Die Produktivität von KI-Agenten und Wissensgraphen nutzen, bei voller Kontrolle über eure Daten.Use the productivity of AI agents and knowledge graphs, with full control over your data.

Agent-in-a-Box Governance mit Secobo®‑OSAgent-in-a-Box Governance with Secobo®‑OS

Jeder KI-Agent, der Unternehmensdaten sieht oder bearbeitet, wirft dieselbe Frage auf: Wer stellt sicher, dass er nur sieht, was er sehen darf, und nur tut, was er tun darf? Every AI agent that sees or edits company data raises the same question: who makes sure it only sees what it is allowed to see, and only does what it is allowed to do?

Für euch als Betreiber und Entscheider ist der Einsatz von KI-Agenten eine stetige Abwägung zwischen Tempo und Kontrolle. KI-Agenten versprechen Produktivität, aber jeder neue KI-Agent vergrößert die Angriffsfläche auf eure Daten. Die Frage dahinter lautet: Wer entscheidet, ob ein Werkzeug-Aufruf ausgeführt wird? Der KI-Agent, oder das System, dem die Daten anvertraut sind? Dieser Artikel beschreibt eine Architektur, die die Abwägung auflöst: KI-Agenten so einfach wie Apps auf einem Smartphone, Datenzugriff so streng wie bisher.

For you as operators and decision-makers, the use of AI agents is a constant trade-off between speed and control. Agents promise productivity, but every new agent enlarges the attack surface on your data. The underlying question is: who decides whether a tool call is executed? The agent, or the system the data is entrusted to? This article describes an architecture that resolves the trade-off: agents as easy as apps on a smartphone, data access as strict as before.

Unsere MissionOur mission

Secobo®‑OSSecobo®‑OS

Unsere Idee ist es, Menschen und KI-Agenten eine gemeinsame Arbeitsfläche mit nativ integrierten GRC Features zu geben. Dabei sollen die KI-Agenten so sicher und einfach wie möglich in eure Arbeitsabläufe integrierbar sein.

Our idea is to give people and AI agents a shared workspace with natively integrated GRC features. In it, AI agents should be as secure and simple to integrate into your workflows as possible.

Das SicherheitskonzeptThe security concept

KI-Agenten so einfach wie Apps auf einem SmartphoneAI agents as easy as apps on a smartphone

Ihr kennt das vom Smartphone: Eine App installiert ihr mit einem Tipp und nutzt sie sofort. Sie läuft in einer Sandbox und kommt nur an das heran, was ihr freigebt. Genau so betreibt Secobo®‑OS KI-Agenten. Drei Regeln sind dabei etwas strenger als auf dem Telefon.

You know this from your smartphone: you install an app with one tap and use it right away. It runs in a sandbox and reaches only what you release. Secobo®‑OS runs AI agents the same way. Three rules are a little stricter than on the phone.

Ein bewährtes Sicherheitskonzept … … auf KI-Agenten angewendet. installieren · nutzen · Sandbox Smartphone Einmal erlaubt, gilt bis zum Widerruf. Die App sieht, was ihr freigebt. Die App handelt selbst. Secobo®‑OS Eine Infrastruktur Agents-in-a-Box Sandbox für KI-Agenten · Pi.dev HeyBop Personal Assistant auf Basis Hermes Agent Klassifizierung Fach-Agent Rezertifizierung Fach-Agent Euer Agent eigene Lösung Secobo Governance & Knowledge Wissen · Rechte · Labels Wie eine Sandbox für Mobile Apps, nur etwas strenger: Rechte gelten nur für die Sitzung, nicht für immer. Ein KI-Agent sieht nie mehr als der Nutzer selbst. Die Plattform handelt, nicht der KI-Agent.
Links das Smartphone: Apps laufen in einer Sandbox und bekommen nur, was der Nutzer freigibt. Rechts Secobo®‑OS: KI-Agenten laufen genauso. Ihr Wissen liefert Secobo Governance & Knowledge: der Wissensgraph des Unternehmens samt Rechten und Labels. Drei Regeln sind strenger. Die Rechte gelten nur für die Sitzung. Ein KI-Agent sieht nie mehr als der Nutzer selbst. Und die Plattform handelt, nicht der KI-Agent. Quelle: Eigene Darstellung, mit Claude erstellt.
A proven security concept … … applied to AI agents. install · use · sandbox Smartphone Allowed once, valid until revoked. The app sees what you release. The app acts on its own. Secobo®‑OS One infrastructure Agents-in-a-Box Sandbox for AI agents · Pi.dev HeyBop Personal Assistant based on Hermes Agent Classification specialist agent Recertification specialist agent Your agent your own solution Secobo Governance & Knowledge knowledge · rights · labels Like a sandbox for mobile apps, only a little stricter: Rights apply to the session only, not forever. An AI agent never sees more than the user does. The platform acts, not the agent.
On the left the smartphone: apps run in a sandbox and receive only what the user releases. On the right Secobo®‑OS: AI agents run the same way. Their knowledge comes from Secobo Governance & Knowledge: the company's knowledge graph with its rights and labels. Three rules are stricter. Rights apply to the session only. An AI agent never sees more than the user does. And the platform acts, not the agent. Source: own illustration, created with Claude.

