Security & governance

Holistic Agent scopes every agent to your own knowledge, isolates each business's data, and routes anything an agent is unsure of to a human — governance is a design constraint, not a feature added afterward.

Answers only from what you give it

Every agent is scoped to your uploaded knowledge. It doesn't draw on general training data to answer business-specific questions, and it says so when it doesn't know.

Isolated data per business

Each business's data, conversations, and knowledge base are isolated with row-level security. Nothing is shared across businesses or used to train models.

Human escalation, not silent failure

When an agent is unsure or a request falls outside its scope, it escalates to a human rather than guessing or acting beyond its remit.

No unattended financial or irreversible actions

Agents that touch bookings, quotes, or account changes are scoped to draft and confirm — not to commit an irreversible or financial action without a defined approval step.

Built and hosted for UK businesses

Holistic Agent is built and supported in the UK. Data handling follows UK GDPR principles — your data is processed only for the purpose you've configured it for, isolated per business, and never sold or used to train models shared with other customers.

For the underlying design discipline behind these controls, see Module 11 — Security, Governance and Control in the free course.

Questions

Does the agent ever act without a human able to review it?
No. Every agent is designed with human-in-the-loop escalation for anything outside its defined scope — the dominant pattern in production agent systems, not an afterthought.
Is my business's data used to train AI models?
No. Each business's data is isolated with row-level security and is never shared with other users or used to train models.
What happens if an agent doesn't know the answer?
It says so, rather than inventing an answer. Agents are scoped to answer only from the knowledge you give them.