Skip to content
BusyBeaver

Security

BusyBeaver decides in code, before any model is called, what an AI agent may read, what it may do and who sees each answer. This page explains how, in plain words.

The three checks

1. What the agent may read

Only notes everyone present may see, decided in code before the model is called.

Every note BusyBeaver stores (a message, a document, a record, an answer it wrote) carries an audience: the people, roles or rooms allowed to see it. Before a group answer, BusyBeaver checks each candidate note against every person in the room. Only notes that all of them may see are handed to the model. When anything is uncertain, such as an error, an unknown rule or a membership that cannot be confirmed, the note is held back.

Held back and missing look the same. A search that only matches notes someone in the room may not see returns "No relevant notes found.", so the room cannot learn that a secret exists.

2. What it may do

Actions need permission, and production deploys need a second person's approval.

The model can only ask for an action; it never runs one. BusyBeaver's action gate checks the asker's role, read from the database and never from notes or model output. Every action then shows a card with the exact action and its arguments. The asker confirms their own card when their role allows the action. When it does not, the card goes to the people who hold that permission, and one of them approves or declines. Production deploys always need a different person to approve. A card works once, is bound to the exact arguments, and expires after 24 hours. Today the built-in action is deploying a service; more arrive with connectors (Coming).

3. What each person sees

Private follow-ups reach only the people allowed to see them.

After the group answer, BusyBeaver writes a short private follow-up for each person who may see more, using only notes that person may see. BusyBeaver's own answers are labeled at least as secret as the notes they came from, so someone who joins the room later, or loses access, cannot read them.

The safety rules in plain words

The benchmark

In our 24-question benchmark, the same model leaked restricted information in 18 questions without BusyBeaver and in 0 with it.

Without BusyBeaverWith BusyBeaver
Questions with a leak18 of 240 of 24
Private follow-ups delivered0 of 87 of 8

Synthetic company data; methodology available on request.

A jailbreak can't reveal what never reached the model.

Any model

Anthropic, OpenAI, Google, or open models through Ollama. Whichever model you choose, it receives only notes that passed the checks, and it never runs tools itself: it can ask for an action, and BusyBeaver's code decides.

Not built yet

Known limits

Report a security issue

Email hello@busybeaver.io with what you found and how to reproduce it. Please do not access other people's data or disrupt the service while testing.