AI agent security / Public sector

Keep public-service AI
accountable.

Use AI to prepare case files, compare submissions and support service teams. Set limits on record access and official actions, with evidence of what the agent was allowed to do.

Every case has an owner. Every action needs authority.
Across agencies and local services

Preparation and authority are different jobs.

An assistant can help move a case forward without receiving every permission held by the person responsible for it.

Citizen services & casework

Retrieve the documents assigned to a case and draft a response for the service team.

Keep separateAccess to other residents’ records, changes to eligibility and the release of an official decision.

Procurement & supplier review

Compare submitted material and prepare an evidence pack for procurement staff.

Keep separateSupplier master-data changes, scoring updates, payment details and award authorization.

Records & information requests

Find candidate documents in an approved collection and prepare material for review.

Keep separateAccess to restricted collections, final redaction decisions and publication to external channels.

Illustrative procurement scenario

A supplier submission cannot grant approval.

An agent is comparing supplier proposals. One attachment instructs it to update the supplier’s bank details through a connected administrative tool.

Connect permissions to ownership
Task / compare proposals
  1. 01

    Read the submission.

    The document is evidence for the comparison. Its embedded instructions carry no administrative authority.

  2. 02

    Check the requested tool.

    The agent’s allowlist permits proposal retrieval. It excludes the supplier bank-details update tool.

  3. 03

    Reject the update.

    At the configured gateway, the disallowed tool call is rejected and recorded. Procurement staff retain the change process.

Comparison access does not include payment authority.

This is an assessment scenario, not a reported incident. Enforcement requires the administrative request to pass through the configured control.

Define who may do what

Make the handoff to an official explicit.

Translate the agency’s process into tool permissions and review responsibilities. A prompt is not an authorization policy.

The agent

Prepares within scope.

Reads approved sources and uses the tools assigned to its role. Attempts to cross that scope are evaluated at the enforcement point.

The process owner

Retains decision authority.

Defines which changes need a person, who may approve them and where the official approval is recorded.

The security team

Maintains the controls.

Configures identity and tool restrictions, investigates rejected requests and reviews changes to the connected systems.

A reviewable decision record

Who acted. What was requested. What happened.

Connect the acting identity, policy decision and triggered rules. With the node key configured, verify the signed audit chain independently of Oktsec Cloud.

See how evidence is verified
Request context
Keep enough context to trace the evaluated action back to the agency workflow.
Evidence ownership
Assign access, retention and export rules before collecting sensitive case content.
Integrity and accountability
An intact record helps investigation. It does not replace the agency’s substantive decision review.
AI security assessment for government workflows

Start with one service and a named owner.

Define the records, roles, administrative tools and environment in scope. Agree test data and operating limits before exercising the workflow.

Test the authority boundary
Exercise cross-case access, supplier-document injection, disallowed administrative tools and transfers to unapproved recipients.
Review the deployment path
Identify where requests are intercepted, which credentials are used and whether direct API paths bypass the control.
Prepare a usable finding record
Capture reproducible actions, affected permissions and remediation priorities. Assign an owner and agree the retest scope.
Before you connect an agent

Public-sector deployment questions.

Which public-sector workflows are a useful starting point?

Start with a defined service: preparing a case file, comparing supplier submissions or drafting a response from an approved records collection. Identify who owns the process and distinguish preparation from the authority to submit, publish or change an official record.

Can a prompt grant an agent new authority?

A document or prompt should not change the permissions assigned to the agent. Configure permitted tools, parameter constraints and backend access independently of model instructions. Test whether an injected instruction can reach a privileged tool or an unintended destination.

Can the controls run inside an agency environment?

The enforcement component can run locally at a supported integration point. Review model-provider traffic, management connections and evidence exports separately. Local enforcement alone does not establish data residency or approval for a particular government environment. See Deployment for current options and requirements.

What does the audit record prove?

It records the request evaluated at the enforcement point, the acting identity, triggered rules and the decision. With the node key configured, the signed hash chain can be verified for integrity. It does not prove that a procurement decision was fair or that the source documents were correct.

From an agency process to a testable scope

Where does preparation become an official action?

Bring one workflow. We’ll help identify the tools and permissions to assess.

Discuss a public-sector assessment