Deliverd Compliance Mode · AI governance in the work
Govern AI work
while it happens.
Compliance Mode adds ownership, risk, data classification, controls, human oversight and evidence to the same tasks your teams already use. It does not turn work into a compliance form. It makes governance part of the work itself.
Included in Business and Enterprise · MCP, REST, CLI and SDKs for TypeScript and Python
Know what the AI was asked to do, which system did the work, what data was involved, what evidence was produced, what the human decided, which controls applied and what actually happened.
How the work runs
Step by step
- 01
Register the AI systems
The assistants, agents and models you use: provider, purpose, owners, risk, data and oversight.
- 02
Govern the task
Name the system, the owners, the risk, the data and how people oversee it. The profile decides the controls.
- 03
Meet the controls
Evidence a reviewer can check, approvals a person gives, and exceptions with an owner and an expiry.
- 04
Ask before acting
The governance gate refuses while controls are outstanding, and says which.
- 05
Hand over the record
One evidence pack: the system, the profile, the controls, the evidence, the decisions and the timeline.
What it does
Everything on this page ships today
Each part names what an agent calls for it and the plans that include it.
An AI system register
The assistants, agents and models your organisation uses: provider, model, purpose, owners, environment, risk, data and oversight. A governed task names a system and is never rated lower than the system doing it.
- Plans
- Included in Business and Enterprise
- It calls
register_ai_systemlist_ai_systems
Governed tasks
A task's governance profile: the AI system, purpose, business and technical owners, risk, data classification, personal data, customers or production, autonomy and how people oversee it. Fill it in over time; an agent can govern work too.
- Plans
- Included in Business and Enterprise
- It calls
govern_taskcreate_governed_taskupdate_governance_profile
Controls from the profile
The profile decides which controls the work must meet. Risk adds an assessment; high risk adds a model evaluation, a security review and a compliance approval; personal data adds a privacy review. A riskier profile never removes one.
- Plans
- Included in Business and Enterprise
- It calls
get_required_controls
Evidence mapped to controls
Anything a reviewer can check — an assessment, test results, a review, a link. One item can satisfy several controls, so nothing is uploaded twice.
- Plans
- Included in Business and Enterprise
- It calls
submit_evidence
Approvals and exceptions
Approval controls are met only when a person approves them. An exception records why a control does not apply for now, who owns that decision, the risk accepted, what compensates and when it runs out — and is shown as waived, never as met.
- Plans
- Included in Business and Enterprise
- It calls
request_control_approval
The governance gate
Before deploying, sending or acting on governed work, an agent asks. Outstanding controls, an open reassessment, an overdue review or a serious unresolved incident mean not allowed, with the reasons named.
- Plans
- Included in Business and Enterprise
- It calls
check_governance_gate
The evidence pack
The AI system and profile, each control and how it was met, the evidence, the task graph, the decisions and who made them, the approvals and the audit timeline — with a sha256 digest so a copy can be checked against the one that left.
- Plans
- Included in Business and Enterprise
- It calls
get_evidence_pack
Framework packs and your own frameworks
Map controls to NIST AI Risk Management Framework, ISO/IEC 42001 AI management system, EU AI Act and UK AI regulatory principles, or write your own framework. A material change — a new model, a newer policy or framework version — calls for reassessment, and work is held to the version it was assessed under.
- Plans
- Included in Enterprise
- It calls
get_framework_mappingcreate_custom_frameworktrigger_reassessment
Deliverd helps organisations operationalise AI governance and create the evidence used to manage and demonstrate compliance. It does not certify compliance with any law, regulation or standard, and readiness is shown as controls complete, never as a legal percentage.
Questions
Compliance Mode and Deliverd.
Does Compliance Mode make us compliant?
No tool can. Deliverd records how AI work was governed — the system, the owners, the controls, the evidence and who decided — so your organisation can manage and demonstrate compliance. Framework packs are a starting point for your own review, not legal advice.
Which plans include it?
Compliance Mode is included in Business and Enterprise. Framework packs, your own frameworks, reassessment on material change and agent authority are included in Enterprise.
Can we start with Tasks and add Compliance Mode later?
Yes. Compliance Mode governs the tasks you already have; there is nothing to migrate to a different product.
What can an agent not do?
An agent can govern work, record what it learns, submit evidence and ask for an approval. It cannot lower a risk, weaken oversight, clear a fact that raised a requirement, retire a system or grant an exception — each of those would let a model grade its own oversight.
Can we try it on one real use case first?
Yes. The governed AI pilot runs one real AI use case through Tasks, gates and Compliance Mode for 30 to 45 days, with one business owner, one approval path and one evidence pack at the end. Ask us about it.
AI does the work. People make the calls. Deliverd keeps the record.
- Tasks— Stop losing the thread
- Gates and evidence— The agent says what it is about to do