Watch the Opal launch video
Governance and Security

Built for the organizations that can't afford to get it wrong.

Opal gives enterprise teams the controls, visibility, and enforcement they need to deploy AI confidently — with role-based access, version-controlled resources, AI-specific safety enforcement, and a full audit trail baked into the platform from day one.

Control layer · enforcedalways on
Access and identity
rbac · sso · teams
active
AI safety enforcement
input · output guardrails
active
Resource governance
versions · activity log
active
Data protection
zdr · secure variables
active
every change on the record
The enterprise AI challenge

Deploying AI at scale creates new governance demands.

The controls that worked for traditional software do not fully cover systems that reason, respond, and act on unstructured content.

Enterprise AI needs access, enforcement, and evidence — by default.

01

Access at scale is hard to control

As teams deploy more agents and workflows, managing who can access what — and making sure access stays appropriate as roles change — requires structure, not trust.

02

AI introduces new safety risks

Unlike traditional software, AI systems can receive and return unexpected content. Sensitive data in responses, policy violations in outputs, and prompt injection attempts are real risks without specific enforcement controls.

03

Change without accountability is liability

When configurations, resources, and agent behaviors change without a record, it is impossible to understand what happened, why, or how to reverse it. Auditability is not optional.

04

Compliance demands proof

Certifications, data residency requirements, and regulatory obligations require documented controls — not assurances. Enterprise buyers need verifiable evidence, not marketing claims.

The Opal approach

Layered controls built into everything.

Opal's governance and security posture is not a set of add-on features — it is embedded in the structure of the platform. Every resource has permissions. Every change has a version. Every interaction has a record.

  1. 01

    Access and identity

    Role-based access control, Single Sign-On (SSO), and team-based organization ensure that the right people access the right resources — and that access can be managed, audited, and updated as teams evolve.

  2. 02

    AI safety enforcement

    Guardrails enforce input and output policies at the agent level — blocking, rewriting, or logging content that violates policy before it reaches users or leaves the platform.

  3. 03

    Resource governance

    Version control, publishing workflows, and activity logging give organizations a documented record of every resource and every change — at any scale.

  4. 04

    Data protection

    Zero data retention eliminates storage of prompts and responses on model provider infrastructure when supported models are used. Your data stays yours.

One interaction · every controlenforced
  1. member requestidentity verified
  2. input guardrailpolicy checked
  3. agent executionpermissions applied
  4. output guardrailresponse screened
  5. activity logevent recorded
Access and identity controls

The right access for every role.

01

Role-Based Access Control

Permissions govern access to every resource in Opal — Agents, Flows, Tasks, Knowledge files, Guardrails, Skills, Connectors, Variables, and more. Access is set at the resource level, so administrators control who can view, edit, use, and manage each asset individually.

02

Single Sign-On (SSO)

Integrate Opal with your existing identity provider. SSO simplifies access management, enforces your organization's authentication policies, and reduces credential overhead for large teams.

03

Teams

Organize members into teams that reflect your organizational structure. Use teams to manage access at group scale — assign permissions to a team rather than managing each individual member.

04

Organization-level controls

Administrators manage model availability, platform configuration, and org-wide defaults from a central administration layer — keeping the platform aligned with internal standards.

AI safety enforcement

Every agent. Every interaction. Enforced.

Guardrails apply input and output policies to every agent interaction. They run automatically — before content reaches the agent and before responses reach users — with no gaps based on volume or timing.

Input Guardrails

Block or handle content that should not reach an agent. Protect against prompt injection attacks, flag harmful inputs, and prevent unauthorized data from entering agent workflows.

Output Guardrails

Prevent sensitive information from appearing in agent responses. Automatically detect and handle PII, confidential data, and policy-violating content before it is delivered.

Three detection methods

Keyword matching

Fast, deterministic detection for known terms, phrases, and patterns.

Semantic classification

AI-powered detection that identifies problematic content by meaning — not just exact phrases — handling paraphrasing and novel phrasing.

Regex patterns

Structured pattern matching for specific formats like account numbers, document identifiers, and structured data types.

Four handling approaches

Block

Prevent the content from proceeding. The interaction stops.

Rewrite

Automatically modify the content to remove or redact the flagged portion.

Log

Record the event for audit and review without interrupting the interaction.

Warn

Alert the user that flagged content was detected while allowing the interaction to continue.

Reusable across your workforce

Create a Guardrail once and attach it to any number of agents. Update it in one place and the change applies everywhere it is used — no per-agent maintenance.

Platform-wide governance

Every resource. Every change. On the record.

