.
Revocation & posture
Revoke an agent’s authority immediately across the registry and the gateway, with the revocation itself recorded as evidence.
Separation of duties
The person who deploys an agent should not be the only person who can widen its scope. RBAC and approval workflows exist so that delegated authority has a reviewable provenance: who requested it, who approved it, against what business justification, and when it expires.
That provenance is what an auditor is actually asking for when they ask how an agent got its permissions — and it is the part that is hardest to reconstruct afterwards if it was never captured.
Escalation has to reach a person
EIT-01 in the open framework requires that a caller’s request for a human be honored. The operational equivalent inside the platform is that a failing control reaches a named reviewer with the authority to act — not a dashboard nobody has open. Escalation paths, review queues, and ownership are configured per agent and recorded alongside the finding.
Related
What the enterprise surface governs.
TrustLayer by NHID-Clinical is in active development. It is not an accredited standard, a certification, or a regulatory compliance guarantee. The open framework it enforces remains free under CC BY 4.0 and is never gated behind a plan.