What are we working on?
Read-only access to simulated control attestations, material-event metadata, risk exceptions, and ownership records. Raw company logs, credentials, and operational data remain isolated.
Read-only access to simulated standards, maturity submissions, risk exceptions, and decision records. Operating-company production data and credentials are not exposed.
Read-only access to simulated use-case metadata, evaluation summaries, control attestations, and aggregate spend. Prompts, credentials, and raw operating-company data are not exposed.
Illustrative policy trace
| Step | Enforced policy | Status |
|---|---|---|
| Request resource | Starts with no access; request is limited to Federated Security Evidence | Approved read-only |
| Run deterministic query | Typed capability; credential remains isolated | Logged |
| Render app | Observed resources stay attached to the output | Bound |
| Share | Viewer permissions are checked at open time | Human controlled |
Read-only access to simulated control attestations, material-event metadata, risk exceptions, and ownership records. Raw company logs, credentials, and operational data remain isolated.
Resource boundaries
Marmon - Federated Security Operating Model
Purpose
Align security maturity to business risk across a diverse industrial portfolio through common outcomes, permission-scoped evidence, explicit exceptions, and accountable local execution.
Jobs to be done
| Priority | Journey moment | Required review |
|---|---|---|
| Identity and privileged-access baseline | Enterprise guardrail, local implementation | Company security + risk review |
| Manufacturing and operational resilience | Company-owned protection and recovery | Operations + security review |
| Third-party access and incident evidence | Exception-based portfolio reporting | Risk + legal review |
Operating principles
- Start with a measurable job to be done, not a new tool.
- Use curated company context before model knowledge.
- The human owner remains accountable for every output.
- An agent never receives more permission than the person using it.
Delivery sequence
Map: Identify accountable local owners, critical services, data boundaries, and relevant obligations.
Pilot: Model an opt-in Marmon/Keystone scenario with synthetic evidence, isolated access, and explicit success measures.
Scale: Publish reusable controls, exception paths, and recovery measures without centralizing raw company data.
Control alignment
Local autonomy, least privilege, credential isolation, evidence provenance, legal review, operational safety, recovery testing, and human-owned risk decisions are mandatory design inputs.
Workspace sources
Draft a decision brief that combines shared security guardrails with company-owned implementation and risk decisions.
Read-only access to simulated standards, maturity submissions, risk exceptions, and decision records. Operating-company production data and credentials are not exposed.
Resource boundaries
Workspace sources
Compare security automation candidates through common evaluation, data-boundary, cost, and human-approval controls.
Read-only access to simulated use-case metadata, evaluation summaries, control attestations, and aggregate spend. Prompts, credentials, and raw operating-company data are not exposed.
Resource boundaries
Integrations
Organization-wide connections for Marmon Holdings, Inc. OS. Gatekeepers hold credentials, scope resources, and log each action.
Illustrative remote services available to authorized workspaces.
Organization Context
Shared, curated knowledge that grounds every Marmon Holdings, Inc. OS workspace. Context is versioned and read-only to agents.
Skills
Reusable workflows for every function. The human requester owns the result.
| Name | Description | Group | Source |
|---|---|---|---|
| meeting-prep | Build an agenda and briefing from authorized calendar, CRM, and document context | General | Shared library |
| weekly-operating-review | Create a cross-functional summary with decisions, owners, and open risks | General | Shared library |
| incident-response | Assemble evidence, draft updates, and preserve human approval for containment | Security | Shared library |
| vendor-risk-review | Compare due-diligence evidence with security and privacy standards | Security | Shared library |
| control-evidence-pack | Map authorized evidence to control requirements and identify gaps | Security | Shared library |
| architecture-review | Review a proposal against architecture principles and decision criteria | IT & Architecture | Shared library |
| change-impact | Map dependencies, affected services, stakeholders, and rollback requirements | IT & Architecture | Shared library |
| service-health-review | Summarize service levels, incidents, changes, and capacity risks | Operations | Shared library |
| runbook-builder | Turn a procedure into a deterministic workflow with approval gates | Operations | Shared library |
| ai-model-review | Summarize ownership, evaluations, drift, risk tier, and release readiness | Data & AI | Shared library |
| data-quality-report | Assess freshness, completeness, lineage, and policy compliance | Data & AI | Shared library |
| budget-variance | Compare actuals with plan and draft a finance-reviewed variance narrative | Finance | Shared library |
| procurement-brief | Summarize requirements, alternatives, risk, and approval status | Finance | Shared library |
| job-description | Draft an accessible role description from approved job architecture | HR | Shared library |
| onboarding-plan | Create a role-based onboarding plan without expanding system permissions | HR | Shared library |
| contract-intake | Extract terms, route issues, and prepare a legal review checklist | Legal | Shared library |
| privacy-assessment | Map a proposed workflow to data categories and privacy obligations | Legal | Shared library |
| account-brief | Create a customer briefing from authorized CRM and public information | Sales | Shared library |
| proposal-draft | Build a first draft using approved claims, pricing, and brand context | Sales | Shared library |
| executive-update | Turn project evidence into a concise decision-oriented update | General | Shared library |
Profile
Illustrative account information for this public prototype.
AI Gateway
Illustrative demo data. Visibility and controls across every AI provider Marmon Holdings, Inc. uses — one console.
Models in Use
This month| Model | Route | Tokens | Spend | Share | p50 latency |
|---|---|---|---|---|---|
| Llama 3.3 70B | Workers AI | 156M | $2,140 | 310 ms | |
| Claude | via AI Gateway | 98M | $3,980 | 720 ms | |
| GPT-4o | via AI Gateway | 61M | $2,510 | 640 ms | |
| Workers AI embeddings (bge) | Workers AI | 27M | $190 | 40 ms |
Spend vs. Budget
9 days remainingUsage by Workspace / Team
342M tokens totalGovernance
Guardrails enforced by Gatekeepers + AI Gateway, with resource-scoped access, audit trails, and human approval.
Per-team allowed models
Restrict which providers each workspace can call.
Monthly spend caps
Hard limits per team; agents stop before overrun.
PII redaction
Strip sensitive fields from prompts before they leave.
Prompt / response logging
Full request logs retained for audit & review.
Rate limits
Per-team request ceilings to protect budgets.
Raise Data & AI cap to $6,000
Change queued by an agent — needs a human sign-off.
Requires approval