IrisKey.ai™ security

Nothing acts without the right permission.

8ORA chooses the best way to complete a job. IrisKey.ai™ separately checks whether the action is allowed. This keeps the system doing useful work without quietly giving itself more access or control.

A separate permission check Live illustration
IrisKey.ai™
  • Identify
  • Verify
  • Approve
  • Refuse
  • Remove access
  • Record
Choosing a worker never grants permission

Powerful AI still needs permission.

Choosing the best way to do a job and being allowed to act are different decisions. 8ORA.AI chooses how the work should be done. IrisKey.ai™ checks whether it is allowed.

8ORA.AI

Chooses the best way to complete the job.

  • Finds and compares suitable tools
  • Chooses separately for each job
  • Builds focused digital workers
  • Coordinates the work from start to finish

IrisKey.ai™

Checks whether the action is allowed.

  • Checks identity
  • Approves, refuses or asks a person
  • Removes access when required
  • Records what was decided and done

From request to recorded result

  1. Business request Work the organisation needs done
  2. 8ORA.AI — Select What is best equipped for this job
  3. IrisKey.ai™ — Authorise Whether it may act at all
  4. Digital worker The scoped worker that carries it out
  5. Action The thing actually done
  6. Evidence The record left behind

8ORA.AI builds the toolbox. IrisKey.ai™ controls the key.

Being best for the job does not grant permission. A digital worker may be fast and capable—and still not be allowed to touch a particular business system, set of records or environment. Nothing 8ORA.AI concludes can turn a denial into permission.

The principles this rests on

Rules that do not bend under pressure.

The system choosing how to do a job should not also decide whether it is allowed to do it. These rules keep approval separate, visible and under the organisation's control.

  • Being suitable does not mean being allowed

    The best digital worker for a job may still be refused access to particular records or systems. Suitability and permission are checked separately.

  • Permission comes before action

    The check happens before an email is sent, content is published, money is spent or business data is changed—not afterwards.

  • Denial cannot be argued with

    No recommendation or strong performance can turn a refusal into permission. Good work does not quietly earn wider access.

  • Access can be removed

    Permission can be withdrawn from one worker, tool or connected system without stopping the rest of the digital team.

  • The business receives a clear record

    The organisation can review what was requested, what was approved and what was done afterwards.

  • No supplier receives automatic trust

    Changing the AI or tool used for a job never changes who controls permission: the business does.

This page describes the security model and the boundary between the two systems. It does not describe implementation detail, and no certification or compliance status is claimed here.

Talk to 8ORA.AI

Which job should your business never have to do manually again?

Show us where time is being lost or work keeps repeating. We will explain whether 8ORA can improve it, what the result could be and what should remain under human approval.

Protected by IrisKey.ai™ — important actions require approval.