Guide

A data intelligence platform for enterprise teams

The phrase is used for several different products. This page says what we mean by it, what the Swfte Intelligence Platform does today, what it is designed to do, and the questions to put to any vendor.

Last reviewed 6 October 2026

The short answer
A data intelligence platform joins an organisation’s data to a model of what that data means: who owns it, where it came from, how fresh it is and how sure anyone is about it. People and AI agents can then ask questions and act on the answers. The Swfte Intelligence Platform is built around a customer-hosted graph of your organisation. Today that graph is built from directory sources: Active Directory and LDAP, Microsoft Entra ID, Okta and Google Workspace. Other sources are designed for, and are labelled that way below.
Definition

What “data intelligence platform” means

The phrase has no fixed meaning. Vendors use it for at least three different things, and it helps to know which one you are being sold.

The first is a data platform with AI added: a warehouse or lakehouse where you store and process data at scale, with natural-language query and agents on top. The second is enterprise search: a layer that reads your documents and applications and answers questions across them. The third is an operational model of the organisation: a structured picture of people, systems, ownership and decisions that AI can use as context.

Swfte’s product sits in the third group. It is not a warehouse, and it does not replace one. It holds a time-aware graph of the organisation, with every fact carrying an evidence status, and it is designed to let analysts ask questions of that graph and to let teams build agents and workflows from what they find.

What it has to do

Six things a data intelligence platform has to do

Whatever the product, these are the tests we would apply. They are the same questions the buyer guide uses to compare vendors.

  • Reach the data you actually have. A platform that answers well over a single source and cannot connect to the rest is a demo.
  • Say how sure it is. An answer without its source, its age and its confidence is an assertion.
  • Respect who is asking. The answer should be limited to what the person asking is allowed to see, and an agent should never hold more access than the person who started it.
  • Run where your policy says it may run. That means your own cloud account, a private network, or an environment with no outbound connection, if your rules require it.
  • Let you act, not just look. Insight that cannot become an agent, a workflow or a decision is a report.
  • Leave a record. Who asked, what was read, what was decided and what was done should be traceable afterwards.
How Swfte does it

A customer-hosted, time-aware graph with evidence on every fact

Underneath the Swfte Intelligence Platform is Swfte Enterprise Intelligence, a customer-hosted appliance. It keeps an insert-only history of facts about your organisation, so you can read the graph as it was at an earlier date. Accounts across directories are resolved into people, and the evidence for each resolution is kept on the link.

Every fact carries one of seven evidence statuses: observed, corroborated, verified, inferred, stale, disputed or unknown. The platform is designed to show the difference. A fact that two sources agree on is treated as stronger than one seen once. A fact that sources dispute is shown as a conflict, not averaged away. A fact with no evidence is shown as unknown, and the platform does not fill the gap with a guess.

The local API is token-scoped, and the tenant is always taken from the credential and never from the request. Row-level security separates tenants. The audit log is hash-chained and anchored by signed checkpoints, so a break in the chain can be detected.

Where it runs

Connected, private or air-gapped

The appliance can run in three modes, and the mode is a configuration you can inspect rather than a promise in a contract.

  • Connected: the appliance runs in your environment and links outbound to the Swfte control plane. Health counts, coverage summaries, diagnostics and command results can leave. Personal and restricted data stay where they are.
  • Private: the same link behaviour, pointed at a control plane that you host yourself.
  • Air-gapped: no outbound connection at all. The link is never started, and updates arrive on signed media that is verified against a key pinned on the appliance.
Install routeWhat it is
Virtual machine with DockerA hardened container image and an installer with verify and uninstall scripts, for a single host.
Kubernetes with HelmA Helm chart for clusters you already run, with a migration job that runs under separate credentials.
Air-gappedAn install route for environments with no outbound access.
These are described as built on the intelligence platform page. Remote commands are signed, typed and limited to an allow-list that you set.
Acting on it

From a finding to a governed agent or workflow

The intent is a closed loop: connect data, analyse, visualise, decide, build, govern, measure and learn. A finding such as a spend anomaly, a repeated support pattern or a rise in policy denials is meant to become the starting point for an agent or a workflow, with its owner and approver taken from the graph.

Agents and workflows are built in Studio, Cortex and Nexus. They are designed to read organisational context from the graph and to act only through typed, approved and audited capabilities. That wiring is on the roadmap, and the table at the end of this page says so. What exists today is the graph, its API, the outbound link and the packaging.

New agents start at L1 Assist or L2 Approve. Autonomy rises by level as the record shows an agent has earned it, and consequential actions wait for a named approver.

Limits

Where this is not the right tool

We would rather say this plainly than let you find it in a pilot.

