Governance

Every prompt is governed before it runs.

Sector policy sets, model controls, approvals, and evidence stay active before, during, and after every run.

Live governance board

Checks before execution

Fail closed

Active policy sets

11

Blocked runs

14

Evidence packs

126

Prompt scanComplete
Model routingApproved
Review gateTriggered
Evidence writeSaved

Evidence trail

Policy event logged

Rule family, sector, and outcome saved.

Run classified

Model path and safety checks recorded.

Evidence attached

Approvals and source traces stay with the run.

Policy enforcement before execution

Every prompt is checked before any model call.

Active now

Company policy upload and enforcement

Uploaded company policy packets shape the rules the workbench enforces.

Active now

Healthcare review gating

PHI, client identifiers, and review rules can block, pseudonymize, or pause a run.

Active now

Violation recording

Warnings, blocks, pseudonym actions, and evidence are stored automatically.

Org configured

Healthcare and legal execution path

Sensitive sectors stay under the strictest path.

PHI, client identifiers, consent, residency, review, and routing checks stay active on every outbound prompt and inbound response.

PHI detection with pseudonymization or redaction
Minimum necessary checks
Need-to-know sharing checks
Consent evidence checks
Research ethics checks
Clinical review gate
Role-based PHI access
Canadian residency lock
Session isolation for notes and memory
Approved-model routing

Stored records

The proof stays attached to the run.

Governance evidence includes policy application, pseudonym protection, review decisions, repeat prompts, and wrong-response reporting.

Audit log entries

Violation records

Prompt run records

Sector and geography targeting

Sector templates

Sector starters come as real, enforceable policy sets.

Topic restrictions, token budgets, model controls, uploaded company policies, and sector overlays ship ready to use.

Healthcare

enforceable

Clinical records, patient identifiers and health information.

  • Healthcare & Clinical — monthly token cap
  • Healthcare & Clinical — blocked keywords
  • Healthcare & Clinical — approved AI platforms
  • Healthcare & Clinical — Canadian residency lock
HIPAASOC 2 all 5PIPEDAAHS Alberta

Financial services

enforceable

Banking, investment, insurance and brokerage work.

  • Banking & Finance — monthly token cap
  • Banking & Finance — blocked keywords
  • Banking & Finance — approved AI platforms
OSFIFINTRACGLBASEC

Government and public sector

enforceable

Citizen records, classified material and public procurement.

  • Government & Public Sector — monthly token cap
  • Government & Public Sector — blocked keywords
  • Government & Public Sector — approved AI platforms
FedRAMPPrivacy ActATIP CanadaSOC 2

Legal

enforceable

Privileged matters, client files and litigation work.

  • Legal Services — monthly token cap
  • Legal Services — blocked keywords
  • Legal Services — approved AI platforms
Attorney-client privilegeSolicitor-client privilegeProfessional conductPrivacy law

Education

enforceable

Student records, assessment, and anything touching minors.

  • Education — monthly token cap
  • Education — blocked keywords
  • Education — approved AI platforms
FERPACOPPAStudent privacyAcademic integrity

Technology

enforceable

Source code, credentials, infrastructure and product data.

  • Technology — monthly token cap
  • Technology — blocked keywords
  • Technology — approved AI platforms
SOC 2GDPRCCPAColorado SB 24-205

General enterprise

enforceable

Everything else: people, retail, operations and supply chain.

  • General Enterprise — monthly token cap
  • General Enterprise — blocked keywords
  • General Enterprise — approved AI platforms
Privacy lawEmployment lawSOC 2Contractual confidentiality

See how your work is governed, then start in the workbench.

Need custom policy mapping or a sector rollout? We map it with you.