September 2026 Close
Synthetic Demo
Security

Security & Compliance

How an agent-operated journal process would be secured, and an honest statement of what is demonstrated here versus what Rogers would need to implement.

Controls in register
44
Illustrative demo metric
Implemented in demo
7
Illustrative demo metric
Simulated
12
Illustrative demo metric
Requires Rogers validation
9
Illustrative demo metric
Requires production implementation
7
Illustrative demo metric
Security control register
Select a control to see its threat, test, evidence and Rogers dependency.
IDDomainObjectiveNatureAutomationMicrosoft serviceOwnerStatus
SEC-001IdentityUnique human identity for every userDetectiveAutomatedEntra ID, Conditional Access, PIMMarcus Hill
Simulated
SEC-002IdentityUnique workload identity for every agentCorrectiveManualEntra ID, Conditional Access, PIMMarcus Hill
Requires Rogers validation
SEC-003IdentityMulti-factor authentication for all interactive accessPreventiveAutomatedEntra ID, Conditional Access, PIMMarcus Hill
Implemented in demo
SEC-004IdentityReauthentication for sensitive finance actionsDetectiveAutomatedEntra ID, Conditional Access, PIMMarcus Hill
Proposed for proof of value
SEC-005AccessLeast privilege role assignmentPreventiveAutomatedEntra ID, Conditional Access, PIMMarcus Hill
Simulated
SEC-006AccessPeriodic access reviewCorrectiveManualEntra ID, Conditional Access, PIMMarcus Hill
Requires Rogers validation
SEC-007AccessJust-in-time privileged elevationCorrectiveManualEntra ID, Conditional Access, PIMMarcus Hill
Requires Rogers validation
SEC-008AccessSeparation of admin and business identitiesDetectiveAutomatedEntra ID, Conditional Access, PIMMarcus Hill
Proposed for proof of value
SEC-009DataSensitivity labelling of finance artefactsDetectiveManualMicrosoft PurviewMarcus Hill
Proposed for proof of value
SEC-010DataData loss prevention on restricted exportsDetectiveAutomatedMicrosoft PurviewMarcus Hill
Simulated
SEC-011DataEncryption in transit and at restPreventiveAutomatedMicrosoft PurviewMarcus Hill
Simulated
SEC-012DataKey management in a dedicated vaultPreventiveAutomatedMicrosoft PurviewMarcus Hill
Simulated
SEC-013PrivacyPurpose limitation for agent processingPreventiveAutomatedMicrosoft PurviewSamantha Roy
Simulated
SEC-014PrivacyData minimization in promptsPreventiveAutomatedMicrosoft PurviewSamantha Roy
Implemented in demo
SEC-015PrivacyRetention limitation for audit evidenceDetectiveManualMicrosoft PurviewSamantha Roy
Proposed for proof of value
SEC-016AgentAgent registry and ownershipPreventiveAutomatedAgent 365, Microsoft FoundryAlex Morgan
Simulated
SEC-017AgentTool allow-listingPreventiveAutomatedAgent 365, Microsoft FoundryAlex Morgan
Implemented in demo
SEC-018AgentDelegation and autonomy limitsCorrectiveManualAgent 365, Microsoft FoundryAlex Morgan
Requires Rogers validation
SEC-019AgentEmergency agent disablePreventiveAutomatedAgent 365, Microsoft FoundryAlex Morgan
Simulated
SEC-020ApplicationInput validation on all user-supplied valuesCorrectiveManualGitHub Advanced Security, DefenderMarcus Hill
Requires production implementation
SEC-021ApplicationOutput encodingCorrectiveManualGitHub Advanced Security, DefenderMarcus Hill
Requires Rogers validation
SEC-022ApplicationSession protectionCorrectiveManualGitHub Advanced Security, DefenderMarcus Hill
Requires Rogers validation
SEC-023NetworkPrivate endpoints for platform servicesCorrectiveManualAPI Management, Private Link, Key VaultMarcus Hill
Requires production implementation
SEC-024NetworkControlled egressCorrectiveManualAPI Management, Private Link, Key VaultMarcus Hill
Requires Rogers validation
SEC-025NetworkWeb application firewallCorrectiveManualAPI Management, Private Link, Key VaultMarcus Hill
Requires production implementation
SEC-026IntegrationSchema validation on ERP payloadsCorrectiveManualAPI Management, Private Link, Key VaultMarcus Hill
Requires Rogers validation
SEC-027IntegrationIdempotency and replay protectionDetectiveAutomatedAPI Management, Private Link, Key VaultMarcus Hill
Proposed for proof of value
SEC-028IntegrationCredential rotation for integration identitiesDetectiveAutomatedAPI Management, Private Link, Key VaultMarcus Hill
Proposed for proof of value
SEC-029LoggingComplete logging of material actionsDetectiveAutomatedAzure Monitor, Sentinel, Purview AuditJordan Lee
Simulated
SEC-030LoggingTamper-evident audit designDetectiveAutomatedAzure Monitor, Sentinel, Purview AuditJordan Lee
Proposed for proof of value
SEC-031LoggingCentralized log retentionPreventiveAutomatedAzure Monitor, Sentinel, Purview AuditJordan Lee
Implemented in demo
SEC-032ResilienceFail-closed behaviour on dependency lossDetectiveManualGitHub Advanced Security, DefenderMarcus Hill
Proposed for proof of value
SEC-033ResilienceManual continuity procedureCorrectiveManualGitHub Advanced Security, DefenderMarcus Hill
Requires production implementation
SEC-034ResilienceRecovery objectives definedPreventiveAutomatedGitHub Advanced Security, DefenderMarcus Hill
Implemented in demo
SEC-035Secure developmentStatic analysis gateCorrectiveManualGitHub Advanced Security, DefenderMarcus Hill
Requires production implementation
SEC-036Secure developmentDependency and secret scanningPreventiveAutomatedGitHub Advanced Security, DefenderMarcus Hill
Simulated
SEC-037Secure developmentRelease approval gatePreventiveAutomatedGitHub Advanced Security, DefenderMarcus Hill
Simulated
SEC-038Responsible AIGroundedness evaluationDetectiveManualAgent 365, Microsoft FoundryAlex Morgan
Requires Rogers validation
SEC-039Responsible AIPrompt-injection red teamingPreventiveAutomatedAgent 365, Microsoft FoundryAlex Morgan
Implemented in demo
SEC-040Responsible AIHuman oversight of material decisionsCorrectiveManualAgent 365, Microsoft FoundryAlex Morgan
Requires production implementation
SEC-041RecordsRecords classification of journalsPreventiveAutomatedMicrosoft PurviewSamantha Roy
Implemented in demo
SEC-042RecordsLegal hold capabilityCorrectiveManualMicrosoft PurviewSamantha Roy
Requires production implementation
SEC-043Incident responseSecurity incident playbookDetectiveAutomatedAzure Monitor, Sentinel, Purview AuditJordan Lee
Proposed for proof of value
SEC-044Incident responseAgent suspension procedurePreventiveAutomatedAzure Monitor, Sentinel, Purview AuditJordan Lee
Simulated
Security statements describe design intent in a prototype. Rogers security, privacy and audit validation is required before any production use.

This prototype uses synthetic journal data, synthetic validation rules and simulated Oracle responses. It is not connected to Rogers, Oracle, UiPath or Microsoft production services.

Not production ready · Conceptual Microsoft architecture · Exact Rogers and Oracle requirements require confirmation · Risk scoring does not replace professional accounting judgment · Not a certification.