  • It is not a data warehouse or lakehouse. If your problem is storing and transforming large analytical datasets, you need one of those, and the Swfte platform is designed to work with the data rather than replace the store.
  • It is not a dashboard or business intelligence replacement today. The data behind graph views is served by the local API, but the views themselves are design intent, and named dashboards and chart types are not published yet.
  • It is not yet enterprise search over documents and business systems. Those sources are designed for, and the connector list beyond directory sources is open: <connector list beyond directory sources - founder to fill>.
  • Pricing and availability are not published. <pricing - founder to fill> <availability - founder to fill>
Buying guidance

Questions to put to any vendor

Ask these in writing and compare the answers side by side. The buyer guide applies the same questions to named vendors, using only what each publishes.

  • Which sources does it read today, and which are on a roadmap? Ask for the list with dates and a named owner.
  • Where does the data live while it is being processed, and what leaves the environment in each deployment mode?
  • How does it represent uncertainty? Ask to see a disputed or stale fact in the product.
  • Can an agent hold more access than the person who started it?
  • What is the unit of pricing, and what does a month of heavy use cost? A figure on a published page is better than a quote in an email.
  • What does exit look like? Ask how you would get your data and configuration out, and in what format.
Honest labels

What is built and what is designed for

This table is the same one that appears on the Swfte Intelligence Platform page. If it disagrees with the product, the table is wrong and we would like to hear about it.

CapabilityStateNote
Directory sources: Active Directory / LDAP, Microsoft Entra ID, Okta, Google WorkspaceAvailablePeople, groups, reporting lines and accounts, read with a read-only account. Passwords and credentials are never read or stored.
Identity resolution into people and org structureAvailableAccounts across directories are resolved into people, with the resolution evidence kept on the link.
Time-aware graph storeAvailableInsert-only history, as-of reads, evidence statuses on facts, tenant isolation and a hash-chained audit log.
Local API for graph, people, groups, coverage and auditAvailableToken-scoped, with the tenant always taken from the credential, never from the request.
Outbound link: enrolment, mutual TLS, signed commands, kill switch, outbox, signed updatesAvailableCustomer-killable, and absent entirely in air-gapped mode.
Packaging: container image, installer, Helm chartAvailableVirtual machine with Docker, Kubernetes via Helm, and an air-gapped route.
Pre-model sanitisation gatewayIn developmentDesigned to clean content before it reaches a model.
Cloud, code, CI/CD, Kubernetes and database collectorsDesigned forOn the roadmap. This is what lets the graph answer who owns a service, not only who a person is.
SaaS, business-system and document sourcesDesigned forOn the roadmap. <connector list beyond directory sources - founder to fill>
Context-package API and MCP serverDesigned forOn the roadmap. Designed so an agent can ask for the context it is allowed to have.
Action gateway with approvalsDesigned forOn the roadmap. Designed so agents act only through typed, approved and audited capabilities.
Production control planeDesigned forOn the roadmap.
Cloud marketplace deliveryDesigned forOn the roadmap. <marketplace listings - founder to fill>
Wiring into Cortex, Nexus, Studio and the Nexus harnessDesigned forOn the roadmap. Each is designed to read organisational context from the graph.
Graph explorer, org and ownership maps, as-of timelines, coverage and evidence viewsDesigned forThe local API already serves the data these views read: the subgraph, as-of reads, coverage and evidence. The views themselves are design intent.
Available means it is described on the Swfte product pages today. Designed for means architectural intent, not something to rely on yet.

Common questions

What is a data intelligence platform?
Software that joins an organisation’s data to a model of what the data means, including ownership, source, age and confidence, so that people and AI agents can ask questions and act on the answers under governance. The term is used loosely, so ask a vendor which of the three meanings it intends.
How is it different from a data warehouse or lakehouse?
A warehouse or lakehouse stores and processes data at scale. A data intelligence platform in Swfte’s sense holds a structured, evidence-backed picture of the organisation and is designed to work with the stores you already have. It does not replace them.
What does the Swfte Intelligence Platform connect to today?
Directory sources: Active Directory and LDAP, Microsoft Entra ID, Okta and Google Workspace. Cloud, code, Kubernetes, database, SaaS and document sources are designed for and on the roadmap.
Where does my data live?
In your environment. The appliance runs on a virtual machine, on Kubernetes, or air-gapped. Personal and restricted data are local-only by default, and secrets and credentials are never stored.
Does the platform send my data to Swfte?
In connected mode it sends health counts, coverage summaries, diagnostics and command results over an outbound link that you can cut with a local kill switch. In air-gapped mode nothing leaves.
Is it compliant?
We do not claim that, and no platform can on its own. It is built for compliance-by-design: it provides technical controls, governance mechanisms and evidence for deploying AI within your regulatory, security and policy requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration.
How much does it cost and when is it available?
<pricing - founder to fill> <availability - founder to fill> Talk to our team for the current position.

Ready to build with Swfte?

One platform for the agents, models and workflows your team ships. Free to start, no card required.