Application governance
Governance applied to the service that provides governance advice.
Eight controls are embedded in the advisory process. Each exists because uncontrolled AI advice has a specific failure mode that the control prevents. These are application design decisions, not marketing language.
01
Source control
Advice is grounded in an approved source hierarchy. General model memory is not used as the evidential basis for a claim. Sources are declared in the output.
02
Scope control
Every question is assessed against defined in-scope and out-of-scope categories before analysis begins. Questions that require regulated professional advice are redirected, not answered.
03
Prompt-injection resistance
User-provided text and external source material are treated as untrusted inputs until assessed. The system does not allow user context to override advisory boundaries or source discipline.
04
Unsupported-claim control
Material claims are assessed against the evidence before the briefing is finalised. Claims without adequate source support are flagged, qualified, or removed.
05
Professional boundary control
Conrad does not present regulated professional advice as a final organisational position. Where a question approaches a professional boundary, the briefing identifies the boundary and recommends specialist advice.
06
Confidence control
Every response includes a confidence assessment derived from ten factors. Uncertainty is made explicit, not suppressed. Where confidence is medium or low, the briefing explains the specific reasons.
07
Human review control
Pilot responses are reviewed by a human operator before delivery. The reviewer can reject, revise, or add caveats. No briefing is delivered without a review sign-off during the pilot phase.
08
Auditability control
The intended future state records source discovery, evidence approval, prompts used, reviewer decisions, output versioning, and delivery history, so the basis for any briefing can be reconstructed later.