Der Rest dieses Artikels zeigt, woher diese drei Regeln kommen: nicht aus dem KI-Agenten, sondern aus der Plattform, der die Daten anvertraut sind.

The rest of this article shows where these three rules come from: not from the agent, but from the platform the data is entrusted to.

BausteineBuilding blocks

Zwei Hälften einer LösungTwo halves of one solution

Ein KI-Agent ist so nützlich wie das Wissen, an das er herankommt. Ohne Zugriff auf die Dokumente, Strukturen und Zusammenhänge eures Unternehmens bleibt er ein Sprachmodell ohne Wissen über euch. Mit Zugriff wird er jedoch zur Governance-Challenge. Denn für Unternehmensdaten sind Rechte und Vertraulichkeitsstufen zu beachten. Ein KI-Agent respektiert davon nichts von selbst. Deshalb steht am Anfang jedes Agenten-Vorhabens dieselbe Frage: Sieht und tut der KI-Agent nur, was der Mensch dürfte, in dessen Namen er handelt?

An AI agent is only as useful as the knowledge it can reach. Without access to your company’s documents, structures and relationships, it remains a language model without knowledge of you. With access, however, it becomes a governance challenge. For company data, rights and confidentiality levels must be observed. An AI agent respects none of them by itself. That is why every agent initiative starts with the same question: does the agent only see and do what the person on whose behalf it acts would be allowed to?

Die Antwort liegt nicht im KI-Agenten. Er kennt die Regeln nicht, und niemand sollte ihm vertrauen, sie einzuhalten. Die Antwort liegt in zwei Bausteinen: einem Wissensgraphen, der das Wissen des Unternehmens und seine Regeln kennt, und einer Sandbox für KI-Agenten, die sie leicht macht.

The answer does not lie in the agent. It does not know the rules, and nobody should trust it to follow them. The answer lies in two building blocks: a knowledge graph that knows the company’s knowledge and its rules, and a sandbox for AI agents that makes them lightweight.

WissensgraphKnowledge graph

Secobo®‑OS

Unsere Data-Governance-Plattform liest Dokumente, Personen, Berechtigungen und Vertraulichkeits-Einstufungen aus Systemen wie Microsoft 365 aus. Daraus entsteht der Wissensgraph eures Unternehmens: ein zusammenhängendes Bild eures Unternehmenswissens und davon, wer was sehen darf. Eine Governance-Wahrheit für Menschen und KI-Agenten.

Our data governance platform reads documents, people, permissions and confidentiality classifications from systems such as Microsoft 365. From this it builds your company’s knowledge graph: a coherent picture of your company’s knowledge and of who may see what. One governance truth for people and agents.

Sandbox für KI-AgentenSandbox for AI agents

Pi.dev

Die Harness ist die technische Hülle, in der ein KI-Agent läuft: Modellanbindung, Werkzeug-Schleife, Sitzungsverwaltung. Pi.dev bringt diese Bausteine fertig mit, schlank und quelloffen, erweiterbar über Plugins. Ein neuer KI-Agent ist für Secobo®‑OS dadurch wie ein Plugin, kein Bauprojekt.

The harness is the technical layer an agent runs in: model connection, tool loop, session management. Pi.dev ships these building blocks ready-made, lean and open source, extensible through plugins. For Secobo®‑OS, a new agent is therefore like a plugin, not a construction project.

