Enable
A tenant administrator turns on governed AI access and registers the assistant as a principal with named tools.
Governed AI
The Resilience Workbench is built to be operated by AI assistants as well as people: reading evidence, drafting analyses, and running workflows through an open standard. You choose when AI is enabled and what it may touch, and every action — AI or human — lands in an attributable, verifiable activity record protected by per-tenant encryption and cryptographic signing.
Your choice, not a default
How it works
The browser is never the security boundary in this platform, and neither is an AI client. Every sensitive action is authenticated, tenant-scoped, server-validated, authorized, and audited — whoever, or whatever, asks.
A tenant administrator turns on governed AI access and registers the assistant as a principal with named tools.
The assistant completes OAuth 2.1 with PKCE, backed by step-up MFA, and receives resource-bound, rotating tokens.
Every call re-enters the same server-side tenant and role authorization gates as a signed-in person. No bypass path exists.
Per-token rate limits and per-principal tool registration keep the assistant inside its granted scope.
Each action is written to the audit trail, marked as AI-originated and attributed to the authenticated principal and token.
Administrators see AI activity alongside all other platform activity, and can forward it to their own SIEM over TLS syslog.
Traceability
AI activity is auditable because everything in the platform is auditable. The same evidence discipline that makes the Workbench defensible for boards and auditors applies to every AI-originated action.
Platform and tenant audit logs record who acted, what changed, and when. AI-originated requests are explicitly marked as such and tied to the authenticated principal and token that made them.
Uploaded evidence is verified with SHA-256 digests server-side and stored with provenance, so what was analyzed is exactly what was collected.
Each customer's data lives in its own database with per-tenant key contexts and envelope encryption backed by a versioned keyring. AI access does not weaken the tenant boundary because it passes through it, not around it.
Board risk decisions are cryptographically signed, and briefings are invalidated when the underlying snapshot changes — a verifiable oversight record, not a meeting note.
Releases are immutable, digest-pinned images; on-premise images are Sigstore-signed with SBOMs; licenses and content updates are KMS-signed and verified before installation.
Workflow events delivered to your systems carry HMAC signatures, approved destinations, and delivery audit records, so downstream automation is verifiable too.
Why this stands out
The hard part of enterprise AI is not the model — it is governance. The Workbench treats AI as a first-class, least-privilege principal in a platform that was already built to prove who did what, when, and why. That is the difference, and it is enforced in the product, not promised on a page.
Bring the assistant and provider your organization trusts — connected through the open Model Context Protocol, an industry standard. Your evidence is never used to train models, and no AI touches your tenant until you decide it should.
Every AI principal holds exactly the access it was granted: registered tools, scoped tokens, rate limits, and the same tenant authorization gates as a person. Governed AI is a security feature here, not an add-on.
AI accelerates the work; owners approve the outcome. Remediation stays planned, assigned, tracked, and validated with a documented approval record — the operating discipline regulators and boards expect.
AI activity lands in the same verifiable record as everything else: attributed audit events, hashed evidence, encrypted tenant state, and cryptographically signed decisions. You can adopt AI and strengthen your compliance posture at the same time.
Governed AI access is delivered through the open Model Context Protocol with OAuth 2.1 authorization. AI assistance supports your team's judgment and documented owner review; it does not constitute legal, audit, or certification advice.