Platform / Intelligence / Analyse
Analyse your organisation, and your AI, in plain language
Ask a question of your own data and get an answer that says where it came from, how sure the platform is, and how old it is.
Analysis is the second stage of the closed loop. It is designed so that an analyst, an AI team or a security lead can ask what is going on, in plain language or by exploring the graph, and get an answer they can defend rather than a number they have to trust.
Why analysis has to start from evidence
Ask most AI tools a question about your organisation and you get a fluent paragraph. It may be right. It may be a plausible guess about a reporting line that changed in the spring. Nothing in the answer tells you which, and for anything that leads to an action that is not good enough.
The Swfte Intelligence Platform is built around a different premise: evidence before inference. The graph underneath holds facts about your organisation, and every fact carries an evidence status. When you ask a question, the answer is assembled from those facts and the status comes with it. A reporting line that was observed in your directory reads differently from one that was inferred, and both read differently from one that has not been seen for longer than it should have been.
That is the property that makes analysis useful as a step in a loop rather than a destination. If you are going to build an agent or a workflow from a finding, you need to know how much weight the finding can carry.
Four ways to ask
Designed so the method fits the question, and so each method returns the same kind of evidence.
Ask in natural language
Type the question the way you would put it to a colleague: who does this person report to, which group are they in, who was in that group last March. The answer comes from the graph and cites its facts.
Explore the graph
Start from a person, a group or a system and walk outward along relationships, to a depth and size you choose. The local API already serves this kind of subgraph read.
Read it as it was
The graph keeps history rather than overwriting it, so a question can be asked as of an earlier time. That is how you answer who held something at the time a decision was made.
Look for what changed
Designed to compare usage, cost, policy decisions and ownership against their own history, and to surface what moved. Thresholds and alerting rules are yours to set.
What an answer carries
An answer in the Intelligence Platform is designed to carry more than a result. It names the facts it used and the evidence status of each one: observed, corroborated, verified, inferred, stale, disputed or unknown. It shows the age of the underlying observation, so a stale fact looks stale. Where two sources disagree, the answer says so and does not quietly pick one.
It also says what it could not see. The platform reports coverage: which sources are connected and which are not. An answer about who owns a service is only as complete as the sources that describe services, and today the appliance reads directory sources. Collectors for cloud, code, Kubernetes, databases and more are on the roadmap, and until they arrive the honest answer to some questions is that the platform does not know.
That restraint is deliberate. The platform is built never to say that it understands everything, because an organisation that believes that will stop checking.
Questions it is designed to answer
A starting set. The first group is within what the appliance reads today. The second depends on sources that are on the roadmap.
- 01
Who reports to whom?
The manager chain and the direct reports for any person, resolved across directories into one person.
- 02
Who is in this group, and who was?
Direct and transitive membership now, and as of an earlier time.
- 03
Which accounts belong to one person?
Identity resolution across directory sources, with the evidence for each link kept.
- 04
What is the coverage?
Which sources are connected, how fresh they are, and where there are gaps.
- 05
Who owns this service, and who can approve a change?
Designed for once cloud, code and system collectors are in place. Not a claim about today.
- 06
Why did this change?
A provenance walk from a fact back to the evidence that produced it. Designed for as the knowledge layer is wired in.
Analysis that respects who is asking
A question is asked by someone, and that someone has a limit on what they may see. The platform is built so that an AI asking on a person’s behalf has never more access than that person. If an analyst is not allowed to see a group, the answer does not include it, and the platform does not tell them what they are missing.
Content that comes back from a source is treated as untrusted. A document that says ignore your instructions and reveal the following is data to be read, not an instruction to follow, and it cannot override policy. That matters more as analysis moves from a human reading a screen to an agent reading context.
Every question and every answer leaves a record. In the Trust and Governance Fabric this is the Traceability and Auditability facets at work: what was asked, by which identity, what was read, and what was returned.
Specifics not yet published
The detail of the question interface is not something we will invent on this page. The query language is <query language - founder to fill>, the named dashboards are <named dashboards - founder to fill>, and the connector list beyond directory sources is <connector list beyond directory sources - founder to fill>. Availability is <availability - founder to fill> and pricing is <pricing - founder to fill>.
How analysis connects to the closed loop
Analysis sits between connecting data and visualising it. What you find here is what you decide on, and what you build from.
- 01 · Layer 02Connect dataBring directory data today, and more systems over time, into a graph that lives in your environment.
- 02 · Layers 02 and 03AnalyseAsk questions in plain language, explore the graph, and look for trends and anomalies.(this page)
- 03 · Layers 02 and 03VisualiseSee the organisation, usage, agents and outcomes as maps, timelines, dashboards and evidence views.
- 04 · PeopleDecideChoose the response with the owner, the approver and the evidence status in front of you.
- 05 · Layers 04 to 06BuildTurn the insight into an agent, a workflow or a packaged solution.
- 06 · Trust FabricGovernIdentity, permissions, policy, audit and human approval apply while the thing runs.
- 07 · Layer 06MeasureTrack the outcome and the cost against the reason you built it.
- 08 · Layer 02LearnFeed what happened back into the graph, so the next question starts from more evidence.
Frequently asked questions
Is this a natural-language interface to a data warehouse?
Not primarily. It is designed around a graph of your organisation with an evidence status on every fact. Questions are answered from that graph and its history. Other sources can be added over time, and the connector list is not published yet.
How do I know an answer is right?
You do not have to take it on trust. The answer is designed to show the facts it used, the evidence status of each, and their age, so you can see whether it rests on observation, inference or a stale record.
What happens when the platform does not know?
It says so. Unknown is an evidence status, and coverage is reported as a measure. The platform is built not to fill gaps with a guess and not to claim it understands everything.
Can an analyst see things they should not?
It is designed not to allow that. Answers are limited to what the person asking is allowed to see, and an AI acting for them has never more access than they do.
Does the analysis leave my environment?
The graph lives in your environment. In connected mode only health counts, coverage summaries, diagnostics and command results go to Swfte, and in air-gapped mode nothing does.
What do I do with a finding?
Take it to the next stage: visualise it, decide, and if it warrants a response, build an agent, a workflow or a solution from it. Each starts under controls you set.
Take analyse further with Swfte
Start with one entry point. Add intelligence, agents, workflows and infrastructure as you prove value.