Der Wissensgraph tut zweierlei. Er ist die Governance-Wahrheit: wer was sehen darf. Und er ist der Grund, warum ein KI-Agent auf dieser Plattform mehr kann als anderswo. Er kennt nicht nur Dokumente, sondern Zusammenhänge – welche Person zu welchem Team gehört, welches Dokument in welchem Ablageort liegt, welche Vertraulichkeitsstufe es trägt, was womit verbunden ist. Ein KI-Agent, der darauf fragt, bekommt Kontext statt Trefferlisten. Für Menschen gilt dasselbe: Sie sehen ihr Unternehmenswissen als Ganzes, nicht als Ordnerbaum.

The knowledge graph does two things. It is the governance truth: who may see what. And it is the reason an AI agent can do more on this platform than elsewhere. It knows not only documents but relationships – which person belongs to which team, which document sits in which storage location, which confidentiality level it carries, what is connected to what. An AI agent that queries it gets context instead of hit lists. The same holds for people: they see their company knowledge as a whole, not as a folder tree.

Erst zusammen ergeben beide Teile die Lösung. Pi.dev macht KI-Agenten leicht zu bauen und zu betreiben. Der Wissensgraph macht sie vertrauenswürdig, denn er steuert, wer was sehen darf. Nach diesem Agent-in-a-Box-Muster entsteht jeder KI-Agent: unser Assistent Hermes heute, Fach-Agenten für Klassifizierung oder Rezertifizierung morgen. Auch eure Fachabteilungen bauen so eigene Lösungen, risikoarm, weil die Governance nicht bei ihnen liegt, sondern in der Plattform.

Only together do both parts form the solution. Pi.dev makes AI agents easy to build and operate. The knowledge graph makes them trustworthy, because it controls who may see what. Every agent follows this Agent-in-a-Box pattern: our assistant Hermes today, specialist agents for classification or recertification tomorrow. Your own departments build their solutions the same way, with low risk, because governance does not sit with them but in the platform.

PrüfzeitpunktTime of check

Welche Art von Steuerung wirklich schütztWhat kind of control really protects

Der naheliegende Ansatz sieht so aus: Secobo®‑OS legt fest, welche Werkzeuge ein KI-Agent nutzen darf, und beobachtet danach, was passiert. Dieser Ansatz kontrolliert aber nicht wirklich. Zwischen dem Festlegen beim Start und dem Beobachten danach vergeht Zeit. In dieser Zeit ändern sich Rechte: Jemand entzieht dem KI-Agenten die Freigabe für eine Vertraulichkeitsstufe, oder der Mitarbeiter, für den er arbeitet, verliert den Zugriff auf einen Ordner. Der KI-Agent weiß davon nichts. Er arbeitet weiter mit den Rechten vom Start der Sitzung. Was er dann liest, war beim Start erlaubt und ist es jetzt nicht mehr. Die Beobachtung zeigt das – aber erst hinterher. Und was ein KI-Agent einmal fälschlicherweise veröffentlicht hat, holt niemand zurück.

The obvious approach looks like this: Secobo®‑OS defines which tools an agent may use and then observes what happens. But this approach does not really control anything. Between the defining at the start and the observing afterwards, time passes. In that time, rights change: someone withdraws the agent’s clearance for a confidentiality level, or the employee it works for loses access to a folder. The agent knows nothing of this. It keeps working with the rights from the start of the session. What it then reads was allowed at the start and is no longer allowed now. Observation shows this – but only afterwards. And what an agent has once wrongly published, nobody takes back.

Die Konsequenz: Die Prüfung gehört nicht vor die Sitzung und die Beobachtung nicht dahinter. Beides muss im Moment des Aufrufs geschehen, als ein einziger, synchroner Vorgang.

The consequence: the check does not belong before the session, and the observation does not belong after it. Both must happen at the moment of the call, as one single, synchronous operation.

Werkzeug-KatalogTool catalogue

Ein Katalog, ein NadelöhrOne catalogue, one bottleneck

Secobo®‑OS führt dafür einen zentralen Werkzeug-Katalog für alle externen KI-Agenten. Hermes ist darin kein Sonderfall, sondern eine von mehreren Optionen neben Coding-Assistenten oder künftigen Kunden-Agenten. Jeder KI-Agent ruft denselben Katalog auf, und jeder Aufruf passiert dasselbe Gate. Was das Gate prüft, zeigt der nächste Abschnitt. Für Pi.dev heißt das: Die Werkzeug-Logik entsteht genau einmal. Pi.dev erhält nur Zugriff auf einen Katalog, der ohnehin für jeden KI-Agenten gilt.

