Governance & Audit

Controls in the path, not after it.

Policy, DLP, human-in-the-loop and audit live in the path of inference. Logs are written where the workload runs. A report generated after the fact is not governance.

Governance and audit in the path of inference

In-path

Policy before weights.

HITL

Consequential actions wait.

Immutable

Logs where the work runs.

Offline

Controls survive a pulled cable.

How a request is governed

1

Classify

The Gateway presents the request. Policy matches data class and caller.

2

Decide

Allow, redact, deny, or hold for a named approver.

3

Execute

Inference or tool call proceeds only on an allow. AgentLab waits on HITL for consequential steps.

4

Write

The decision, model version, caller and outcome are written to an immutable log on the same machine.

Controls that actually fire

Policy

Which model class may see which data class. Named rules, not tribal knowledge.

DLP

Fields that must not leave a document unmodified. Redaction is logged. Originals are preserved.

Human-in-the-loop

Consequential AgentLab actions wait for a named approver. Nothing silent posts to ERP.

Immutable audit

Written locally. Not a cloud SIEM you hope is reachable.

RBAC

Who may invoke, who may approve, who may read the log.

Disconnect

Pull the network. Policy still matches. Logs still write. Approvals still wait.

Governance surface

Policy

  • Data class
  • Model class
  • Caller role
  • Allow / deny / hold

The rule fires before the weight sees the prompt.

DLP & redaction

  • Field masks
  • Original preserved
  • Change log
  • Citation to source region

Modify is an application action. The audit of it is a Foundation duty.

Approvals

  • Named approver
  • Consequential tools
  • Rollback
  • Versioned prompts

AgentLab does not execute silent writes to systems of record.

Audit

  • Who
  • What
  • Which model
  • Which policy
  • Where written

The security pack lists the fields. The install writes them.

What this is not

After-the-fact is not enough

A weekly export from a SaaS console is a report. It is not a control.

Air-gap is the test

If governance requires a vendor cloud, it will fail the day the cable is pulled.

Applications inherit it

DocxIntel asks and AgentLab actions share the same policy engine.

Readable by legal

Licence list, audit fields and key custody are files. Not a slide.

The full stack on one machine, disconnected from the network.

In your office, on your documents, with the cable pulled out. No competitor's sales engineer can do this.

Start a conversation

Requirements

Share your requirement

Tell us what you need. We will reply by email. Book an offline demo when you are ready.

By sending, you agree to our privacy policy.