01

Role-Based Access Control

Every resource on Opal is permissioned, including Agents, Flows, Tasks, Knowledge, Skills, Guardrails, Connectors, and Variables. Roles determine who can view, edit, publish, and administer, so the right people reach the right resources.

02

Single Sign-On

SSO integrates authentication at the organization level, so access follows your existing identity provider and offboarding happens in one place.

03

Guardrails

Guardrails apply to Agents and Agent Templates, enforcing input and output policy on every interaction by blocking, rewriting, warning, or logging before content reaches users or leaves the platform.

04

Version control

Every resource on Opal is versioned. Changes are tracked across a clear history so teams can understand what changed, when it changed, and by whom.

05

Draft and publishing workflow

Resources are edited in draft. Changes are reviewed and approved before they go live. Published versions remain stable and available while drafts are in progress, so teams can develop and test without disrupting active work.

06

Activity Log

A comprehensive log records all activity across the organization, including resource creation, edits, configuration changes, access events, and agent interactions. The Activity Log provides the documented audit trail compliance and security teams require.

07

Linked resources

Every resource on Opal tracks its dependencies. Before changing an agent, a model, a guardrail, or a knowledge file, teams can see what depends on it, preventing unintended downstream impact and making change management informed.

08

Resource tags

Apply custom tags to resources for organization, discoverability, and cross-resource management at scale.

09

Variables

API keys, tokens, and configuration values are stored as named, permissioned secrets. Sensitive values are referenced by name and never exposed in the interface after saving.

10

Zero data retention

For supported models and providers, zero data retention is applied automatically, so prompts and responses are not stored on model provider infrastructure. No additional configuration is required.

Data privacy and protection

Your data, handled appropriately.

Zero data retention

When you use a model and provider that supports zero data retention, Opal enables it automatically. Prompts and responses are not stored on model provider infrastructure for eligible models. No additional configuration is required.

Secure credential management

Variables allow teams to store API keys, tokens, and configuration values as named, permissioned secrets. Sensitive values are never exposed in the interface after saving — they are referenced by name and used in configuration without being visible.

Per-user authorization

Connectors can be configured with per-user authorization, ensuring that each team member's credentials are used for their own interactions — not a shared service account.

Certifications and compliance

Accountability you can document.

Opal is designed to meet the requirements of enterprise compliance frameworks.

01

ISO 27001

Information security management. ISO 27001 certification is underway.

02

ISO 42001

AI management system. ISO 42001 certification is underway.

03

SOC 2 Type II

Security, availability, and confidentiality. SOC 2 Type II certification is underway.

ISO 27001, ISO 42001, and SOC 2 Type II certifications are underway.

Who relies on governance and security

The teams accountable for getting it right.

01

IT and Security Teams

Deploy Opal knowing every agent interaction is governed, every credential is managed, and every change is logged. Use RBAC, SSO, and the Activity Log to maintain visibility and control.

02

Governance and Compliance Teams

Enforce AI policy through Guardrails, document compliance posture through the Activity Log, and demonstrate controls through version-tracked resources. Governance is not bolted on — it is built in.

03

Organization Administrators

Manage access, configure org-level settings, control model availability, and maintain oversight of everything running in the platform from a central administrative layer.

04

Enterprise Buyers and Procurement

Evaluate Opal against your security requirements with confidence. RBAC, ZDR, SSO, Guardrails, and in-progress certifications address the controls enterprise procurement teams require.

See it in practice

Governance working in the background.

Controls that do their job without slowing the work down.

Case 01
Financial Services

Customer-facing agent deployment

A financial services organization deploys a customer-facing agent to assist with account inquiries. Guardrails with semantic classification and regex patterns prevent account numbers and PII from appearing in agent responses. The Activity Log records every interaction for audit purposes. ZDR is enabled automatically because the selected model supports it.

Enforcement
Semantic + regex guardrails
Evidence
Activity Log on every interaction
Outcome
Security team approval
Case 02
Compliance

Policy update without disruption

A compliance team updates the organization's approved response language for a regulatory change. Using the publishing workflow, they edit the relevant Guardrails and Knowledge resources in draft, review the changes with the legal team, and publish — all without interrupting the agents already running in production. The Activity Log records the review, approval, and publish events.

Workflow
Draft, review, publish
Scope
Guardrails and Knowledge
Outcome
No production interruption
Case 03
IT Administration

Access management at scale

An IT administrator onboards a new team of forty agents across three departments. Using teams, she assigns resource-level access at the group level rather than managing each member individually. SSO ensures every new member authenticates through the organization's existing identity provider. When a team member leaves, access is revoked in one place.

Model
Team-level permissions
Identity
SSO through existing IdP
Outcome
One-place offboarding
Governance and Security

Ready to deploy AI your security team will approve?