AI · Governance

A compliance gate between the model and the person.

An AI system is only as usable as it is accountable. We design the controls that decide what a model may do, check what it produced, and keep a record anyone with authority can read — before the output reaches a customer, a patient or a record.

The controls

Six controls we build in.

Designed into the architecture from the first sprint, not added once a regulator asks.

01

Compliance gate

A mandatory review step — automated checks, human approval, or both — between every AI-generated recommendation and the person it’s for.

02

Guardrails

Input and output rules that keep a model inside its brief: allowed topics, required disclaimers, blocked actions and data it must never expose.

03

Agent registry

A record of every AI agent in use — what it’s for, which model and prompts it runs, what it may access, and who owns it.

04

Usage & token ledger

Every model call attributed to a user, agent and purpose, so cost, volume and behaviour can be traced after the fact.

05

Audit trail

Inputs, outputs, reviewer decisions and changes logged immutably — the evidence an auditor asks for.

06

Explainability

Sources, reasoning and confidence surfaced alongside an answer, so a reviewer can judge it rather than just trust it.

How it runs

From request to record.

The path every governed AI output follows.

  1. 01 · REQUEST

    Scoped input

    Guardrails check the request and strip data the model shouldn’t see.

  2. 02 · GENERATE

    Registered agent

    A known agent, on a known model and prompt version, produces the output.

  3. 03 · CHECK

    Compliance gate

    Automated checks run; sensitive outputs are routed to a qualified reviewer.

  4. 04 · DELIVER

    Approved output

    Only what passed the gate reaches the person, with its sources shown.

  5. 05 · RECORD

    Audit trail

    Input, output, decision and cost logged — legible to an auditor later.

Where it matters

Built for workflows with consequences.

We map these controls to the rules your organisation answers to — sector regulation, internal policy, or the AI framework you’ve adopted.

Financial advice

In our AI financial planning product, no recommendation reaches a customer without passing the compliance gate.

AI financial planning →

Healthcare

Call summaries and scheduling agents operating inside a HIPAA boundary, writing to the patient record.

Healthcare communications →

Software delivery

AI that audits code and requirements, with its own decisions logged and reviewable.

AI delivery →

Connect & consult

Planning AI where the stakes are real?

Talk to Prithipal Thakur about the controls your context needs — before the first model call goes to production.