Docs

Trust and Control

How human access, agent identity, signed workloads, secrets, proposals, and managed execution stay distinct.

GAEZLA can read operational data and run controlled work, so human access, machine identity, AI assistance, secrets, and execution use separate controls.

Controls an operator can inspect

  • configured human authentication and role checks for dashboard access
  • per-agent credentials rather than one shared fleet credential
  • workload signature verification before supported endpoint execution
  • encrypted platform storage for sensitive values held by the platform
  • optional external secret connections for supported runtime resolution
  • execution history with target scope, state, timing, logs, and result metadata
  • read-only investigation tools separated from external mutation
  • durable investigation proposals with current evidence, risk, safeguards, rollback, approval, and policy-required step-up

The control follows the type of work

Investigation tools are read-only. A change proposed from an investigation requires evidence, scope, safeguards, rollback, approval, and any policy-required step-up. Managed playbooks, schedules, and routines follow their configured execution controls and retain their own execution history.

Operators choose connection permissions, enroll agents, establish signing trust, select secret sources, define target scope, and set approval policy. GAEZLA keeps those decisions visible alongside the work and the returned output.