---
title: "Control AI Systems and Agent Access Physically | Firevault"
description: "AI systems and autonomous agents need bounded access, not standing credentials. See the paths that need governing, what physical Control changes and where the…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/control-for-ai-systems#webpage",
      "url": "https://fire-vault.com/control-for-ai-systems",
      "name": "Control AI Systems and Agent Access Physically",
      "description": "AI systems and autonomous agents need bounded access, not standing credentials. See the paths that need governing, what physical Control changes and where the…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/control-for-ai-systems#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/control-for-ai-systems#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Control AI Systems and Agent Access Physically",
          "item": "https://fire-vault.com/control-for-ai-systems"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What is exposedWhy it existsThe path to controlWhat Control changesThe Control philosophyThe BlueprintQuestions

Systems and access 

# AI systems act on their own. Their access should still be bounded. 

An AI system or agent inherits whatever it is connected to. Once it holds standing credentials and a permanent route into your data and tooling, its reach is only as small as the last configuration change. Physical Control puts the boundary somewhere an agent cannot rewrite.

-   Agent and model access
-   Standing credentials
-   Bounded windows
-   Recorded activity

[See what Control changes](#change) [What is Control](/control)

The connection state today

## Permanent, credentialed and wide

Access **Standing API keys and service accounts**

Scope **Whatever the integration was granted**

Duration **Until someone revokes it**

Evidence **Application logs, if retained**

Need → Control → Blueprint → Modules

![Corridor of offline storage racks inside a Firevault bunker](/assets/hero-square-bunker-B6Y7Qt9r.jpg)

01 What is exposed 

## The reach of an agent is rarely the reach that was intended

AI systems are connected to make them useful. The exposure comes from what remains connected after the useful work has finished.

**01**

### Standing credentials

Keys and service accounts issued once and used indefinitely, often outside normal joiner and leaver process.

**Identity**

**02**

### Wide data reach

An agent given access to a share or system can usually read far more of it than the task required.

**Data**

**03**

### Tool and action rights

Agents that can act, not just read, can change systems at machine speed and without a person in the loop.

**Action**

**04**

### Prompt-driven behaviour

Instructions can arrive inside the content an agent processes, so intended limits are not always the limits that apply.

**Behaviour**

**05**

### Weak evidence

When something goes wrong, the record of what the agent reached is frequently incomplete.

**Audit**

**06**

### Model and training material

Proprietary models, weights and curated training sets sit online with the same reach as ordinary files.

**Assets**

02 Why the exposure exists 

## Agents are integrated quickly and reviewed slowly

The pace of adoption is the point. The consequence is that access is granted to get something working, then inherited by everything that follows.

The pattern 

### Convenience becomes permanence

Nobody decides that an agent should hold indefinite access to a production system. It happens because the credential worked and nothing forced it to expire.

**Control the path, protect the asset.**

01

### Pilots become production

Access granted for an experiment is rarely reissued when the experiment becomes a dependency.

02

### Scope is hard to express

Most systems grant access at the level of a share, a database or an account, not the level of a task.

03

### Autonomy outpaces review

An agent can take thousands of actions between the change control meetings meant to govern it.

04

### Ownership is unclear

AI integrations often sit between engineering, data and the business, so no one holds the access register.

03 Which paths need controlling 

## Name the routes an agent can take

Control starts by writing down the specific paths between AI systems and the systems and data they reach.

The path or relationship Who uses it How it behaves today What Control governs 

**Agent to production data**Internal AI platform Standing service account Window opened for a named purpose, then closed 

**Agent to external model API**Third-party provider Always-on egress Defined route, approved destinations, recorded transfers 

**Agent to tooling and actions**Automation layer Broad permissions Validated requests with revocation on signal 

**Model and training assets**Data science Live shares Held offline and brought back for the work 

**Human oversight route**Named owners Ad hoc Out-of-band approval and an evidenced trail 

The list matters more than the technology. Once the paths are written down, the governance question becomes concrete.

