Operate · Trust boundaries
Privacy and security by design
Agent surveillance should be transparent, limited, and accountable. Phigon makes authorization, collection scope, evidence quality, and access boundaries part of the operating model—not an afterthought.
Consent before collection
The machine owner sees the requested scope and explicitly accepts it. Starting a pairing flow is only a request; it is never treated as consent.
If consent is declined or revoked, Phigon does not provide a hidden path around that decision.
Metadata first
The default profile is designed to avoid the contents of prompts, responses, reasoning, terminal output, files, browser pages, and environment values.
Start with the smallest useful scope. Broader collection should be exceptional, understandable, and approved for a specific purpose.
Redaction before transport
Local policy can further restrict what the server requests. Disallowed categories are removed on the supervised machine before transmission—not merely hidden later in the dashboard.
Independent evidence
Agent-native, OS-native, and gateway claims remain separate. If sources conflict or expected coverage disappears, that limitation can override positive attribution.
This is both a security and privacy property: the system should not make stronger claims merely because stronger claims are convenient.
Authenticated workspace access
Production workspaces require organization-backed access. Private routes fail closed when required authentication is unavailable.
Tenant isolation
Machine, credential, audit, consent, telemetry, and deletion operations are scoped to an authoritative tenant identity.
Revocation and deletion
Authorized operators can revoke consent and credentials, remove a machine, and follow scheduled deletion state. Removing access and removing retained data are related, but distinct, operations.
A practical trust checklist
- Every supervised machine has an authorized owner.
- The owner understands and accepts the current scope.
- Collection begins metadata-first.
- Local redaction remains enabled.
- Workspace access is limited to approved operators.
- Conflicts and missing evidence remain visible.
- Revocation and deletion processes are understood.