Intelligence moves where it is authorised. Confidential information remains within agreed boundaries.

Arthur works through defined organisational context, deliberate connections and accountable authority. The boundary comes before the capability.

Organisation 01OperationsBoundary closed
Organisation 02Authorised contextPermission gate open
Organisation 03KnowledgeBoundary closed
ArthurArthurpermission-aware intelligence
Authorised routeNo routeNo route
Evidence trail
Conceptual trust model

Boundary → Permission → Isolation → Control → Evidence

Explore the model
Our position
Your business stays your business.

DELTAGUARD will tell you what information a workflow needs, where it may go, what may remain and who controls the next action. Security begins before access is granted.

Access is granted. Access is bounded. Access can be withdrawn.

Move through the model to see the working relationship between the organisation, its permissions and Arthur.

01 / Organisation

The organisational boundary is established first.

People, systems and information begin inside a named working context. A client relationship alone does not make every system available.

Conceptual permission model. The exact route depends on the authorised service and connection.

Disconnected until you decide otherwise.

Choose systems in the model. Only authorised routes illuminate; the rest remain outside Arthur’s working context.

ArthurArthur2 authorised
Illustrative permission stateDocuments · Projects

Becoming a DELTAGUARD client does not itself connect these systems. Each route needs an agreed purpose, suitable credentials and the permissions required for the work.

Try the controls — this visual changes locally and does not connect to any real system.

Five decisions define the working boundary.

Nothing needs to be connected until these questions have clear answers.

  1. 01

    What Arthur may access

    The named systems, accounts, information and purpose of the connection.

  2. 02

    What Arthur may retain

    Where information is transient and where operational records, memory or evidence may remain.

  3. 03

    What Arthur may do

    The difference between reading, preparing, recommending and changing something.

  4. 04

    What requires human authority

    Approval points, accountable roles, escalation and stopped states.

  5. 05

    What happens when access ends

    Connection withdrawal, credentials, export, retention and deletion arrangements.

One flow. Five places to stay precise.

The route varies by service and connection. Retention and access are established around the work being delivered.

01Client system

The source remains identifiable.

Email, document store, CRM or another system inside the agreed account and scope.

Customer-controlled source
02Authorised connection

The route has a purpose.

The connection and capability are made available for the agreed work.

Permission boundary
03Controlled processing

Only useful context should travel.

Arthur or an external intelligence service may process the context required by the workflow.

Transient or operational
04Knowledge / action

The result has a defined state.

Working context, durable memory, prepared work and approval are treated differently.

Retention by design
05Evidence / result

Important activity remains explainable.

Relevant outputs, sources and approvals can remain connected to the result.

Evidence and outcome
Transient processing

Context used for a particular operation.

Operational storage

Records needed to deliver and govern the service.

Arthur memory

Working and durable knowledge states.

Logs & evidence

Relevant action, approval and incident history.

Backups

Recovery copies with their own treatment.

Control should remain understandable to the people accountable for it.

Useful intelligence does not require vague access or invisible authority.

01

Access is not ownership

Your organisation remains the owner of its information. DELTAGUARD treats access as permission granted for an agreed purpose.

02

Organisational boundaries matter

Arthur works inside named organisational context. Each commissioned information path is considered against that boundary.

03

Connections are deliberate

Sources, accounts and capabilities are connected for a defined reason, using the access needed for the work.

04

People retain authority

Sensitive or state-changing work can be placed behind approval according to the capability and the organisation’s rules.

05

Important activity should be explainable

Evidence, approvals and relevant execution records help people understand what happened and why.

06

Information handling is specific

Processing, operational storage, memory, audit evidence, backups and retention are different matters and are addressed as such.

External capability. Organisational continuity remains with Arthur.

Arthur can use external intelligence services where a workflow benefits from them. DELTAGUARD treats those providers as replaceable capabilities—not as the owner or sole home of the organisation’s operating knowledge.

Where provider processing matters, the provider, necessary context and applicable handling terms can be discussed before the connection is commissioned.

Organisation knowledgeScoped context
Operational records
Evidence
Arthur’s continuity layer
Arthurpurpose · context · provider
Provider AExternal processing
Provider BExternal processing
Replaceable capability
CONFIDENTIAL / FIRST

Confidential before anything connects.

DELTAGUARD is prepared to agree appropriate confidentiality and NDA protections before sensitive operational detail is shared. Controlled disclosure begins with knowing who needs the information and why.

The questions a responsible director should ask.

Specific answers create more confidence than generic claims.

01What can Arthur see?

Only the systems and information made available for the authorised work. Becoming a DELTAGUARD client does not automatically connect email, documents, finance, CRM or any other system.

02Can another organisation see our information?

Arthur’s client-facing memory and projections are scoped to the organisation. Every additional commissioned data path is assessed against that organisational boundary before it is used.

03Can DELTAGUARD personnel see everything?

No unrestricted staff access is implied by a client relationship. Where delivery or support requires DELTAGUARD access, who needs it, why and for how long should be established before sensitive information is shared.

04Where does information go?

That depends on the authorised workflow. Information may stay in a connected client system, pass through controlled processing, or be retained as an operational record, Arthur memory, evidence or recovery copy. Arthur distinguishes short-lived working context from durable organisational memory. The route and retention are discussed before connection.

05Are external intelligence providers involved?

They may be used for some workflows. Where they are relevant, DELTAGUARD can explain the provider, the context needed for the work and the applicable handling terms before that workflow is commissioned.

06What happens when our relationship ends?

The exit arrangement should address connection withdrawal, credential revocation, export where applicable, operational retention, backups and deletion. These are agreed for the service rather than hidden behind one blanket promise.

Security before sales.

Talk about the boundary before connecting a single system.

You do not need to send sensitive information to discuss confidentiality, architecture, permissions or information handling with DELTAGUARD.

Discuss security first