04 What physical Control changes 

## The boundary sits outside the software the agent runs on

Physical Control does not attempt to reason about intent. It governs whether a route exists at all.

Connection state today

### Before

Access is configured and trusted to stay configured.

-   • Credentials persist until someone removes them
-   • Reach is defined inside the application
-   • Revocation depends on the system responding
-   • Evidence is scattered across logs

Connection state with Control

### After

Access exists only inside a window that has been opened.

-   ✓ No standing path between runs
-   ✓ Windows opened for a named purpose and owner
-   ✓ Revocation enforced at the physical layer
-   ✓ Every window recorded as evidence

**An agent cannot exceed a connection that is not there.**Connected when approved. Disconnected by default. 

05 The Firevault principle 

## Control is physical, or it is only a policy

Software can be told to deny a connection. Physical Control removes the connection itself, so the denial does not depend on the system behaving as configured.

**01**

### Start with the path, not the tool

Every incident that spreads does so along a connection that was already there. Control begins by naming that connection in plain language, before anyone talks about products.

**02**

### Make the default state disconnected

A path that exists only when it is needed cannot be used at three in the morning by someone who should not have it. Disconnection is the resting state, not the emergency response.

**03**

### Open on approval, close on schedule

When work genuinely needs a connection, Control opens it for a named person, a stated purpose and a fixed period, then closes it again without anyone having to remember.

**04**

### Prove it physically, not on paper

A policy says the path should be closed. Physical control shows that it is. That difference is what auditors, insurers and boards are actually asking about.

How this fits together

### Your need sets the direction. Control sets the rule. The Blueprint sets the architecture.

Need Control Blueprint Modules and Firebreak 

06 Where this is designed 

## The Blueprint for this need is CP-03 Control Third-Party Access 

Governing AI access uses the same architecture as third-party access, with compliance evidence alongside it.

CP-03 · Lead layer FIRE+VAULT

### Control Third-Party Access

Give third parties access without giving them a permanent doorway.

Modules the Blueprint leads with

[Validate](/control/modules/validate)[Relay](/control/modules/relay)[Lock](/control/modules/lock)

Applied to time-bounded vendor and supplier access. The Blueprint page carries the architecture, the zone detail and the deployment sequence.

[Open the AI Control Blueprints](/control-blueprints/cp-03) [See Firebreak hardware](/firebreak)

Why it is worth exploring

### What you get from the Blueprint that this page does not cover

-   ✓ It shows how a request is validated before any route opens
-   ✓ It sets out time-bound windows instead of standing credentials
-   ✓ It defines the evidence trail an auditor or regulator will ask for

[Compare all Blueprints](/control-blueprints)

[Also relevant · CP-06

### Prove Compliance Through Control

Compliance becomes stronger when control can be demonstrated, not just documented.

Open CP-06](/control-blueprints/cp-06) [Also relevant

### AI Control Blueprints

AI access patterns are set out in the AI Control Blueprints playbook, which covers agent access, tooling rights and oversight in more depth than a single numbered Blueprint.

Open the playbook ](/playbook/ai-control-blueprints)

A different job

This page is about the routes an AI system can take. Protecting the models, weights and training material themselves is a different job, and Offline Secure Storage holds those copies physically outside the connected environment.

[Protect models and training data offline](/oss-for-intellectual-property)

Questions 

## What teams ask about AI access

The practical questions that come up once agents move from pilot to production.

Does this stop us using AI?

No. It changes when the connection exists. The work still happens, inside a window opened for a named purpose that closes afterwards.

Is this not just better identity management?

What about external model providers?

Where do the models themselves live?

Need → Control → Blueprint 

## Name what the agent can reach. Then bound it.

The AI Control Blueprints show how agent access is validated, time-bound and evidenced without slowing the work down.

[Open the AI Control Blueprints](/control-blueprints/cp-03) [Talk to a member of the team](/contact)