Governance

Governance you configure once — not a spreadsheet you maintain forever.

Three EU AI Act–style risk wizards generate scored, narrative documentation as you configure the platform. Suitable for board packs and regulator responses. Updated automatically in the change log.

WIZARD

AI Model Risk Wizard

/admin/ai-model-risk-wizard/
01 Purpose answered
02 Data sensitivity answered
03 Individual impact answered
04 Human oversight answered
05 Testing & governance answered
Output
Low / Moderate / High / Very High + narrative
COMPUTED RISK
LOW
MODERATE
current score
HIGH
VERY HIGH
Narrative (excerpt)

Deployment uses a high-quality third-party foundation model with human-in-the-loop review for sensitive outputs. PHI-class data is de-identified before inference. Disallowed lists enforce HIPAA-aligned content blocking. Mitigations reviewed quarterly; last review logged 2026-03-12 by ciso.admin.

auditor-visible simple-history versioned
Roles

Four built-in roles. Read-only auditor by design.

User

Start chats, upload to collections, view own history, use published chatbots.

Org Admin

Users, models, filters, wizards, chatbots, logs. Cannot view other orgs.

Auditor

Read-only review of moderation logs, audit log, validation scores. Cannot modify.

Superuser

Platform-wide. Dataset management, cross-org dashboards, training.

EU AI Act ACT-2024/1689 · HIGH-RISK TIER
NIST AI RMF AI-RMF-1.0
SOC 1 Type II AICPA-SOC1-TYPEII
HIPAA HIPAA-ALIGNED
GDPR GDPR-2016/679