Compliance Mode
Govern AI work while it happens: which AI system did it, who owns it, what data it touched, the controls it was held to, the evidence, and who approved what.
Compliance Mode turns a task into a governed AI activity. Deliverd records what the AI was asked to do, which AI system did it, who owns the work, what data it touched, how people oversee it, the controls it was held to, the evidence produced, and who approved what. It is included in Business and Enterprise.
AI systems
Admin → Agent governance → AI systems is the register of the assistants, agents and models your organisation uses: provider, model, purpose, owners, environment, risk, data and oversight. A governed task names a system instead of describing it again, and takes the system's risk and environment — a task is never rated lower than the system doing it. Retiring a system keeps it on record, because governed work names it; only a person retires one.
Governing a task
On an objective's page, Govern this task records its profile: the AI system, purpose, business and technical owners, risk, data classification, whether it involves personal or sensitive data, customers or production, its autonomy and decision impact, and how people oversee it. You can fill it in over time. An agent can govern work too, over the MCP server, and side tasks are governed by their objective.
Owners and administrators can make every new objective governed on the AI systems page. A task governed that way cannot be made ungoverned.
Human oversight is one of these, from the weakest to the strongest:
- None
- Post-action review
- Sampled review
- Human on the loop
- Human in the loop
- Approval before action
- Two approvals before action
Controls
The profile decides which controls the work must meet. Every governed task records its purpose, AI system, business owner, data classification and oversight. Risk adds an assessment; high risk adds a model evaluation, a security review, a technical owner and a compliance approval; personal data adds a privacy review; production use adds a deployment approval; and so on. Raising the risk or adding a fact adds controls — they are never removed by a riskier profile.
| Control | Area | Met by |
|---|---|---|
| Purpose documented | Purpose & intended use | Recording it on the profile |
| AI system identified | Governance & accountability | Recording it on the profile |
| Business owner assigned | Governance & accountability | Recording it on the profile |
| Data classified | Data governance | Recording it on the profile |
| Human oversight defined | Human oversight | Recording it on the profile |
| Technical owner assigned | Governance & accountability | Recording it on the profile |
| Risk assessment | Risk management | Evidence |
| Privacy review | Privacy | Evidence |
| Security review | Security | Evidence |
| Model evaluation | Testing & evaluation | Evidence |
| Transparency to affected people | Transparency | Evidence |
| Human review recorded | Human oversight | Evidence |
| Agent authority defined | Agent authority | Evidence |
| Compliance approval | Governance & accountability | An approval |
| Deployment approval | Deployment | An approval |
- Evidence is anything a reviewer can check: an assessment, test results, a review, a link. One item can satisfy several controls, so nothing is uploaded twice. Evidence added on a side task remembers it came from there — an investigation's result is the evidence for the control it was opened to meet.
- Approval controls are met only when a person approves them, through the ordinary approval process.
- Waiving says a control does not apply here, with a reason. Only a person can, it is recorded in their name, and it is shown as waived — never as met.
What agents may and may not do
- An agent can govern work, record what it learns — a higher risk, personal data it found — submit evidence, and ask for an approval.
- An agent cannot lower a risk, weaken oversight, clear a fact that raised a requirement, retire a system or waive a control. Each of those would let a model grade its own oversight, so each is a person's decision.
- Before deploying, sending or acting on governed work, an agent asks the governance gate. If controls are outstanding the answer is not allowed, with the controls named, and the agent stops.
The evidence pack
Evidence pack on a governed task's page (owners and administrators) assembles the whole record: the AI system and profile, the controls and how each was met, the evidence, the task graph with what each side task found, the decisions and who made them, the approvals, and the audit timeline — with a sha256 digest, so a copy can be checked against the one that left. It assists audit; it does not certify anything, and says so on its first page.