Security & human governance
Separate what AI may read, prepare, approve and publish
DES-Prime authority is enforced by identity, dataset scope and action policy. Prompt text cannot grant a user or agent additional statistical authority.
| Action | Agent | Statistical officer | Supervisor / authorised release |
|---|---|---|---|
| Find authorised records | Allowed | Allowed | Allowed |
| Run approved validation rules | Allowed | Allowed | Allowed |
| Prepare clarification / working table | Allowed as draft | Allowed | Allowed |
| Change establishment master | Not allowed | Controlled request | Approve per policy |
| Register corrected return | Only after approval event | Initiate / controlled | Approve per policy |
| Accept return for aggregation | Not allowed | Recommend / review | Authorised decision |
| Release official statistic | Not allowed | Not by agent workflow | Authorised publication process |
Security benchmark results
Protected requests authenticated1,200 / 1,200
Unauthorised protected actions blocked120 / 120
Requests with correlation ID1,200 / 1,200
Official release without approval0
Sensitive operational data should be minimised in prompts and logs. Audit events retain identifiers, versions and decision evidence needed for traceability without copying entire protected datasets.
Primewayz industrial statistical intelligence