Security & trust

Trust, built into every agent.

Fulcrum gives AI real work, so it holds AI to firm rules. Agents get the same permissions as people, never more than their supervisor. Guardrails apply company-wide. And every action, by every person and agent, is on the record.

Security principles

One permission model

People and agents use the same tools, levels, and templates. An agent can never exceed its supervisor’s access.

Guardrails that hold

Company-wide rules for what agents never do, what they ask first, and what they may do on their own.

Everything on the record

Every action by every person and agent is logged, with the reasoning, inputs, and tool calls behind it.

Your data stays yours

Customer data is never used to train models, and sensitive details can be redacted before AI processing.

Permissions

One permission model for people and agents.

Permission templates set access tool by tool, from None to Read, Standard, and Admin, with granular rights like approving change orders up to a dollar limit. Agent templates use the same levels and add autonomy, and an agent can never exceed its supervisor.

  • Templates for executives, PMs, supers, engineers, accounting, safety, design teams, owners, and subs
  • Granular rights with dollar thresholds
  • Agents capped at their supervisor’s access
Fulcrum permission templates with tool access levels for a Project Manager template.

Audit log

Every action, by every person and agent.

The audit log records who did what, when, to which record, and how, whether in the app, from a phone, or by an agent at runtime. Filter by person, agent, project, or action, ask it questions in plain words, and export it.

  • Agent runs show reasoning, inputs, and tool calls
  • Approvals recorded with the approving person
  • Search in plain language and export to CSV
The Fulcrum audit log with actions by agents and people, timestamps, objects, and approvals.

AI governance

Guardrails apply to every agent. Agents can be stricter, never looser.

Admins set company guardrails once. Individual agents and tools can be tightened further, but nothing an agent does can override them.

People only

No agent, at any autonomy level

  • Commit or release money Approve invoices, execute change orders, issue purchase orders.
  • Sign on behalf of a person Signatures always belong to the accountable person.
  • Change permissions or invite users Only people with Admin can change who has access.
  • Delete records Agents can void or archive with a reason, never hard delete.

Ask first

Agent proposes, a person approves

  • Send messages to other companies Email, RFI distribution, transmittals, and notices.
  • Draft financial changes over $25,000 Budget modifications, change event pricing, and forecasts.
  • Modify the baseline schedule Lookaheads and forecasts are fine; the baseline is not.
  • Publish drawing and spec sets Makes a new set current for every user.

Allowed

Inside the agent’s tools and projects

  • Create and update internal records Within the tools and projects the agent can access.
  • Search drawings, specs, and past answers Read anything its permission template allows.
  • Draft documents and messages RFIs, logs, reports, and replies, left for review or sent per policy.
  • Remind and assign internal tasks Nudge people on your team and log what it asked for.
The AI governance page in Fulcrum with a Pause all agents control and company guardrails set to Allowed, Ask first, or Never.

Data & access controls

Controls your IT team will ask about.

  • No training on your data

    Customer data is never used to train models. It is a locked policy, not a setting.

  • Redaction before processing

    Strip Social Security numbers and bank details before an agent ever sees them.

  • Retention for audit

    Agent inputs and outputs are retained alongside the audit log, so every decision can be reconstructed.

  • Email access you control

    Choose whether agents can read project email, company-wide.

  • SSO and MFA

    Single sign-on, multi-factor authentication, and session controls for every member.

  • Scoped API keys

    API keys and MCP tokens scoped to exactly the actions an integration needs.

  • Spend limits

    Reasoning tiers, per-agent compute budgets, a company cap, and alerts at 80% of any budget.

  • Pause all agents

    One switch stops every agent across the company. Running steps finish; nothing new starts.

FAQ

Security questions

Have a question that is not here? Ask us

Is our data used to train AI models?

No. Customer data is never used to train models. This is a locked policy in AI governance rather than an option an admin can switch on.

Can an agent do more than the person who supervises it?

No. Agents use the same permission templates as people, add autonomy settings on top, and can never exceed their supervising person’s access.

What can agents never do?

Commit or release money, sign on behalf of a person, change permissions or invite users, or hard-delete records. These hold for every agent at every autonomy level.

How do we see what an agent did and why?

Open the audit log or the agent’s activity. Each run shows the trigger, every tool call with its inputs and results, the reasoning, and who approved any gated step.

Who should I talk to about a security review?

Contact us and choose “Something else.” We will connect you with the team to answer questionnaires and walk through Fulcrum’s architecture and controls.

Have a security questionnaire?

We are happy to walk your IT and risk teams through how Fulcrum handles data, access, and AI governance.