Trust and governance fabric

Governance that runs inside AI

Governance happens inside AI. Policy changes what the agent can actually do.

The trust and governance fabric runs through all six layers. It is not a seventh layer and not a document set. It is designed as the runtime layer that decides what AI may do, records what it did and lets you prove it. Policy enforcement is live today for runs that have a policy attached; the rest is designed for.

Thirteen facets of the fabric

These apply to every layer, from infrastructure to solutions.

  • Identity
  • Access
  • Data controls
  • Policy
  • Security
  • Privacy
  • Compliance
  • Risk
  • Human oversight
  • Auditability
  • Traceability
  • Evidence
  • Monitoring

What each facet does

  • Identity

    Every user, agent and workflow acts as a known identity.

  • Access

    Permissions scoped to each identity, tool and data source.

  • Data controls

    Classification, residency and boundaries applied to what AI can read and write.

  • Policy

    Rules that change what an agent can actually do, not what a document says it should do.

  • Security

    Protection for the runtime, credentials and tool connections AI depends on.

  • Privacy

    Handling of personal and sensitive data in prompts, context and outputs.

  • Compliance

    Technical controls and evidence, built in by design, for your own regulatory requirements.

  • Risk

    Risk levels and thresholds that decide what needs approval.

  • Human oversight

    Approval, escalation and review points where people stay in charge.

  • Auditability

    A record of what happened and under which policy.

  • Traceability

    The chain from data to model to agent to decision to action to outcome.

  • Evidence

    Records you can hand to a reviewer, an auditor or a regulator.

  • Monitoring

    A live view of behaviour, cost and policy decisions.

Runtime, not paperwork

A policy that lives in a PDF changes nothing about what an agent does at two in the morning. On this platform, governance is designed to be enforced inside the AI runtime: a policy change alters what the agent can actually do, on the next action.

The traceability chain makes that checkable: data, then model, then agent, then decision, then action, then outcome. Each link is recorded, so a result can be followed back to its causes.

Guardrails and governance are different questions

Guardrails answer: should this be blocked? Governance answers: who is acting, allowed to do what, under which policy, with which data, using which model, at what risk, with what oversight, and can we prove it? A governance decision is one of six verbs.

  • Allow

    The action is within policy and proceeds.

  • Deny

    The action is outside policy and is stopped.

  • Warn

    The action proceeds, and the risk is flagged to the right people.

  • Filter

    The action proceeds with sensitive content removed or masked.

  • Escalate

    The action is routed to a person or team with authority to decide.

  • Require human approval

    The action waits until a named approver says yes.

A Trust Profile for every AI system

The Trust Profile is a design concept: one record per AI system that states what it is and what it may do. Today these controls exist as separate parts of the platform (policy engine, approvals, run ledger) and are not yet joined into a single record. The profile is designed to hold:

  • Identity
  • Owner
  • Risk level
  • Approved models
  • Data classification
  • Data residency
  • Permitted systems
  • Allowed actions
  • Restricted actions
  • Human approval rule
  • Retention
  • Audit
  • Policy set

Worked example: an AI Procurement Agent

One agent, four lists. The agent’s authority is explicit, and so is the evidence it leaves.

AI Procurement Agent

Can

  • Read approved supplier info
  • Analyse contracts
  • Compare pricing
  • Prepare purchase recommendations
  • Create draft POs

Cannot

  • Access unrelated employee data
  • Approve its own high-value transaction
  • Make payments
  • Modify restricted records

Requires approval

  • Purchases above threshold
  • Contractual changes
  • Sensitive external comms

Records

  • Identity
  • Data accessed
  • Model used
  • Output
  • Tools called
  • Policy applied
  • Decision
  • Approval
  • Action
  • Outcome

Compliance-by-design

Swfte provides the technical controls, governance mechanisms and evidence required to deploy AI within an organisation's applicable regulatory, security and policy requirements. The exact posture depends on the customer's use case, jurisdiction, deployment and configuration.

