# Trust & Guardrails

How Otonoma's network keeps people in control, runs compiled plans you can check before they start, keeps your data in your own node, and stays around regulated systems — by architecture, not by policy.

## Autonomy with the guardrails built in

Guardrails for agentic artificial intelligence (AI) belong in the architecture. Models predict; the network executes.

## People stay in control

The routine runs itself; the judgment calls go to a person. A human in the loop is a first-class step in every workflow, not an exception path. People are actors on the network, with their own permissions, and the network decides only what it has been allowed to decide.

- **One-tap approvals.** When a decision needs a person, it arrives as a single clear question in the channel they already use, with just the context they need.
- **Escalation, options worked out.** Exceptions reach a person with the alternatives already planned and checked, so the answer is a choice, not a research project.
- **The network learns.** Each answer becomes part of how the workflow handles the same situation next time.

For mission-critical work, the workflow can require human approval at every gate — nothing moves until the right person says so.

## Deterministic execution: you can see the plan before it runs

Workflows compile into goal trees before anything happens. Generative AI helps build and validate the plan up front. At runtime the model never improvises: the compiled plan executes as written, the same way every time.

- **Plan, then execute.** In Paraflow, a rule's output is a plan, not execution, so the whole plan can be inspected and validated first.
- **Predictable by construction.** Deterministic execution of compiled plans — you know what will happen before it happens.
- **Failures re-plan, within the rules.** When a step fails, the goal tree substitutes a task it already knows about, or asks a person.
- **No surprises on cost.** Compiled plans run at a small fraction of the cost of asking a language model to reason from scratch.

## Negative trust

Zero trust verifies who you are at the door; negative trust keeps watching what you do inside.

- **Every actor carries a certificate.** Identity is verified for every system, device and person on the network.
- **Only registered skills.** Nothing can be requested or performed unless it has been declared.
- **Skill-level access control.** Permissions apply to each individual request, so an actor can be allowed one skill and refused the next.
- **Observers.** Invisible to the actors they watch, they monitor behavior continuously and can flag, pause or remove a misbehaving actor.

## Your data stays yours

Each operator runs its own node in its own cloud, and its customers' data never leaves it. There is no central server and no shared database for anyone to reach into, including us.

- **Directional federation.** A hotel can be asked for rooms without being able to reach back into whoever asked.
- **You choose what to share.** Each party exposes exactly the skills it chooses, and nothing else.
- **Your integrations stay your intellectual property.** What you connect, you own.

## Around regulated systems, never through them

The network orchestrates the work around a regulated system without taking it over. Those systems keep their own controls and their own owners.

- **Payments and cardholder data** stay in the payment systems built for them. The network coordinates what happens next, not the transaction itself.
- **Regulated gaming systems** at a resort with a casino floor are out of scope. The stay, the dinner and the car around them are not.
- **Regulated flight operations** governed by the Federal Aviation Administration (FAA) stay with the airline. The network looks after the passenger around them.

## A complete record

Actors talk in conversations, not calls, and every message is recorded in each node's ledger: who asked, who answered, what happened. The network is auditable by construction, in real time and after the fact.

- **Per-node ledgers.** Each party keeps the record of its own work, in its own node.
- **Declined options are kept, not deleted.** When a person picks one alternative, the others stay in the record, showing what was offered and why.
- **One trail from request to result** — for operations, for compliance, and for the customer who asks what happened.

## Overlay, not rip-and-replace

Keep every system you run; add the layer that connects them. An actor sits in front of an existing system without touching its internals, so adopting the network means zero downtime and no migration. Start with one workflow, prove it, then add the next.

## Learn more

- [What is the Paranet](https://www.otonoma.com/what-is-the-paranet)
- [Developers](https://www.otonoma.com/developers)
- [How the Paranet works — the full technical walkthrough](https://www.otonoma.com/events/how-the-paranet-works)

[Request a demo](https://www.otonoma.com/demo-request) or [talk to us](https://www.otonoma.com/contact).
