Handvantage

ARCHITECTURE

Seven control layers.Seven questions a buyer can test.

Architecture diagrams are useful only when they lead to a reproducible test. Vantage Workspace separates policy, prompt handling, tool authority, memory, identity, service authentication, and software provenance so each can be examined in a bounded workflow.

The public architecture describes the control outcomes. Restricted detection, credential, and deployment-topology details are reviewed only in an appropriate technical evaluation.

architecture / evidence chain
Editorial illustration showing a digital action connected to a sealed record and a review artifact.
Architecture earns trust when a buyer can follow one action through its boundary, decision, and retained record.

THE EVALUATION STANDARD

Follow one job from request to evidence.

Start with a real job, not a feature list. Name the source, the AI Worker, the human reviewer, the permitted authority, the model route, the rejection rule, and the record that must remain.

Then test the boundary: remove a grant, request a higher-authority action, introduce representative sensitive content, or ask the Worker to use a source outside its scope. A credible architecture should make the refusal or approval path visible.

Finally, retrieve the record and rerun a buyer-selected control. Claimed is not documented. Documented is not demonstrated. Demonstrated is not reproduced.


THE SEVEN LAYERS

Each layer earns its place with a buyer test.

The outcome, test, and evidence are public. Sensitive implementation mechanics are not part of the marketing claim.

  1. 01

    Policy and authority

    Who may read, draft, approve, or act?

    TestChoose one role and one restricted action. Confirm the permitted path, then repeat without the required grant or approval.

    EvidenceThe policy decision, named human, named AI Worker, approval state, and resulting outcome for the demonstrated run.

  2. 02

    Prompt and data boundary

    What reaches the approved model route?

    TestUse representative content containing a known sensitive element and inspect the configured NemoClaw decision before model use.

    EvidenceThe selected route, observed boundary result, and event retained for the test. Restricted detection mechanics remain private.

  3. 03

    Tool authority

    Can the AI Worker exceed the job it was given?

    TestAsk the Worker to move from reading or drafting into a higher-authority action. Confirm the refusal or human approval gate.

    EvidenceThe requested tool, permitted scope, approval or refusal, and final action state.

  4. 04

    Memory and source access

    Which source can this role retrieve?

    TestSelect a source the role may use and one it may not. Verify the denied path fails closed, then qualify the entitled path for the chosen workflow.

    EvidenceThe caller, source, retrieval decision, and result. Per-document entitled access is verified per workflow rather than assumed.

  5. 05

    Identity and delegation

    Can a reviewer distinguish the human from the AI Worker?

    TestRun a task through a named Worker, then retrieve the event and confirm both the human actor and Worker attribution are visible.

    EvidenceHuman identity, Worker identity, role, delegation path, and timestamp for the observed event.

  6. 06

    Service authentication

    Which trusted service path handled the request?

    TestReview the configured service boundary for the selected deployment and the failure behavior when authentication is absent or expired.

    EvidenceThe service decision and operational result available to the reviewer, without exposing restricted topology or credentials.

  7. 07

    Software provenance

    Which build is the buyer evaluating?

    TestConfirm the visible build identifier, the release artifact in use, and the result of the selected acceptance test.

    EvidenceBuild identifier, tested workflow, observed result, and any known limit relevant to the release decision.


THREE DECISIONS TO KEEP SEPARATE

Deployment, model route, and evidence are related. They are not interchangeable.

Customer environment

Vantage Workspace is single tenant. The managed-private, private-cloud, or customer-hosted pattern is selected from the customer’s operating and support requirements.

Model route

The customer approves a public, private, or local model route. A local-only route and a governed public route are distinct configurations, not one universal claim.

Evidence scope

The record is evaluated against a bounded workflow. A demonstrated event does not prove that every possible application action is captured.


FROM DIAGRAM TO PROOF

Pick the control you most expect to fail.

A useful evaluation is adversarial. Ask for data without the grant, request an action above the Worker's authority, or introduce sensitive content into the selected route.

The buyer should see the refusal, approval gate, or boundary decision and then retrieve the corresponding event. Anything else is a diagram, not proof.

vantage workspace / bounded refusal
Vantage Workspace Desk showing a prompt-injection attempt blocked by the configured policy before the request proceeds.
Demonstrated refusal path — the requested instruction was blocked and the reason remained visible to the operator.

CONTINUE THE CONVERSATION

Choose one control to challenge.

Bring the workflow, source, role, and rejection rule. We will show the configured boundary, run the test, and retrieve the evidence it produced.

Run a control proof →

Or write to hello@handvantage.com directly.