Methodology · Penguin Protect
Guardian Protocol
No automation writes to a live system that moves money, deletes data, or talks to the outside world without a human approval gate.
Most AI consultants ship speed. We ship speed with brakes. Guardian is the signature wrapper on Penguin Protect audits and automation sprints — and the reason CFOs let us near the GL.
The three hard gates
Money movement
Payments, payroll exports, vendor bank changes, invoice sends that trigger settlement.
Data deletion or bulk export
Anything that erases records or ships PII / financial data outside the approved boundary.
External communications
Customer emails, filings, or partner notifications drafted by an agent — human sends.
What “protected” looks like in practice
- Named approver per gate (not “the bot”)
- Credential hygiene: least privilege, MFA, no shared root passwords
- Clients own tools and data; we transfer capability, not hostages
- Audit trail of what was proposed vs what was approved
- Rollback plan before go-live on any write path
One sentence for proposals
“Every automation that can move money, delete data, or send external messages requires a named human approver before it runs in production — documented, least-privilege, and reversible.”
See it on an Audit
The AI Readiness & Protection Audit maps where Guardian gates belong in your stack.