For this, Secobo®‑OS keeps a central tool catalogue for all external agents. Hermes is no special case in it, but one of several options alongside coding assistants or future customer agents. Every agent calls the same catalogue, and every call passes the same gate. What the gate checks is shown in the next section. For Pi.dev this means: the tool logic is built exactly once. Pi.dev only gets access to a catalogue that applies to every agent anyway.

Architektur-SkizzeArchitecture sketch

Drei Prüfebenen um die DatenThree layers around the data

Die Daten liegen im Kern von drei ineinander verschachtelten Prüfebenen in Secobo Governance & Knowledge. Jede Prüfebene entscheidet, ob eine Fähigkeit des KI-Agenten sie passieren darf. Ein Aufruf erreicht die Daten nur, wenn er alle drei durchdringt. Jede innere Ebene prüft unabhängig davon, ob die äußere gehalten hat. Die Freigabe von Tools für den KI-Agenten in der Agent-in-a-Box zählt bewusst nicht als Prüfebene: Diese Freigabe prüft keine Berechtigung.

The data sits at the core of three nested clearance layers in Secobo Governance & Knowledge. Each layer decides whether a capability of the agent may pass through it. A call reaches the data only if it penetrates all three. Each inner layer checks independently of whether the outer one has held. The clearance of tools for the AI agent in the Agent-in-a-Box deliberately does not count as a layer: this clearance checks no permission.

Nutzer Anfrage Fremdanwendung ggf. fremder KI-Agent Externes LLM z. B. Claude, GPT Secobo®‑OS Eine Infrastruktur Agent-in-a-Box Pi.dev CUSTOM AGENT z. B. Hermes-Agent handelt im Namen des Nutzers CLI API-Gateway Fremdanbieter-Anbindung Secobo UI Oberfläche für Menschen EMBEDDED UI vom Custom Agent Secobo Governance & Knowledge 1 · ANBINDUNG · KATALOG 2 · AGENT-FREIGABE · LABEL · NUTZUNGSRECHT 3 · NUTZER-RECHTE · SICHT · AI-FREIGABE Datenraum Absicht ungeprüft Tools Freigabe in Pi.dev Übernahme durch Secobo®‑OS Inhalt prüfen 1 2 3
Drei Ebenen, von außen nach innen: Der Nutzer stellt seine Anfrage über die Kommandozeile (CLI) an die Agent-in-a-Box, in der ein Custom Agent läuft, zum Beispiel der Hermes-Agent. Der Custom Agent liefert nur eine Absicht, ungeprüft. Am Rand der Agent-in-a-Box passiert sie die Tool-Freigabe in Pi.dev. An der Grenze zu Secobo Governance & Knowledge übernimmt Secobo®‑OS den Auftrag: Es prüft seinen Inhalt, führt ihn durch die drei Prüfebenen und führt ihn dann selbst aus. Menschen arbeiten in Secobo UI, für sie gilt Prüfebene 3 direkt. Ein Custom Agent kann eine eigene Oberfläche mitbringen, eingebettet in Secobo UI. Eine Fremdanwendung, die der Nutzer ebenfalls benutzt, bindet ihren KI-Agenten über das API-Gateway an, mit eigener Identität, und durchläuft alle drei Prüfebenen. Ein externes LLM, zum Beispiel Claude oder GPT, können der Custom Agent und die Fremdanwendung nutzen. Es sieht nur, was diese nach den drei Prüfebenen erhalten. Quelle: Eigene Darstellung, mit Claude erstellt.
User Request Third-party app may host an AI agent External LLM e.g. Claude, GPT Secobo®‑OS One infrastructure Agent-in-a-Box Pi.dev CUSTOM AGENT e.g. Hermes agent acts on behalf of the user CLI API gateway Third-party integration Secobo UI Interface for people EMBEDDED UI from custom agent Secobo Governance & Knowledge 1 · CONNECTION · CATALOGUE 2 · AGENT CLEARANCE · LABEL · USAGE RIGHT 3 · USER RIGHTS · VIEW · AI CLEARANCE Data space Intent unchecked Tools Clearance in Pi.dev Handover to Secobo®‑OS content check 1 2 3
Three layers, from the outside in: the user sends a request through the command line (CLI) to the Agent-in-a-Box, in which a custom agent runs, for example the Hermes agent. The custom agent delivers only an intent, unchecked. At the edge of the Agent-in-a-Box it passes the tool clearance in Pi.dev. At the boundary to Secobo Governance & Knowledge, Secobo®‑OS takes over the task: it checks its content, runs it through the three layers and then executes it itself. People work in Secobo UI, and layer 3 applies to them directly. A custom agent can bring its own interface, embedded in Secobo UI. A third-party application the user also works with connects its agent through the API gateway, with its own identity, and passes through all three layers. An external LLM such as Claude or GPT can serve the custom agent and the third-party application. It sees only what they receive after the three layers. Source: own illustration, created with Claude.
1 Prüfebene 1 · Secobo®‑OSLayer 1 · Secobo®‑OS