Compliance-by-design means the controls and evidence are part of how the platform runs, so your teams can use them in their own EU AI Act, security and policy work. It does not mean that using the platform satisfies your obligations on its own. For what Swfte can and cannot show today, read the trust centre.

Where this sits in the closed intelligence loop

Control, then intelligence, then agency, then execution, then outcomes. Outcomes and their evidence flow back into data and context, so the loop closes.

  1. 01 · Layer 01ControlDecide where and how AI runs.(this page)
  2. 02 · Layers 02 and 03IntelligenceTurn data and knowledge into useful intelligence.(this page)
  3. 03 · Layer 04AgencyLet AI act within defined authority.(this page)
  4. 04 · Layer 05ExecutionEmbed that action in how the organisation operates.(this page)
  5. 05 · Layer 06OutcomesMeasure business results, and feed evidence back into data and context.(this page)

Governance is present at every stage of the loop. It is what turns AI that acts into AI you can account for.

Where Swfte products take part

Product names are kept. Each is an entry point into the platform.

  • Nexus

    Captures every agent action, enforces policy in-flight and traces every agent and connection.

  • Cortex

    Answers from your files and meetings, runs on the laptop by default, and puts engineers’ AI agents under one policy and one audit trail.

  • Studio

    Build agents, chatflows and automations without code.

What this means for your team

CISO
Give AI identity, permissions, policies and auditable controls.
Legal / Compliance
Make AI activity traceable, governed and evidential.
Chief AI Officer
Move from AI experiments to governed production AI.

Frequently asked questions

What is an AI governance platform?

A platform that controls what AI systems may do and records what they did. On Swfte that means identity, access, policy, risk thresholds, human oversight, auditability, traceability and evidence, designed to work at runtime across every layer.

What is the difference between guardrails and governance?

Guardrails decide whether an output or action should be blocked. Governance covers who is acting, what they may do, under which policy, with which data and model, at what risk and with what oversight, and whether it can all be proved.

Does Swfte cover our EU AI Act obligations?

No platform can discharge an organisation’s obligations by itself, and we do not claim it. Swfte provides technical controls, governance mechanisms and evidence that support your own programme. The exact posture depends on your use case, jurisdiction, deployment and configuration.

What is compliance-by-design?

Building controls and evidence into how AI runs, instead of adding them afterwards. It gives your compliance and legal teams records to work with.

What is a Trust Profile?

A record attached to each AI system that states its identity, owner, risk level, approved models, data classification and residency, permitted systems, allowed and restricted actions, human approval rule, retention, audit and policy set.

Which Swfte product enforces policy?

Nexus captures agent actions and enforces policy in-flight. Cortex puts engineers’ AI agents under one policy and one audit trail. The fabric spans all layers, so other products take part through their own controls.

Across every layer

These ideas apply to every layer of the platform.

  • Controlled autonomy

    Five levels, from AI that recommends to AI that adapts within limits.

  • Trust Profile

    The record that describes what each AI system is and may do.

  • AI sovereignty

    Seven kinds of control over your AI estate.

  • Swfte Intelligence Platform

    Analyse and visualise your data, usage, agents and outcomes, then build from what you see.

  • Company brain

    One governed place for everything your organisation knows, for every product to read from.

  • Custom models

    Models adapted on your own data, evaluated before release and deployed under your control.

  • How Swfte builds with Cortex

    An honest first-party account of how we build, review and approve work, labelled by status.

  • Governed agents

    Identity, permissions, policy, approvals and audit for agents, with ten templates.

  • Compliance-approved workflows

    Workflows with approval gates and evidence built in, with twelve templates.

Build on Trust & Governance Fabric with Swfte

Start with one entry point. Add intelligence, agents, workflows and infrastructure as you prove value.

See what your agents are actually doing

Nexus gives you governance, observability and spend control across every agent you run.