Every material action: policy-gated, reviewed, approved, on the record.
This page is written for the people who sign: risk, compliance and IT. Every claim below names its mechanism - and where an artifact exists, you can read it before you commit.
Two gates. No exceptions for material actions.
Finding
A case needs a decision - context assembles from your systems.
Agent review
Specialist analyses challenge the recommendation - policy, compliance, evidence.
GATE 1Consensus
A structured verdict - rationale, disagreements, unresolved evidence.
Human approval
The named quality, clearing or compliance owner decides. Nothing runs without this.
✓ GATE 2Execution
Only approved actions execute in your systems - logged and signed.
logged · signedHuman authority built in - not bolted on.
Authority rules
Approval limits, spend authority, referrals, exceptions and escalation - encoded as policy and enforced at the approval gate, not written in a handbook.
Review & challenge
Independent agent review challenges every material recommendation - policy, compliance, evidence and quality - before it reaches a human.
Named human approval
Every material action routes to a named accountable person with the authority to decide it. No anonymous approvals, no silent execution.
Hash-chained audit history
Evidence, recommendation, challenge, approval, action and outcome are recorded in a hash-chained history - reproducible for any case, exportable for any audit.
Autonomy levels & revocation
Low-risk repeatable patterns earn automation on measured performance. Your critical actions never graduate. One bad outcome revokes autonomy - with retro-review of the autonomous window.
Evaluation framework
Case-level accuracy, completeness, escalation quality, latency, human acceptance and business outcomes - measured against a baseline agreed before every shift.
The Materiality & Gates Specification.
A short normative document - public, not marketing. It defines materiality default-deny: any action that writes to a system of record, communicates externally, commits money or coverage, or touches personal data is material and human-gated unless explicitly whitelisted by a named customer role under four-eyes. It states the exact two-gate semantics (agent challenge gate, then named-human gate), the autonomy graduation and revocation governance including the customer-locked always-human list, and a build-status column per control - present tense only where shipped.
The works-council commitment: the system evaluates agents, never employees - acceptance metrics are aggregated-only (minimum group size n≥5), with no per-user drill-down in product or exports, as a contractual product commitment.
DORA / VAIT outsourcing readiness, prepared.
Outsourcing review is the gate that blocks procurement in regulated sectors - so we prepare the file, as a readiness pack, not a compliance claim:
- Outsourcing-readiness mapping for DORA / VAIT
- DORA Art. 30 contract clauses prepared for your legal review
- Audit rights including BaFin access
- Exit and data-return plan
- ICT-register language ready to paste
- Subprocessor and model-provider chain, disclosed
- Key-person clause for a two-founder vendor, stated plainly
Evidence for your obligations - stated precisely.
The audit chain produces evidence supporting Art. 12 record-keeping, Art. 14 human oversight in operation, and your Art. 26 deployer obligations. Annex III high-risk obligations apply from 2 August 2026 - Annex III 5(c) explicitly covers risk assessment and pricing in life and health insurance. The provider/deployer role allocation (Art. 25) is stated in writing before any pilot touching underwriting.
The boundary is permanent, not a phase.
Most vendors describe what they would like access to. This is the opposite: five categories we do not ask for, do not plan as a later stage, and do not renegotiate. It is part of the data processing agreement, so widening it would be a contract change you would have to sign — not a setting somebody adjusts.
- Slack, Teams or e-mail content
- Source code of any kind
- Financial-system access
- Any live or standing integration
- Personnel files or performance data
Your data plane, your model estate.
Vendor-managed, EU-resident - with BYOM
The headline deployment: we operate an EU-resident instance, and bring-your-own-model routes every request into the model estate you already have agreements for - fail-closed, so a destination with no credential stops the request rather than falling back to one. Self-hosting remains a full capability for houses with their own operations team, on request.
GDPR-aligned architecture
Customer-managed keys, schema-per-tenant isolation, no training on customer data, and one-operation tenant erasure. We name the mechanisms - we never claim a certification or status we do not hold.