AnbindungConnection

Die Fähigkeit existiert im Katalog und ist für diesen Agenten-Typ angebunden. Sonst läuft der Aufruf ins Leere.

The capability exists in the catalogue and is connected for this agent type. Otherwise the call goes nowhere.

2 Prüfebene 2 · Secobo®‑OSLayer 2 · Secobo®‑OS

Agent-FreigabeAgent clearance

Darf dieser KI-Agent diese Vertraulichkeitsstufe verarbeiten? Und darf dieser Nutzer diesen KI-Agenten überhaupt einsetzen? Beides entziehbar zur Laufzeit.

May this agent process this confidentiality level? And may this user use this agent at all? Both revocable at runtime.

3 Prüfebene 3 · Secobo®‑OSLayer 3 · Secobo®‑OS

Nutzer-RechteUser rights

Sieht der Nutzer, in dessen Namen der KI-Agent handelt, das Zielobjekt selbst? Und ist der Ablageort für KI-Zugriff geöffnet? Seine Sicht ist die Obergrenze.

Does the user on whose behalf the agent acts see the target object themselves? And is the storage location opened for AI access? Their view is the upper limit.

Alle drei Ebenen prüft Secobo®‑OS bei jedem Aufruf auf dem Server, unabhängig davon, welche Tools die Agent-in-a-Box für den KI-Agenten freigegeben hat. Diese Freigabe hält den KI-Agenten fokussiert, verhindert aber nichts. Ein Werkzeug, das in Pi.dev auftaucht, aber in Secobo®‑OS nicht freigegeben ist, scheitert an Prüfebene 1 mit einer klaren Fehlermeldung.

Secobo®‑OS checks all three layers on the server at every call, regardless of which tools the Agent-in-a-Box has cleared for the AI agent. That clearance keeps the agent focused but prevents nothing. A tool that appears in Pi.dev but is not cleared in Secobo®‑OS fails at layer 1 with a clear error message.

Damit die Prüfung wirklich vor der Tat liegt, dürfen Prüfung und Ausführung nicht zwei getrennte Schritte sein. Ein Modell, in dem Secobo®‑OS nur ein „Ja, das ist erlaubt“ ausstellt und der KI-Agent in der Sandbox den Zugriff danach selbst vornimmt, öffnet genau die Lücke, die es schließen soll. Die Sandbox bräuchte dafür eigene Zugangsdaten zu den Daten. Und ein Freibrief lässt sich immer auch anders einlösen als vorgesehen.

For the check to truly come before the act, check and execution must not be two separate steps. A model in which Secobo®‑OS only issues a “yes, that is allowed” and the agent in the sandbox then performs the access itself opens exactly the gap it is meant to close. The sandbox would need its own credentials to the data. And a blank cheque can always be cashed differently than intended.

GrundsatzPrinciple
Autorisierung ist Ausführung.
Authorisation is execution.
  • Secobo®‑OS prüft und handelt in einem Schritt.
  • Keine Autorisierung, die ein KI-Agent selbst sicherstellt.
  • Kein KI-Agent hat Direktzugriff auf die Daten.
  • Secobo®‑OS checks and acts in one step.
  • No authorisation that an AI agent ensures itself.
  • No AI agent has direct access to the data.

Der KI-Agent schickt aus der Sandbox die vollständige Anfrage an den Katalog, Aktion samt Parametern. Secobo®‑OS prüft die drei Ebenen und führt bei Erlaubnis die Aktion selbst aus: liest das Dokument, schreibt den Eintrag, versendet die Nachricht. Zurück kommt nur das fertige Ergebnis oder eine Ablehnung. Ein zweiter Weg zum Datenraum existiert nicht. Damit verhält sich das Gate wie eine Firewall: Es lässt nichts durch, was nicht ausdrücklich erlaubt ist. Es prüft jeden Aufruf einzeln, nicht nur beim Verbindungsaufbau. Und es sitzt zwingend im einzigen Pfad. Ein Unterschied bleibt: Eine klassische Firewall entscheidet nach Adresse und Port. Dieses Gate entscheidet nach der Identität des Nutzers und der Vertraulichkeits-Einstufung des Zielobjekts. Es prüft inhaltlich, nicht nur adressbasiert.

