Plan Runner — AI-native enterprise planning

Trust architecture

Control is part of every decision.

Identity, authorization, residency, audit, and AI approval are platform planes with enforceable contracts—not optional UI settings.

Least-privilege access by relationship
Region-aware routing and storage
Immutable actor and change provenance
Reversible production mutations

Identity and provisioning

SAML, OIDC, SCIM, service identities, revocable sessions, invitations, groups, and lifecycle controls.

Relationship authorization

Tenant, workspace, application, model, and document relations combine with specialized cell-access evaluation.

Tenant cryptography

Tenant encryption contexts, customer-managed key references, vault-backed secrets, and explicit rotations.

Regional isolation

Planning data and AI context stay in assigned regions with tiered cell, namespace, cluster, or sovereign isolation.

Governed intelligence

AI proposes. Policy and people decide.

Agents receive typed tools and governed context. Any production mutation becomes a reviewable proposal with actor, inputs, outputs, approvals, and rollback.

1
Context builder selects permitted model metadata
2
Policy service evaluates model, data, and action
3
Agent runtime calls typed, auditable tools
4
Approval gateway holds governed mutations
5
AI audit records prompt, context, output, and action