Trust should come from visible boundaries and precise facts: where data moves, what a digital operator may access, what it may do, and where policy places a named human.
DAERTHO / TRUST BOUNDARIES
WHERE THE WORK HAPPENS
Zone 01 · Customer
Customer environment
documents · profiles · transactions
Zone 02 · Control
Daertho control plane
identity · policy · audit · scoped credentials
Zone 03 · Runtime
Operator execution
task scope · approved tools · isolated context
Zone 04 · Sources
External evidence
registry · sanctions · PEP · media
Zone 05 · Authority
Human approval
analyst · MLRO · maker-checker
Customer → Control → Runtime → Sources → controlled case → Authority when required.
Evidence returns to the controlled case path. Human authority enters when required.
Boundaries define where work may happen.
Control model
Security is a set of things the system refuses to do.
Access, execution and authority are bounded separately. Controls define what the operator can access, what it can execute and where authority changes hands.
CONTROL PRINCIPLES
01 · ACCESS
Least privilege.
Scope roles, tools and credentials to the task rather than exposing them broadly.
02 · DATA
Explicit boundaries.
Data movement and access should follow defined boundaries.
03 · RUNTIME
Constrained execution.
Operators work inside a bounded runtime with approved tools and clear authority limits.
04 · AUDIT
Reconstructable actions.
Inputs, evidence, tool use, policy and approvals stay together in the case record.
Policy defines where execution stops.
Authority matrix
Operators stop where policy says stop.
A serious trust model distinguishes preparation from authority.