The agent sends the complete request from the sandbox to the catalogue, action and parameters included. Secobo®‑OS checks the three layers and, if permitted, performs the action itself: it reads the document, writes the entry, sends the message. Only the finished result or a rejection comes back. A second path to the data space does not exist. The gate therefore behaves like a firewall: it lets nothing through that is not explicitly allowed. It checks every call individually, not only when the connection is established. And it sits, without exception, in the only path. One difference remains: a classic firewall decides by address and port. This gate decides by the identity of the user and the confidentiality classification of the target object. It checks content, not just addresses.

RestrisikoResidual risk

Was abgesichert ist und wo ein Restrisiko bleibtWhat is covered and where residual risk remains

Vier Antworten für eure Entscheidung: wie KI-Agenten hereinkommen, wo das Ganze läuft, was abgesichert ist, und wo ein Restrisiko bleibt.

Four answers for your decision: how agents come in, where it all runs, what is covered, and where residual risk remains.

Zu den Fähigkeiten führen zwei Wege, und beide enden am selben Gate. In-App-Agenten laufen in der Pi.dev-Harness und handeln im Namen des Nutzers, der sie benutzt. Seine Sicht ist ihre Obergrenze. KI-Agenten aus Fremdsystemen erreichen denselben Katalog über eine reguläre Schnittstelle. Sie bekommen eine eigene Identität und eigene Rechte, die ihr ausdrücklich vergebt, unabhängig von einzelnen Nutzern. Ohne Vergabe sehen sie nichts.

Two paths lead to the capabilities, and both end at the same gate. In-app agents run in the Pi.dev harness and act on behalf of the user who uses them. That user’s view is their upper limit. Agents from third-party systems reach the same catalogue through a regular interface. They receive their own identity and their own rights, which you grant explicitly, independent of individual users. Without a grant they see nothing.

Pi.dev läuft auf demselben Server wie Secobo®‑OS, und das ist mehr als Bequemlichkeit. Erst diese Nähe macht die synchrone Prüfung praktikabel. Auf einem entfernten Server wäre jeder Aufruf ein Netzwerk-Umweg mit Tunnel und Latenz.

Pi.dev runs on the same server as Secobo®‑OS, and that is more than convenience. Only this proximity makes the synchronous check practical. On a remote server, every call would be a network detour with tunnel and latency.

Ein Punkt bleibt offen, und er verdient eine klare Ansage. Die drei Prüfebenen klären, ob gehandelt werden darf. Sie klären nicht, warum. Ein KI-Agent liest Dokumente, Mails und Webseiten. In solchen Inhalten kann eine Anweisung stecken, die nicht vom Nutzer stammt. Das Modell übernimmt sie und formt daraus einen Arbeitsauftrag. Dieser Auftrag ist dann formal berechtigt, und alle drei Prüfebenen lassen ihn zu Recht durch.

One point remains open, and it deserves a clear statement. The three layers check whether an action is allowed. They do not check why. An agent reads documents, emails and web pages. Such content can contain an instruction that does not come from the user. The model picks it up and turns it into a task. That task is then formally authorised, and all three layers rightly let it through.

Der Vergleich: Ein Türsteher prüft den Ausweis, nicht die Absicht. Wer echte Papiere hat, kommt herein, auch wenn ihn jemand geschickt hat. Genau deshalb ist die Linie im Bild oben zweigeteilt. Die Agent-in-a-Box liefert nur eine Absicht. An der Grenze zu Secobo Governance & Knowledge übernimmt Secobo®‑OS den Auftrag, prüft seinen Inhalt und führt ihn erst dann durch die Prüfebenen und zur Ausführung. Die Kontrolle über den Zugang ist durchgängig. Die Kontrolle über den Auftrag hängt an dieser Inhaltsprüfung.

The comparison: a doorman checks the ID, not the intention. Whoever has genuine papers gets in, even if someone sent them. That is exactly why the line in the diagram above is split in two. The Agent-in-a-Box only delivers an intent. At the boundary to Secobo Governance & Knowledge, Secobo®‑OS takes over the task, checks its content and only then runs it through the layers and to execution. Control over access is continuous. Control over the task depends on this content check.

