01

Trusted identity

Attribute traffic to an organization, workspace, principal, application, and key before policy is evaluated.

02

Pre-dispatch enforcement

Evaluate access, spend, region, retention, and endpoint eligibility before a provider call is made.

03

Explicit failover

Fail over only across administrator-approved endpoints. Policy constraints do not relax to recover a request.

04

Runtime evidence

Record the policy version, endpoint, attempt chain, reservation, settlement, and outcome without requiring payload logging.

05

Least privilege

Separate model, billing, security, and organization responsibilities. Payload access is not implied by an administrative role.

06

Controlled change

Version policy changes, approvals, emergency actions, and administrative events for audit and rollback.