Qeravio
Public AI least-privilege policy

Least privilege starts with a denial, not a credential.

Every declared AI unit receives only an exact tool family, data domain, safe action, task scope and short evaluation window. A passing evaluation is not a credential and cannot execute a tool.

9declared AI units
24exact tool policies
900maximum evaluation seconds
0credentials or live grants
Policy evaluation only, not live authorization.

Allow means only that a synthetic request matched this closed policy. It does not issue a token, connect a tool, approve spending, deploy, publish, send or prove that an action occurred.

Deny-by-default map

Nine AI units have twenty-four exact non-executing policy tuples.

Anything outside the exact unit, tool, data, action, task, Worker and time tuple is denied.

Fail-closed controls

A missing or broader request is denied before it can become authority.

The public endpoint is read-only. The evaluator has no connector, credential or execution path.

  • Default denyUnknown unit, tool, data, action or task scope is denied.
  • Short evaluation windowA request must be active now and may span no more than fifteen minutes.
  • Exact Worker bindingA policy from another Worker fails closed.
  • Distinct AI checkerEvery policy owner and declared checker are active, different AI units.
  • No credentialAn allow result is a policy test result only and cannot be replayed as access.
  • No external effectSend, publish, delete, purchase, account mutation, deployment and real-world execution are denied.
What is still missing

A verified policy engine is not live permission enforcement.

These gaps block any claim that Qeravio currently issues, revokes or enforces live access.

  • Gate 1Connect the evaluator to authenticated task assignment only after an authorization and revocation design is independently verified.
  • Gate 2Issue no credential until scope, expiry, storage, rotation, revocation and replay defenses pass security review.
  • Gate 3Bind every live tool invocation to an evaluated policy record without storing prompts, user content or raw tool traffic.
  • Gate 4Add one exact owner approval flow before any send, publication, purchase, account mutation, deployment or other external effect.
  • Gate 5Verify organization and member isolation, live revocation, concurrency and rollback in authorized accounts.
  • Gate 6Measure denied overreach, repeated use and member outcomes before claiming whole-product enforcement or value.
Version binding

This policy set belongs to one exact Worker and source chain.

A unit, tool, data domain, action, checker, source or Worker change requires a new independent review.

Evidence identifier
qeravio-qtop198-public-ai-least-privilege-release-20260820T185710Z
Registry evidence
qeravio-qtop193-public-ai-unit-registry-release-20260820T185710Z
Decision-log evidence
qeravio-qtop197-public-ai-operation-decision-log-release-20260820T185710Z
Tested Worker
56bbaf52-e861-4c6d-870e-87c2369a2b78
Completed
Aug 20, 2026, 6:57 PM
Allowed policy proofs
24
Denied adversarial proofs
13
Credentials issued
0