Trust

Seeing never waits. Doing is earned.

An AI that understands your business does not automatically get control of it. What Arden may see and what it may do are separate questions, and the second always lags the first.

The trust ladder

Autonomy climbs policy by policy.

The ladder gates what Arden may do, never what it may see or say. Each policy climbs on its own, at the monthly review, and any rung can be taken back with one click.

  1. Rung 1

    Watch

    Read-only: Arden sees your systems and says what it sees — the brief, the watches, the catches, the answers. It writes to nothing.

    Day one, always

  2. Rung 2

    Notify

    Arden proposes: a decision arrives with its evidence and blast radius, and waits. Nothing happens until a person acts on it.

    Week one

  3. Rung 3

    Approve-required

    Arden executes what you approve, back into your systems, under a written policy that names who may approve what. Logged with actor, decision and evidence.

    Week two onward

  4. Rung 4

    Auto-execute under policy

    For decisions you have approved the same way enough times, Arden acts without asking and tells you after. Policy by policy, never all at once, always revocable.

    Earned, monthly

The standard of care

In every deployment. Not an enterprise upsell.

Least-privilege access

Each connector requests the narrowest scopes that let it do its job, stated on screen before you grant. Visibility inside Arden mirrors what each person’s role can see in the source system.

Read-only for the first week. Always.

No deployment writes to any system in its first seven days, whatever the plan or the urgency.

Blast radius before approval

Which system is written to, what changes, what it costs, how long it stays reversible, what the customer sees. Shown before you tap.

Approval by default

Anything customer-facing or money-moving defaults to approval required. Auto-execution is earned after you have watched Arden be right.

Every decision keeps its transcript

The reasoning is stored with the evidence it cited, and every claim opens in the system it came from.

A kill switch at three levels

Per agent, per connector, and global. One click, no ticket.

Append-only audit

Decisions, actions, outcomes and learnings are never edited in place. Corrections are new records that reference the old ones.

A trust-incident counter, tracked forever

An action you regret is recorded as an incident and reported in every monthly review. The target is zero.

Seven questions

Ask these of any AI you let near your systems.

Here are our answers.

Identity
Who is asking?
Every request, approval and decline is tied to a person or a named agent with a charter. There is no anonymous actor in Arden.
Permissions
What can Arden access?
Exactly the scopes you granted, per tool, listed in the console and revocable from either side.
Authority
What is Arden allowed to do?
What a written policy says, and nothing more. Policies are readable in plain language and reviewed monthly.
Evidence
Where did this understanding come from?
Every claim carries its source. Hover it in the console and the record that supports it lights up; click and it opens in its system.
Confidence
How certain is Arden?
Stated on every decision, next to the policy gate. Low confidence is a reason to ask you, not a reason to guess.
Approval
Which actions require a person?
By default, anything customer-facing or money-moving. The set shrinks only as you move a policy up the ladder.
Audit
What happened, and why?
Every read and write, with actor, decision and evidence, append-only, exportable, yours.

Ask us the hard questions first.

Before you grant anything, ask for the scope list for each tool you run, the starting policy set for your deployment, and a walk through the audit log of a live decision. We would rather answer on the first call than after.