Persona boundaries
Keep each synthetic identity within its defined purpose and context.
Security
Synthetic identities are useful only when their boundaries are explicit. stickysweet is designed around controlled personas, scoped access, durable audit history, and analyst visibility.
01 / Identity isolation
Synthetic identities should remain separate from production employee identities and real employee credentials. The boundary is the principle: it defines where a persona belongs and what it must never inherit.
Conceptual model — not a deployment architecture
02 / Access principles
These principles guide the control foundation across identity, authorization, credentials, sessions, and review. Specific controls and availability are verified during product evaluation.
03 / Agent controls
Controlled engagement starts with explicit limits, observable behavior, and a human path to intervene. These principles describe the direction of the engagement control model; they are not a claim that every capability is production-deployed today.
Keep each synthetic identity within its defined purpose and context.
Limit tools and data to what an approved engagement requires.
Define what a persona may do before an interaction begins.
Make disallowed behavior clear and enforceable by the control model.
Use synthetic data without production employee credentials.
Preserve conversation context for review, logging, and investigation.
Give operators a clear path to halt activity and retain human oversight.
Route decisions beyond a persona's authority to an analyst.
04 / Auditability
A durable activity history helps analysts reconstruct what changed, who or what acted, and where an interaction belongs. Records should connect operational events back to the relevant persona.
SYSTEMANALYSTSYSTEMANALYSTSYSTEMANALYSTSYSTEM05 / Data ownership
Security teams should be able to understand the personas they operate, the assets connected to them, and the intelligence those interactions produce. Deployment, retention, and data-handling requirements should be evaluated for each environment.
06 / Architecture philosophy
These principles guide how controlled identity operations should be designed, reviewed, and evolved.
Security by control