Der mögliche Schaden bleibt dabei begrenzt. Ein KI-Agent in der Agent-in-a-Box kann nie mehr erreichen, als der Nutzer selbst darf. Innerhalb dieser Grenze kann er aber das Falsche tun.

The possible damage remains limited. An agent in the Agent-in-a-Box can never reach more than the user themselves may. Within that limit, however, it can do the wrong thing.

Kein blindes VertrauenNo blind trust

Gegen untergeschobene Anweisungen wirkt die Inhaltsprüfung an der Übergabe. Die Absicht des KI-Agenten wird dort in einen internen, fest strukturierten Aufruf übersetzt, den Secobo®‑OS versteht und prüft, statt freien Text auszuführen. Ergänzend helfen eng geschnittene Fähigkeiten je KI-Agent, eine Rückfrage vor jedem schreibenden Schritt, und ein Protokoll, das jeden Aufruf dem auslösenden Inhalt zuordnet.

Against planted instructions, the content check at the handover takes effect. There, the agent’s intent is translated into an internal, strictly structured call that Secobo®‑OS understands and checks, instead of executing free text. In addition, narrowly cut capabilities per agent, a confirmation before every writing step, and a log that links every call to the content that triggered it all help.

Secobo KI-Agent in a boxSecobo AI agent in a box

Dieselbe Pi.dev-Sandbox ließe sich bei einem Kunden auch ohne Secobo®‑OS betreiben, dann aber ohne diese Gates und mit einem eigenen, schlankeren Werkzeug-Set.

The same Pi.dev sandbox could also be operated at a customer without Secobo®‑OS, but then without these gates and with its own, leaner tool set.

AusblickOutlook

Der KI-Agent bringt seine Oberfläche mitThe agent brings its own interface

Ein Custom Agent bringt Fähigkeiten mit. Er kann auch eine eigene Ansicht mitbringen, mit eigenem Eintrag in der Hauptnavigation von Secobo®‑OS. Ein Rezertifizierungs-Agent zeigt dann seine offenen Prüfungen, ein Klassifizierungs-Agent seine Vorschläge, jeweils an dem Ort, an dem ihr ohnehin arbeitet.

A custom agent brings capabilities. It can also bring its own view, with its own entry in the main navigation of Secobo®‑OS. A recertification agent then shows its open reviews, a classification agent its proposals, each in the place where you work anyway.

Die Ansicht läuft in einem abgeschotteten Fenster innerhalb der Seite, einem sogenannten iframe. Secobo®‑OS stellt den Rahmen: Navigation, Design und Sprache. Das Plugin liefert die Ansicht, und eine schmale Brücke trägt Nachrichten zwischen beiden. Der Navigationseintrag hängt am Nutzungsrecht. Wer den KI-Agenten nicht nutzen darf, sieht ihn auch nicht. Und die Ansicht erreicht Daten nur so, wie der KI-Agent sie erreicht: durch das Gate und im Rahmen der Rechte des Nutzers, der sie öffnet. Es gibt keine globalen Agenten-Rechte, die ihr außerhalb mühsam pflegen müsstet.

The view runs in an isolated window within the page, a so-called iframe. Secobo®‑OS provides the frame: navigation, design and language. The plugin delivers the view, and a narrow bridge carries messages between the two. The navigation entry hangs on the usage right. Whoever may not use the agent does not see it either. And the view reaches data only the way the agent reaches it: through the gate and within the rights of the user who opens it. There are no global agent rights that you would have to maintain laboriously elsewhere.

Damit wird Secobo®‑OS zur Plattform, auf der KI-Agenten nicht nur laufen, sondern auch sichtbar werden. Governance, Wissensgraph und Oberfläche bleiben aus einer Hand, während die KI-Agenten selbst von euch, von uns oder von Partnern kommen können.

Secobo®‑OS thus becomes the platform on which agents not only run but also become visible. Governance, knowledge graph and interface remain from a single source, while the agents themselves can come from you, from us or from partners.

NutzenValue

Was habt ihr davon?What is in it for you?

Ihr bekommt die Produktivität von KI-Agenten, ohne die Kontrolle über den Zugang zu euren Daten aus der Hand zu geben. Secobo®‑OS ist das Werkzeug dafür.

