Governed AI

An AI-operable security platform — governed by you, verifiable by design.

The Resilience Workbench is built to be operated by AI assistants as well as people: reading evidence, drafting analyses, and running workflows through an open standard. You choose when AI is enabled and what it may touch, and every action — AI or human — lands in an attributable, verifiable activity record protected by per-tenant encryption and cryptographic signing.

Your choice, not a default

AI access exists only after you enable it.

Off until opted inNo AI pathway into a tenant exists until a tenant administrator enables it. There is no background AI, no silent processing, and no vendor-side model reading your evidence.
Your assistant, your accountYou connect the AI assistant your organization already uses through an open standard, the Model Context Protocol. The assistant signs in through the same authorization service as a person — OAuth 2.1 with PKCE and step-up multi-factor authentication.
Permission by principal, tool by toolEach connected AI principal is registered with an explicit set of tools it may call, and rate limits per token. An assistant can be granted read-only reporting access, or scoped workflow access, and nothing more.
Revocable at any timeDisable the integration, revoke a token, or retire a principal and access ends immediately. Air-gapped on-premise deployments never call out at all — outbound channels fail closed by design.

How it works

An AI request passes the same gates a person does.

The browser is never the security boundary in this platform, and neither is an AI client. Every sensitive action is authenticated, tenant-scoped, server-validated, authorized, and audited — whoever, or whatever, asks.

01

Enable

A tenant administrator turns on governed AI access and registers the assistant as a principal with named tools.

02

Authenticate

The assistant completes OAuth 2.1 with PKCE, backed by step-up MFA, and receives resource-bound, rotating tokens.

03

Authorize

Every call re-enters the same server-side tenant and role authorization gates as a signed-in person. No bypass path exists.

04

Bound

Per-token rate limits and per-principal tool registration keep the assistant inside its granted scope.

05

Record

Each action is written to the audit trail, marked as AI-originated and attributed to the authenticated principal and token.

06

Review

Administrators see AI activity alongside all other platform activity, and can forward it to their own SIEM over TLS syslog.

Traceability

Every action leaves a record you can verify.

AI activity is auditable because everything in the platform is auditable. The same evidence discipline that makes the Workbench defensible for boards and auditors applies to every AI-originated action.

Attributed audit events

Platform and tenant audit logs record who acted, what changed, and when. AI-originated requests are explicitly marked as such and tied to the authenticated principal and token that made them.

Hashed evidence

Uploaded evidence is verified with SHA-256 digests server-side and stored with provenance, so what was analyzed is exactly what was collected.

Encrypted tenant state

Each customer's data lives in its own database with per-tenant key contexts and envelope encryption backed by a versioned keyring. AI access does not weaken the tenant boundary because it passes through it, not around it.

Cryptographically signed decisions

Board risk decisions are cryptographically signed, and briefings are invalidated when the underlying snapshot changes — a verifiable oversight record, not a meeting note.

Signed platform artifacts

Releases are immutable, digest-pinned images; on-premise images are Sigstore-signed with SBOMs; licenses and content updates are KMS-signed and verified before installation.

Signed outbound events

Workflow events delivered to your systems carry HMAC signatures, approved destinations, and delivery audit records, so downstream automation is verifiable too.

Why this stands out

Most platforms bolt on a chatbot. We built AI a security leader can say yes to.

The hard part of enterprise AI is not the model — it is governance. The Workbench treats AI as a first-class, least-privilege principal in a platform that was already built to prove who did what, when, and why. That is the difference, and it is enforced in the product, not promised on a page.

Your models, your choice

Bring the assistant and provider your organization trusts — connected through the open Model Context Protocol, an industry standard. Your evidence is never used to train models, and no AI touches your tenant until you decide it should.

Least-privilege AI, enforced server-side

Every AI principal holds exactly the access it was granted: registered tools, scoped tokens, rate limits, and the same tenant authorization gates as a person. Governed AI is a security feature here, not an add-on.

Human-governed decisions

AI accelerates the work; owners approve the outcome. Remediation stays planned, assigned, tracked, and validated with a documented approval record — the operating discipline regulators and boards expect.

An audit story your auditor will love

AI activity lands in the same verifiable record as everything else: attributed audit events, hashed evidence, encrypted tenant state, and cryptographically signed decisions. You can adopt AI and strengthen your compliance posture at the same time.

Governed AI access is delivered through the open Model Context Protocol with OAuth 2.1 authorization. AI assistance supports your team's judgment and documented owner review; it does not constitute legal, audit, or certification advice.

Put AI to work on your evidence — on your terms, on the record.

Talk to us about governed AI