AnantState
Governance and control

The controls are in the product, not in the contract.

Governance that lives in a policy document is a promise. Here the rules are built into the product: who can see what, what every action records, and a check that refuses to let an unproven model make decisions.

In plain termsThe controls are enforced by the software, not left to people remembering the policy.

What is enforced, and where

ControlEnforced by
Tenant isolationRow-level security in the database, not application filtering
Role-based accessRole and workspace checked on every request
Single sign-onOIDC
Multi-factor authenticationMFA challenge on login
Directory provisioningSCIM
Action audit trailEvery action recorded with the acting user, tenant-scoped
Policy and rule governancePolicies and rules are versioned objects, not free text in a wiki
Limits and budgetsPer-domain limits and budget ceilings, evaluated by the platform
Model promotion gateRefuses on provenance, divergence, null-baseline and unmeasured-horizon checks
Override loggingA human may override a refusal; the override is attributed and recorded

Tenant isolation in the database. If isolation lives in application code, one missing filter is a cross-tenant leak. We push it into the database so the application’s failure mode is closed, not open.

A gate that can refuse. The promotion gate stops an unvalidated model from reaching production, and its refusals are recorded with reasons. See decision horizon.

The audit log: a compliance snapshot and the guard rails that blocked actions, including entities whose conflicting evidence holds autonomous actionFictional reference world: OgMart
Every blocked and held action is recorded with its reason, including actions held because the evidence conflicts.

What the platform is allowed to do, by edition

EditionPurposeContains
DemoEvaluation on a reference worldA built-in simulator and fictional reference worlds
BetaProduction-shaped operation without a simulatorReal sources only
EnterpriseRegulated, multi-tenant deploymentThe full governance surface

The simulator exists only in the demo edition. A production deployment cannot accidentally run a fictional world, because the edition gate removes the capability rather than the button.

What touches your systems

  • Read-mostly. Consuming events and reference data does not require write access to your production systems.
  • Explicit actions only. Any write to an external system goes through a named, audited action. There is no background write path.
  • Failed events are visible. Ingest failures land in a dead-letter view; they are not dropped silently.
  • Reversibility. Actions are recorded with their outcome, so an unintended action is a documented event with a known actor rather than an unexplained change.

Claims discipline

Authority is granted, not assumed

Every automatic action sits inside a grant you wrote, and the conflict gate can withdraw it.

Authority is granted per action class, within limits you set. When the evidence disagrees, the same action stops and asks a person.

Put your security reviewer in the room

A controls conversation is more useful than a document. Bring the questionnaire.