Skip to content
MajuWorks

Architecture, security and accountability

Systems designed to be understood and operated.

MajuWorks documents system boundaries, data ownership, interfaces, permissions, controls and support responsibilities so business and technical owners can evaluate how the solution will operate.


01Reference architecture

A layered operating environment.

06Control plane— identity, permissions, approvals, logging, monitoring, change control, recovery
05Intelligence layer
Reports, metrics, alerts and management analysis
04Agent layer
Defined AI tasks, bounded actions and escalation
03Workflow layer
Business rules, approvals and orchestration
02Integration layer
APIs, connectors, events and controlled data exchange
01Systems of record
ERP, retained applications and authorised data sources
LegendSystem of recordRules-based automationAI agentHuman step
The actual architecture, providers, hosting arrangement and data locations are documented for each deployment.
Note

The actual architecture, providers, hosting arrangement and data locations are documented for each deployment.


02Technical due diligence

Questions the design must answer.

  • Which system owns each important data object?
  • How are users, services and agents authenticated?
  • How are permissions granted, reviewed and removed?
  • Which interfaces can write to production records?
  • Which actions require approval?
  • What activity is logged and for how long?
  • How are integrations monitored and reconciled?
  • How are changes tested, approved and released?
  • How are failures detected, escalated and recovered?
  • What are the backup and restoration arrangements?
  • Where is customer data processed and stored?
  • How are third-party providers and models assessed?
  • What happens to data, configurations and documentation when service ends?

03Security and data protection

Controls are selected according to the deployment.

Security and personal-data protection depend on the systems, data and responsibilities within scope. Relevant measures may include access control, multi-factor authentication, encryption, environment separation, secure secret management, vulnerability management, backups, logging, incident procedures, retention controls and supplier assessment.

Note

Organisations remain responsible for meeting applicable obligations under Singapore’s Personal Data Protection Act. MajuWorks documents its role and relevant processing responsibilities for each engagement. Do not use a generic "PDPA compliant" badge as a substitute for describing actual practices.


04Responsible AI

Governance for agents that can act.

Assess and bound risk

Select appropriate use cases and limit action space, access and autonomy.

Meaningful human accountability

Name responsible owners and place approval checkpoints at material decisions.

Technical controls and processes

Apply lifecycle testing, access controls, guardrails, logging, monitoring and change management.

Responsible end-user use

Explain capabilities, limits, data access, responsibilities and escalation; provide appropriate training.

Note

This approach is designed with reference to IMDA's current Model AI Governance Framework for Agentic AI. It is a design framework, not a claim of certification.


05Evidence available by engagement

Trust should be supported by documentation.

Possible artefacts: architecture diagram; data-flow map; role and permission matrix; integration specification; risk assessment; agent use-case specification; test plan and results; change log; operating runbook; incident and escalation procedure; data-processing terms where applicable.


06Claims policy

What we will not claim without evidence.

  • IMDA approval or certification
  • AI Verify certification
  • Guaranteed accuracy, savings or return on investment
  • Full auditability of an AI model's private reasoning
  • Singapore-only data hosting unless contractually verified
  • 24/7 service or contractual response times unless included
  • Compliance with every law or sector requirement without a scoped assessment