Skip to content

Security

Deception without
losing control.

Synthetic identities are useful only when their boundaries are explicit. stickysweet is designed around controlled personas, scoped access, durable audit history, and analyst visibility.

Control the identity. Preserve the evidence.

01 / Identity isolation

Separate the synthetic from the real.

Synthetic identities should remain separate from production employee identities and real employee credentials. The boundary is the principle: it defines where a persona belongs and what it must never inherit.

01Real environmentPeople · systems · credentials
Controlled boundary
02Synthetic persona environmentControlled identity · synthetic data

Conceptual model — not a deployment architecture

02 / Access principles

Access should be deliberate, scoped, and reversible.

These principles guide the control foundation across identity, authorization, credentials, sessions, and review. Specific controls and availability are verified during product evaluation.

01Identity verification
02Scoped authorization
03Credential lifecycle
04Session boundaries
05Account disablement
06Review history
Platform directionENGAGEMENT CONTROL MODEL

03 / Agent controls

Constrain the persona before it engages.

Controlled engagement starts with explicit limits, observable behavior, and a human path to intervene. These principles describe the direction of the engagement control model; they are not a claim that every capability is production-deployed today.

01

Persona boundaries

Keep each synthetic identity within its defined purpose and context.

02

Constrained tools

Limit tools and data to what an approved engagement requires.

03

Explicit permitted actions

Define what a persona may do before an interaction begins.

04

Prohibited actions

Make disallowed behavior clear and enforceable by the control model.

05

Isolated synthetic data

Use synthetic data without production employee credentials.

06

Analyst visibility

Preserve conversation context for review, logging, and investigation.

07

Stop controls

Give operators a clear path to halt activity and retain human oversight.

08

Escalation controls

Route decisions beyond a persona's authority to an analyst.

04 / Auditability

Every action should leave a trail.

A durable activity history helps analysts reconstruct what changed, who or what acted, and where an interaction belongs. Records should connect operational events back to the relevant persona.

ACTIVITY / PERSONA-1028 ILLUSTRATIVE
14:32:00Persona createdSYSTEM
14:33:01Identifier attachedANALYST
14:34:02Asset assignedSYSTEM
14:35:03Exposure changedANALYST
14:36:04Interaction receivedSYSTEM
14:37:05Analyst reviewedANALYST
14:38:06API key usedSYSTEM
Conceptual activity history; retention and audit behavior depend on evaluated capabilities.

05 / Data ownership

Your personas. Your infrastructure. Your intelligence.

Security teams should be able to understand the personas they operate, the assets connected to them, and the intelligence those interactions produce. Deployment, retention, and data-handling requirements should be evaluated for each environment.

01Personas
02Infrastructure context
03Interaction intelligence

06 / Architecture philosophy

Security is a system of boundaries.

These principles guide how controlled identity operations should be designed, reviewed, and evolved.

01Least privilege
02Isolation
03Explicit identity boundaries
04Auditability
05Controlled engagement
06Human oversight

Security by control

A honeypot should create intelligence—
not another source of risk.