Authority
Define which agent, person, or service may request an operation and for which purpose.

The gap between GRC and execution
Platforms such as Scrut, Drata and Vanta help manage controls, compliance and evidence. But an agent still needs a live decision before it reads data, changes a record or starts a payment. DataInbox turns the relevant requirement into an execution rule and returns evidence of what happened.
Identity, customer context, current business state, policy, authority and approval produce one clear result: allow, warn, approve or block.

The governed solution
Agents can still be built with OpenAI, Claude, local models or specialist tools. Instead of connecting each one directly to production, they submit a proposed action to DataInbox.
DataInbox checks the current business context, policy and authority. It can allow, warn, request approval or block. After execution, the decision and outcome return as structured evidence for your organisation and its GRC platform.
Build agents anywhere. Operate them as one accountable organisation.
Provider development · 29 September 2026
OpenAI reports that its public-beta Agents API can now use an OpenAI-hosted browser; the application handles website-access approvals and sign-in. This confirms a browser capability and its access boundary. It does not authorize a refund, change a customer record, or establish a DataInbox integration.
For a service owner, an order exception illustrates the proposed DataInbox boundary. Before: an agent signs in, finds the order and clicks a refund control, with the approval and evidence assembled later. After: the agent proposes the refund; DataInbox would check current order state, amount, customer identity and the owner's approval rule before any permitted action, then record the result. That governed sequence is a design to pilot, not a newly released product flow.
A pilot could test fewer manual handoffs, less rework after an incorrect action, and faster evidence retrieval. Measure completed cases, approval waiting time, corrections, failed browser steps and total tool plus model cost. It needs a scoped identity, stable website access, an authoritative order source, an accountable approver and a safe recovery path.
Five controls
Define which agent, person, or service may request an operation and for which purpose.
Expose only the message fields, references, and history required for the current task.
Validate the proposed operation against schemas, policy, limits, and current business state.
Require an expert or accountable owner where judgment, risk, or policy demands it.
Record the request, context, decision path, action, outcome, and override as structured messages.
One subject, four pages
Governance should not become one giant collection of generic controls. Each product surface has a specific job.
The operating context for one agent role, its messages, tools, proposals, approvals, and outcomes.
ExploreThe execution layer that coordinates messages, policy, capabilities, iteration, and results.
ExploreThe broader Inbox, platform, identity, deployment, retention, and evidence controls around the operation.
ExploreA focused view of runtime accountability and evidence that may support organisational obligations.
Explore