Identity isolation
Governed actions carry a tenant-scoped workload identity.
ELITZE connects identity, reachability, policy, authorized execution, runtime observation, adversarial validation and evidence without pretending missing telemetry is real.
Governed actions carry a tenant-scoped workload identity.
Sensitive actions are evaluated against explicit policy before execution.
Secrets and credentials stay outside the agent context and are brokered under controlled infrastructure.
Tool and protocol requests are treated as authorization decisions, not trusted instructions.
Decision and enforcement records preserve the security path for investigation and retest.
Containment can be handed to a separately authorized executor for isolation or credential action.
The repository contains an authorized pentest control surface and release-security skill definitions. A pentest result is only a result when an actual runner returns evidence; the UI deliberately reports the runner as unavailable when it is not connected.
External intelligence and customer infrastructure supply inputs; they do not replace the ELITZE decision and evidence boundary.