AI Executive Office — CXO Assistant Platform · View 26 of 30 · 7 · Assurance
The blast-radius argument
- The orchestrator holds no credential for any store. Compromising it yields the ability to ask questions as whoever is calling, and nothing more. That is the point of putting the tool plane in a separate zone
- Public ingress ends at the perimeter. Every service behind it is private-endpoint only, and administrative access has no standing privilege
- Egress has exactly one path, through a firewall with an FQDN allow-list. A model that has been talked into exfiltrating data has nowhere to send it
The threats this addresses
- Prompt injection through a retrieved document, treated as the primary AI-specific threat: retrieved content is data, never instruction, and the model has no write tool to be talked into using
- Credential theft of an executive account: conditional access, device compliance and MFA, and the platform inherits the account's authority rather than exceeding it
- The operator as a threat: Customer Lockbox, PIM, and telemetry that excludes content
Risks
- The tool plane is now the single most security-critical component in the platform. It is small by design, changes rarely, and every tool contract change goes through security review