For financial services

Risk wants an inventory.
Hand them the record.

Firms are approving AI assistants and agents several at a time, and risk and compliance ask the same questions of each: what is in use, who owns it, what data it touches, and where a person stays in charge. Deliverd sits around the tools already in use rather than replacing them. Agents ask before they act, a named person decides, and the register, the controls and the evidence build up as the work happens.

No card required · Unlimited readers · Secure by default

The situation

What this looks like today

Every new AI tool starts a new review

An assistant for one desk, an agent for another, a model inside a vendor's product. Each is reviewed on its own from a blank questionnaire, and by the fifth nobody can say in one place what is in use, for what, and with whose data.

Oversight that lives in a policy document

The policy says a person reviews what the AI does. What the firm can show is a meeting note and a screenshot — not who decided, on what, and when.

Evidence assembled after the fact

When an auditor or a regulator asks, somebody spends a week rebuilding the story from mailboxes and tickets. The record should exist because the work happened, not because somebody asked for it.

What changes

Deliverd for financial services

Everything below ships today. Where something needs a paid plan, it says so.

Your AI asks before it acts

An agent that needs a decision puts it to a named person and waits: what it wants to do, why, how risky it is, and what to read first. They approve, approve with changes, reject with a reason, or ask the agent a question — on the page, from an email link, in Slack or Teams, or from a push notification on a phone — and a colleague can cover their approvals while they are away. It can also ask for a review, or for information it is missing, the same way.

A check before the agent acts

Before a consequential action — a payment, a deployment, a message to a customer — the agent declares what it is about to do and waits for the answer. A named person decides, or your organisation's rules settle the routine cases and send the rest to a person; with no rules, every one goes to a person. Afterwards the agent records what ran, and the record is checked against what was allowed.

On every plan; policy rules included in Business and Enterprise

Governance recorded as the work happens

Compliance Mode adds a register of the AI systems you use and, on governed work, the owners and the risk and data classification. That profile decides the controls: evidence or a person's approval meets each one, and an exception, with an owner and an expiry, shows as waived rather than met. The whole record exports as one evidence pack. It records how the work was governed — it does not certify compliance with any law or standard.

Included in Business and Enterprise

One pack for the auditor

Every step of a piece of work — who was asked, what they said, what was decided and when — exported as a single timeline in JSON, CSV or PDF. It carries a digest so an altered copy can be told apart, and the export itself is on the record.

The work keeps its objective

A task holds what the work is for apart from the conversation doing it, with a short state — where it stands, the next action, what is in the way — that any agent reads when it resumes. Side tasks take a bug or a piece of research out of the main thread and come back with a result. Switch tool or model and the next one picks up where things stand instead of starting over, and only a person changes the objective.

Included in Team, Business and Enterprise

A second thought, where it matters

Your organisation writes rules for requests that touch someone's job, money, health or privacy, or that cannot be undone. When one matches, whoever decides sees the concern first and has to say why it is right to go ahead; a rule can also ask more people to agree, or refuse. Ethics rules only add oversight — none of them can approve anything — and they are on every plan.

Your AI cannot publish to the world

An agent identity can never grant public access — that is refused at the service, not hidden in the UI — and can be confined to named workspaces and audiences. Every refusal is written to the audit trail.

Rules your firm sets once

Publishing policies run on every publish and share: no external sharing for a classification, a ceiling on how long a link may live, a workspace that must be named. A tester shows what a publish would do before anyone tries it.

A record of who opened it

Views, versions, access changes and share links are written to an audit trail you can export — which is the difference between believing a client saw something and being able to show it.

A workspace per client

Segment who can reach what, so an analyst on one engagement cannot browse another. Access is decided per report and evaluated on every request, assets included.

When deletion has to stop, it stops

A matter opens and routine destruction becomes the wrong thing to do. Place a hold and the retention schedule suspends, the organisation cannot be closed, and a report’s data cannot be deleted — refused in the database, not by a setting somebody has to remember. Released with a reason, and both ends are on the record.

Included in Enterprise

A finished flow, Q3 claims close: a request, a review and a report, a timeline of who asked, answered, asked for changes, approved and published, and its evidence pack as PDF, JSON or CSV.

Questions

Financial services and Deliverd.

Does this replace the AI tools we have already approved?

No. Deliverd sits around them. Assistants and agents reach it over the MCP server, the REST API, the CLI or the TypeScript and Python SDKs, and the TypeScript SDK has adapters for the Claude Agent SDK, the AI SDK, the OpenAI Agents SDK and LangGraph. The tools your teams use keep doing the work; what changes is that they ask a person, and that the asking is on the record.

Can we give risk and compliance an inventory of the AI in use?

Yes, with Compliance Mode, included in Business and Enterprise. The AI system register lists the assistants, agents and models your organisation uses — provider, model, purpose, owners, environment, risk, data and oversight — and each governed piece of work names the system doing it and is never rated lower than that system. It lists what you register; it does not go looking for tools on its own.

Who decides when an agent wants to act?

A named person, unless your organisation has written a rule that settles it. The agent declares what it is about to do and waits. Policy rules, included in Business and Enterprise, permit the routine cases, refuse others and send the rest to one person or two; only an owner or an administrator writes them, and an agent cannot. A gate is advisory: the agent asks and then acts itself, and the execution record shows whether what ran matches what was allowed.

Does Compliance Mode make us compliant?

No tool can, and we will not say otherwise. Deliverd records how AI work was governed — the system, the owners, the controls, the evidence and who decided — so your firm can manage and demonstrate compliance. Framework packs map controls to NIST AI Risk Management Framework, ISO/IEC 42001 AI management system, EU AI Act and UK AI regulatory principles as a starting point for your own review, not legal advice; they are included in Enterprise.

Where is our data, and which certifications do you hold?

Your data is stored in London. We do not hold SOC 2 or ISO 27001 certification, and our security page says so rather than implying otherwise. A data processing agreement under Article 28 of the GDPR is available on request.

Can a request touching someone's credit get a second look?

Yes. The starter ethics rule “Credit, housing and insurance” flags requests about loans, credit limits, mortgages and underwriting, and asks whoever decides to check that nothing like age or postcode is standing in for a protected characteristic. “Messages sent in someone else's name” asks whether a customer would be misled about who wrote a message or what it commits to. They arrive switched off; once on, a flagged approval needs a reason before it goes ahead.

The record should exist because the work happened.

Keep the AI tools your teams already use, put each decision in front of the person who owns it, and hand risk and compliance the record rather than a reconstruction.