Platform

The layer your programme actually runs in.


Not a report you receive. Not a dashboard you check. The working record of your AI governance programme — inventory, framework, risks, roadmap, policies and evidence — with agents being built to keep it current and the disclosure gate keeping it defensible.

Where it sits

Above your AI tools. Below your board.


Your security stack sees traffic. Your AI platforms see configuration. Your board sees a slide. The operating layer is the only place those three meet — and the only place a finding can be classified, owned, sequenced and evidenced without being retyped.

Reporting out
Board and committee reporting · maturity scorecards · audit artifacts
↑
The AI Governance Operating Layer
Inventory · Framework · Risk register · Roadmap · Policies · Evidence
Agents will keep it current. The disclosure gate keeps it defensible. One consultant signs it.
↑
Signal in — in build, no date published
Security stack — Splunk, Netskope, Cato, Fortinet, Cisco  ·  Enterprise AI platforms — OpenAI, Google, Anthropic, Microsoft
Today the layer is fed by engagement evidence, intake and consultant observation. Direct connectors to the systems named above are in build for Q4. Vendor names indicate intended coverage, not existing integrations.
↑
Your AI estate
Sanctioned tools · tools under review · shadow AI you don't yet know about

Your security stack answers "who is touching AI we haven't sanctioned?" Your AI platforms answer "is the AI we did sanction still inside its approved boundary?" A firewall cannot see a model version change or a retrieval-index re-crawl. Both classes land in the same layer and get classified the same way.

The rules

The rules that make it defensible. Three architectural, one in build.


Governance software is easy to build and hard to defend. These are the constraints designed in first, because each one is something you would be asked to evidence in an audit and could not retrofit.

Two states, one gate today

Every record carries an internal review state and a separate client-visibility flag. Quality control and disclosure are different decisions, so they are different switches. Today the disclosure gate is enforced and the review state is a discipline, not a lock — we are wiring the dependency, and until we have, we will not describe it as a control.

Tenancy enforced in the query, never by prompt

Your data is scoped where it cannot be forgotten — at the query layer, not by asking a model nicely. No user record resolves to zero rows, not to everything. Never a silent failure, never an unscoped view, never a model decision.

Coordination automated, judgement not

An agent may be responsible for execution. An agent is never accountable. Every classification, adoption and closure is a human decision by design — because if the software decides, the defensibility argument collapses.

Governance metadata only

We record that an event happened, which domain it maps to and whether a policy covers it. Never prompt text, response text or document content. Platform activity is attributed to a department or index, not to a named person.

Gap library

The questions your records should be able to answer. Most can't.


Each of these is a join, not an opinion. Each returns a fact about your record set that no single screen displays. Every agent added to the layer lights up new gaps against everything already in it — which is why the layer gets more valuable as it fills.

The standing gap queries — in build, no date published

Nine definitions, seven of which run against your record set. A gap is never on a dashboard, because dashboards render records

GapDomainWhose finding
Critical or High risk with no linked roadmap item D5⚠ Client
Adopted policy with no accountable owner D5⚠ Client
AI tool touching regulated data with no agreement recorded D3⚠ Client
Automated decisioning use case with no risk entry D2⚠ Client
Reassessment falling due, unscheduled D5AegisPoint
Client record contradicting its own policy library D4⚠ Client

Gaps are records, not code. Each definition carries a name, an absence statement, a query, a severity, an owner side and a coverage precondition — so a consultant can add one without a developer, and the definition itself is an artifact we can show you. Ranking is deterministic: "the three that matter" comes from severity ordering, never from a model choosing.

Your portal

Fourteen pages. One programme.


Every page ends where the next one starts. A risk links to its roadmap wave. A policy gap links to the register entry it creates. A regulatory item names the adopted policy it affects. That is what turns fourteen pages into a programme rather than fourteen reports.

Governance

Current State · Intake Scores · Assessment Results · AI Inventory · Risk Register · Policies · RACI Matrix

Security & Intelligence

AI Security Logs · Intelligence Feed

Resources

Documents · Training · Knowledge Base

Programme

Roadmap · Reports

The disclosure gate

No score reaches you before your executive briefing. Not your own intake rating, not a validated score as it firms up. If a number is on screen while your teams are being interviewed, everyone anchors to it — including us. The briefing is the disclosure event, and the gate fails closed: an unset briefing date shows the withheld state, never the score.

Get started

See it running against your own estate.


A 30-minute discovery call, then a walkthrough of the operating layer with a worked example. No preparation required.