The eight commitments
01
Your data does not train Grok, Claude or OpenAI.
Your data does not train models. Customer Content is excluded from training, fine-tuning and model improvement at xAI, Anthropic and OpenAI under their commercial API terms. That obligation is flowed into our DPA.
02
Production traffic uses enterprise APIs with Zero Data Retention — not consumer chat apps.
Production traffic uses enterprise APIs, not consumer chat. Nothing goes through grok.com, Claude.ai, Claude for Work UI, or ChatGPT consumer accounts. Those products are out of scope.
Zero Data Retention at the model layer. Eligible Grok, Claude and OpenAI API endpoints run with ZDR so prompts and completions are not kept by the vendor after inference. The system of record for evidence is your audit store.
03
You choose the allowed models. The router fail-closes if a vendor is off the list.
You choose the models and you can stop them. Grok only, Claude only, both, or OpenAI as a third option.
The client’s AI policy names the approved vendors. The router obeys that list.
04
Nothing posts without a named human approval.
The agent prepares. A named human approves. NetSuite posts only after that approval. The same identity cannot draft and approve the same transaction. L2 is the approved payload only.
The agent prepares. A named human approves. NetSuite posts only after that approval. Journals, invoices, vendor bills and master-data changes are drafted by the agent. A named human clicks Approve, and NetSuite posts only that approved entry. The same identity cannot draft and approve the same transaction.
05
NetSuite access is a custom least-privilege MCP role. Oracle already blocks Administrator from the Connector.
A custom least-privilege role. Administrator cannot use the connector. Oracle already blocks that. Write tools refuse unless they carry an approval token issued by our control plane. Oracle’s official AI Connector Service. Model Context Protocol. OAuth 2.0. User-delegated.
NetSuite permissions stay yours. The connector uses a custom MCP role. Oracle blocks Administrator and full-access roles from the AI Connector. Tools cannot run elevated scripts or call the public internet.
06
Email, Slack, SharePoint and Drive use delegated OAuth and allow-lists — not tenant-wide admin tokens.
Microsoft 365 and Google Workspace through their APIs, with user-delegated OAuth. Slack limited to allow-listed channels. Mailbox, site and channel allow-lists. Tenant-wide application permissions are not the default. PII, bank details and national IDs are redacted before any model call.
Least privilege on every other system. Email, Slack, SharePoint and Drive use user-delegated OAuth with mailbox, site and channel allow-lists. Tenant-wide application permissions are not the default.
07
Every material action writes an exportable audit record.
An immutable audit log you can export to Internal Audit or your SIEM. The audit pack stores the source, the model version, the approver and the NetSuite internal ID.
Every material action is reconstructable. Source document IDs, model and version, tool calls, proposed payload, approver, timestamp and NetSuite internal ID are written to an immutable log you can export to Internal Audit or your external auditor.
08
One kill-switch disables a model or freezes all writes.
You choose the models and you can stop them. Grok only, Claude only, both, or OpenAI as a third option. A kill-switch disables a vendor or all write actions without waiting on us.