Reference architecture

A controlled execution boundary between AI agents and enterprise systems.

ContactLab separates organizational policy from individual agent behavior. The organization defines the execution boundary. The agent operates inside it. Relevant evidence remains available after the execution ends.

Architecture layers

Five layers separate organizational policy from agent behavior. Each layer is defined before the workload starts; together they produce governed execution with retained evidence.

Organization control plane

Defines who can run which supported agent against which resource under which execution profile.

IdentityTeamsResourcesExecution profilesPolicyReviewersRetention

Execution profile

Defines the technical boundary before the workload starts.

Base environmentResource scopeNetwork policyCredential scopeApproved toolingRuntime limitsApproval requirements

Ephemeral agent runtime

Runs the selected supported agent in a task-scoped environment.

Claude CodeOpenAI Codex

Policy & event layer

Evaluates relevant execution activity against configured controls and surfaces blocks or review requests.

Tool eventsFile/data eventsNetwork eventsPolicy decisionsApproval requestsRuntime status

Evidence layer

Preserves the context required for later security review and audit.

Session metadataPolicy decisionsArtifactsChanges/diffsApprovalsReview outcomeAudit history

Assume the agent and its inputs can become untrusted.

Agents consume repository content, user instructions, tool responses and external data while executing actions. Security-critical constraints should rely on enforceable environment and resource boundaries, not only on the model following instructions correctly.

  • Constrain filesystem and data access
  • Restrict network access
  • Scope credentials and workload identity
  • Use task-scoped, ephemeral execution
  • Preserve structured evidence
  • Keep human control for designated high-risk operations

ContactLab complements native agent security controls.

Claude Code and Codex continue to evolve their own sandboxing, permissions, managed configuration and telemetry. ContactLab's role is to provide an organization-owned execution and evidence model across the supported agent layer and the enterprise resources those agents need to reach. The differentiation is organizational standardization and cross-vendor, cross-resource control.

See ContactLab at work.

During the meeting, we show a live or prepared governed execution in ContactLab's own company environment. You will see the enforced boundaries, a human review step and the evidence retained after the run.