You get the productivity of AI agents without giving up control over access to your data. Secobo®‑OS is the tool for this.

Secobo®‑OS ist der GRC-driven Workspace mit Wissensgraph und KI-Agenten, die denselben Regeln folgen wie Menschen. Der Wissensgraph trägt alle Rechte und Vertraulichkeitsstufen der Quellsysteme, ergänzt um GRC-Features.

Secobo®‑OS is the GRC-driven workspace with a knowledge graph and AI agents that follow the same rules as people. The knowledge graph carries all the rights and confidentiality levels of the source systems, complemented by GRC features.

Diese Kontrolle hängt nicht vom Verhalten der KI-Agenten ab. Sie ist in der Architektur verankert:

That control does not depend on the behaviour of the agents. It is anchored in the architecture:

TempoSpeed

Ein neuer KI-Agent ist eine Plugin-Definition, kein Bauprojekt. Neue Anwendungsfälle in Tagen statt Monaten, auch aus euren Fachabteilungen, ohne neues Risiko für eure Daten.

A new agent is a plugin definition, not a construction project. New use cases in days instead of months, also from your departments, without new risk to your data.

SicherheitSecurity

Ein einziges Gate für jeden Datenzugriff. Ein entzogenes Recht wirkt beim nächsten Aufruf. Zehn KI-Agenten bedeuten nicht zehnfaches Zugriffsrisiko.

One single gate for every data access. A withdrawn right takes effect at the next call. Ten agents do not mean tenfold access risk.

NachweisEvidence

Jeder Zugriff passiert denselben Prüfpunkt. Ihr belegt für jeden KI-Agenten, was er sehen durfte. Basis für Audits und die Nachweispflichten der kommenden KI-Regulierung.

Every access passes the same checkpoint. You can prove for every agent what it was allowed to see. The basis for audits and the evidence obligations of the coming AI regulation.

KostenCost

Die Werkzeug-Logik entsteht genau einmal, für alle KI-Agenten. Die Sandbox für KI-Agenten ist quelloffene Standardware. Kein Eigenbau bei jedem KI-Agenten erneut.

The tool logic is built exactly once, for all agents. The sandbox for AI agents is open-source standard software. No custom build repeated for every agent.

Über unsAbout us

Secobo GmbHSecobo GmbH

Secobo ist ein Beratungs- und Engineering-Unternehmen für Informationssicherheit. Wir bauen Sicherheit in Prozesse, Software, Cloud und KI ein. Alles in einem integrierten System, inklusive KI-Agenten-in-a-Box. Hands-on gebaut nach GRC-Engineering-Prinzipien. Zertifizierungsreif, wenn ihr es braucht.

Secobo is a consulting and engineering company for information security. We build security into processes, software, cloud and AI. All in one integrated system, including AI agents in a box. Built hands-on according to GRC engineering principles. Certification-ready when you need it.

Unsere vier Kernleistungen:

  • Informationssicherheits-Managementsysteme. Aufbau und Betrieb eines ISMS bis zur Zertifizierungsreife. ISO 27001 · ISO 27701 · BSI IT-Grundschutz · DSGVO
  • Secure Software Development Lifecycle. Sicherheit von der Anforderung bis zum Release, eingebaut in den Entwicklungsprozess. OWASP · ISO/IEC 27034 · Cyber Resilience Act (CRA)
  • Cloud Security Governance & Compliance. Regeln, Kontrollen und Nachweise für sichere und regelkonforme Cloud-Umgebungen. BSI C5 · SOC 2 · NIS2
  • AI Security & Security Automation. Absicherung von KI-Systemen und Automatisierung von Sicherheits- und Compliance-Aufgaben mit KI. ISO 42001 · EU AI Act

Our four core services:

  • Information security management systems. Building and operating an ISMS up to certification readiness. ISO 27001 · ISO 27701 · BSI IT-Grundschutz · GDPR
  • Secure Software Development Lifecycle. Security from requirement to release, built into the development process. OWASP · ISO/IEC 27034 · Cyber Resilience Act (CRA)
  • Cloud Security Governance & Compliance. Rules, controls and evidence for secure and compliant cloud environments. BSI C5 · SOC 2 · NIS2
  • AI Security & Security Automation. Securing AI systems and automating security and compliance tasks with AI. ISO 42001 · EU AI Act

Mehr unter More at www.secobo.de

Secobo. Enjoy Security.