<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
<title>IBM BAW Tips Q&amp;A - Recent questions tagged security</title>
<link>https://bpm.tips/tag/security</link>
<description>Powered by Question2Answer</description>
<item>
<title>How should AI outputs be governed inside a BAW process (human in the loop, confidence thresholds, audit, PII, prompt injection)?</title>
<link>https://bpm.tips/3559/how-should-ai-outputs-be-governed-inside-baw-process-human-in-the-loop-confidence-thresholds-audit-pii-prompt-injection</link>
<description>Before we put generative AI or ML predictions into customer-facing processes, risk management asks how decisions are controlled and audited. What process design patterns keep AI in BAW governable?</description>
<guid isPermaLink="true">https://bpm.tips/3559/how-should-ai-outputs-be-governed-inside-baw-process-human-in-the-loop-confidence-thresholds-audit-pii-prompt-injection</guid>
<pubDate>Sun, 06 Sep 2026 14:00:36 +0000</pubDate>
</item>
<item>
<title>Who can see which process instances and tasks in BAW, and how do I restrict instance visibility per business unit?</title>
<link>https://bpm.tips/3505/who-can-see-which-process-instances-and-tasks-in-baw-and-how-do-i-restrict-instance-visibility-per-business-unit</link>
<description>Managers of one region must not see instances of another region in the portal, saved searches or Process Inspector. Which rules decide instance and task visibility, and how do we restrict them without building a custom portal?</description>
<guid isPermaLink="true">https://bpm.tips/3505/who-can-see-which-process-instances-and-tasks-in-baw-and-how-do-i-restrict-instance-visibility-per-business-unit</guid>
<pubDate>Sun, 06 Sep 2026 13:51:14 +0000</pubDate>
</item>
<item>
<title>How do I secure coach views and REST calls against a strict Content Security Policy and clickjacking headers on BAW?</title>
<link>https://bpm.tips/3441/how-do-i-secure-coach-views-and-rest-calls-against-a-strict-content-security-policy-and-clickjacking-headers-on-baw</link>
<description>Security asked us to add Content-Security-Policy and X-Frame-Options headers on the BAW web tier. After that, coaches with inline scripts broke and the portal iframe stopped rendering. What is compatible with coaches and what needs code changes?</description>
<guid isPermaLink="true">https://bpm.tips/3441/how-do-i-secure-coach-views-and-rest-calls-against-a-strict-content-security-policy-and-clickjacking-headers-on-baw</guid>
<pubDate>Sun, 06 Sep 2026 13:39:49 +0000</pubDate>
</item>
</channel>
</rss>