Security
Security & Compliance
How an agent-operated journal process would be secured, and an honest statement of what is demonstrated here versus what Rogers would need to implement.
Controls in register
44
Illustrative demo metric
Implemented in demo
7
Illustrative demo metric
Simulated
12
Illustrative demo metric
Requires Rogers validation
9
Illustrative demo metric
Requires production implementation
7
Illustrative demo metric
Security control register
Select a control to see its threat, test, evidence and Rogers dependency.
| ID | Domain | Objective | Nature | Automation | Microsoft service | Owner | Status |
|---|---|---|---|---|---|---|---|
| SEC-001 | Identity | Unique human identity for every user | Detective | Automated | Entra ID, Conditional Access, PIM | Marcus Hill | Simulated |
| SEC-002 | Identity | Unique workload identity for every agent | Corrective | Manual | Entra ID, Conditional Access, PIM | Marcus Hill | Requires Rogers validation |
| SEC-003 | Identity | Multi-factor authentication for all interactive access | Preventive | Automated | Entra ID, Conditional Access, PIM | Marcus Hill | Implemented in demo |
| SEC-004 | Identity | Reauthentication for sensitive finance actions | Detective | Automated | Entra ID, Conditional Access, PIM | Marcus Hill | Proposed for proof of value |
| SEC-005 | Access | Least privilege role assignment | Preventive | Automated | Entra ID, Conditional Access, PIM | Marcus Hill | Simulated |
| SEC-006 | Access | Periodic access review | Corrective | Manual | Entra ID, Conditional Access, PIM | Marcus Hill | Requires Rogers validation |
| SEC-007 | Access | Just-in-time privileged elevation | Corrective | Manual | Entra ID, Conditional Access, PIM | Marcus Hill | Requires Rogers validation |
| SEC-008 | Access | Separation of admin and business identities | Detective | Automated | Entra ID, Conditional Access, PIM | Marcus Hill | Proposed for proof of value |
| SEC-009 | Data | Sensitivity labelling of finance artefacts | Detective | Manual | Microsoft Purview | Marcus Hill | Proposed for proof of value |
| SEC-010 | Data | Data loss prevention on restricted exports | Detective | Automated | Microsoft Purview | Marcus Hill | Simulated |
| SEC-011 | Data | Encryption in transit and at rest | Preventive | Automated | Microsoft Purview | Marcus Hill | Simulated |
| SEC-012 | Data | Key management in a dedicated vault | Preventive | Automated | Microsoft Purview | Marcus Hill | Simulated |
| SEC-013 | Privacy | Purpose limitation for agent processing | Preventive | Automated | Microsoft Purview | Samantha Roy | Simulated |
| SEC-014 | Privacy | Data minimization in prompts | Preventive | Automated | Microsoft Purview | Samantha Roy | Implemented in demo |
| SEC-015 | Privacy | Retention limitation for audit evidence | Detective | Manual | Microsoft Purview | Samantha Roy | Proposed for proof of value |
| SEC-016 | Agent | Agent registry and ownership | Preventive | Automated | Agent 365, Microsoft Foundry | Alex Morgan | Simulated |
| SEC-017 | Agent | Tool allow-listing | Preventive | Automated | Agent 365, Microsoft Foundry | Alex Morgan | Implemented in demo |
| SEC-018 | Agent | Delegation and autonomy limits | Corrective | Manual | Agent 365, Microsoft Foundry | Alex Morgan | Requires Rogers validation |
| SEC-019 | Agent | Emergency agent disable | Preventive | Automated | Agent 365, Microsoft Foundry | Alex Morgan | Simulated |
| SEC-020 | Application | Input validation on all user-supplied values | Corrective | Manual | GitHub Advanced Security, Defender | Marcus Hill | Requires production implementation |
| SEC-021 | Application | Output encoding | Corrective | Manual | GitHub Advanced Security, Defender | Marcus Hill | Requires Rogers validation |
| SEC-022 | Application | Session protection | Corrective | Manual | GitHub Advanced Security, Defender | Marcus Hill | Requires Rogers validation |
| SEC-023 | Network | Private endpoints for platform services | Corrective | Manual | API Management, Private Link, Key Vault | Marcus Hill | Requires production implementation |
| SEC-024 | Network | Controlled egress | Corrective | Manual | API Management, Private Link, Key Vault | Marcus Hill | Requires Rogers validation |
| SEC-025 | Network | Web application firewall | Corrective | Manual | API Management, Private Link, Key Vault | Marcus Hill | Requires production implementation |
| SEC-026 | Integration | Schema validation on ERP payloads | Corrective | Manual | API Management, Private Link, Key Vault | Marcus Hill | Requires Rogers validation |
| SEC-027 | Integration | Idempotency and replay protection | Detective | Automated | API Management, Private Link, Key Vault | Marcus Hill | Proposed for proof of value |
| SEC-028 | Integration | Credential rotation for integration identities | Detective | Automated | API Management, Private Link, Key Vault | Marcus Hill | Proposed for proof of value |
| SEC-029 | Logging | Complete logging of material actions | Detective | Automated | Azure Monitor, Sentinel, Purview Audit | Jordan Lee | Simulated |
| SEC-030 | Logging | Tamper-evident audit design | Detective | Automated | Azure Monitor, Sentinel, Purview Audit | Jordan Lee | Proposed for proof of value |
| SEC-031 | Logging | Centralized log retention | Preventive | Automated | Azure Monitor, Sentinel, Purview Audit | Jordan Lee | Implemented in demo |
| SEC-032 | Resilience | Fail-closed behaviour on dependency loss | Detective | Manual | GitHub Advanced Security, Defender | Marcus Hill | Proposed for proof of value |
| SEC-033 | Resilience | Manual continuity procedure | Corrective | Manual | GitHub Advanced Security, Defender | Marcus Hill | Requires production implementation |
| SEC-034 | Resilience | Recovery objectives defined | Preventive | Automated | GitHub Advanced Security, Defender | Marcus Hill | Implemented in demo |
| SEC-035 | Secure development | Static analysis gate | Corrective | Manual | GitHub Advanced Security, Defender | Marcus Hill | Requires production implementation |
| SEC-036 | Secure development | Dependency and secret scanning | Preventive | Automated | GitHub Advanced Security, Defender | Marcus Hill | Simulated |
| SEC-037 | Secure development | Release approval gate | Preventive | Automated | GitHub Advanced Security, Defender | Marcus Hill | Simulated |
| SEC-038 | Responsible AI | Groundedness evaluation | Detective | Manual | Agent 365, Microsoft Foundry | Alex Morgan | Requires Rogers validation |
| SEC-039 | Responsible AI | Prompt-injection red teaming | Preventive | Automated | Agent 365, Microsoft Foundry | Alex Morgan | Implemented in demo |
| SEC-040 | Responsible AI | Human oversight of material decisions | Corrective | Manual | Agent 365, Microsoft Foundry | Alex Morgan | Requires production implementation |
| SEC-041 | Records | Records classification of journals | Preventive | Automated | Microsoft Purview | Samantha Roy | Implemented in demo |
| SEC-042 | Records | Legal hold capability | Corrective | Manual | Microsoft Purview | Samantha Roy | Requires production implementation |
| SEC-043 | Incident response | Security incident playbook | Detective | Automated | Azure Monitor, Sentinel, Purview Audit | Jordan Lee | Proposed for proof of value |
| SEC-044 | Incident response | Agent suspension procedure | Preventive | Automated | Azure Monitor, Sentinel, Purview Audit | Jordan Lee | Simulated |
Security statements describe design intent in a prototype. Rogers security, privacy and audit validation is required before any production use.