Platform / Company brain / Sources

Sources: connecting every source of organisational information into the company brain

How documents, conversations, code, infrastructure, identity, business systems and decisions are designed to flow into one evidence-backed graph, and which of them are connected today.

The company brain is only as good as what flows into it. This page sets out the nine families of organisational information the brain is designed to hold, how any source is connected, what the four directory sources read today and what they never read, how several accounts become one person, where document content stands, and how to decide which source to connect next.

What a source is, and what it gives the brain

A source is any system that holds a piece of the truth about how your organisation works. The directory knows who people are and who they report to. The code repository knows who changed a service last. The ticket queue knows what broke and who fixed it. No one of these systems knows the whole picture, and most of them were never designed to talk to each other.

The brain’s job is to read each source on its own terms, keep what it learned as evidence with a status and a time, and join it to everything else it knows. Swfte Enterprise Intelligence runs in your environment, so the reading happens there too. Today the connected sources are directory and identity systems. Everything else on this page is described as in progress or on the roadmap, and it says which.

The nine source families

What each family would tell the brain, and where it stands today.

  • Documents

    Policies, specifications, contracts and working papers: what the organisation has written down, who wrote it and who may read it. The content store that would hold them is in progress, and document connectors are on the roadmap.

  • Email and chat

    Who talks to whom about what, and where a decision was actually made. Designed to be read with the source’s own access rules attached. On the roadmap.

  • Code and CI/CD

    Repositories, commits, pipelines and deployments: who builds and ships each service, and what changed when. On the roadmap.

  • Cloud and Kubernetes

    Accounts, projects, clusters, workloads and the identities that run them: what is actually running, and where. On the roadmap.

  • Databases

    Which systems hold which data, who can reach them, and how sensitive that data is. On the roadmap.

  • Identity and directory

    People, accounts, groups, reporting lines and organisational units. Built today, with four directory sources.

  • SaaS and business systems

    The tools where work happens, from finance to sales to human resources, and which teams depend on each one. On the roadmap.

  • Tickets

    What broke, who was paged, who fixed it and what changed afterwards: the working record of ownership. On the roadmap.

  • Decisions and policies

    What was decided, by whom, under which constraint, and which policy applies. Designed to be held as modelled data rather than only as text. On the roadmap.

How any source connects

The same rules apply to every connector, whether it is built today or designed for.

  1. 01

    A read-only account

    Each connector uses an account you create for it, with read access only. The brain does not write back to the source, so connecting it cannot change a user, a group or a setting there.

  2. 02

    An allow-list of attributes

    The connector reads named attributes and nothing else. A field that is not on the list is not fetched, so a new attribute added to the source later does not quietly start flowing in.

  3. 03

    Secrets read from files, never credentials

    The connector’s own access secret is read from a file you mount, not typed into a screen. Passwords and other credentials belonging to your people are never read or stored, and the directory connector refuses to start if it is configured to read one.

  4. 04

    A sync schedule

    Each source is read on a schedule you set. Every observation is stored with the time it was seen, so history builds up rather than being overwritten.

  5. 05

    Freshness and the stale status

    Every fact has a freshness window. A fact that has not been seen again within it becomes stale, and anything built on it shows that, rather than presenting old information as current.

What the four directory sources read today, and never read

Active Directory and LDAP, Microsoft Entra ID, Okta and Google Workspace are connected today. From each, the brain reads the attributes that describe how the organisation is structured: names, email addresses, employee number, whether the account is enabled, group memberships and the manager. Groups are stored with transitive membership, so a person in a nested group is known to be in the parent group too. Organisational units and reporting lines come with them.

What the connectors never read matters as much. They do not read passwords or any other credential. They do not read login times or device activity. They do not read the content of anyone’s email or files. Service accounts and devices are stored as what they are, and are not counted as people. Personal data stays in the appliance by default, and values that look like secrets are removed before anything is stored.

Identity resolution: one person, several accounts

Most people have an account in more than one directory. The brain resolves those accounts into a single person and records, on each link, the evidence that joined them, such as a matching employee number or email address. A link resting on weaker evidence carries a weaker status. If two sources disagree, the fact is marked disputed rather than settled quietly in favour of one of them.

This matters for every later question. A count of people is a count of people, not of accounts. A question about what someone can see takes every account they hold into account. And when a resolution turns out to be wrong, the evidence on the link shows why it was made, so a person can find the cause and correct it.

Documents and content: in progress

The content store that holds documents is being built. Each object keeps the access list copied from its source, so a document visible to one team in the source system stays visible to that team only. Content is split into chunks and indexed for keyword and vector search together, and every search is filtered by the principals of the person asking, inside the database, before any result leaves it.

These pieces exist as libraries with passing tests. The HTTP endpoints that would let a person or a product search them are not finished, so document search is not something to rely on yet. Where an object’s access list is missing or incomplete, the object is invisible. The design fails closed rather than open.

What is on the roadmap, and how to choose the next source

Collectors for cloud, code, CI/CD, Kubernetes, databases, SaaS and business systems and tickets are on the roadmap, along with document and email connectors and decisions and policies held as modelled data. The current position on specific connectors is <connector list beyond directory sources - founder to fill>. No dates are given here, and none should be assumed.

Choosing the next source is a measurement exercise, not a guess. The brain reports coverage per source: what is connected, how fresh it is, and how complete the picture is relative to what it can see. Coverage is a measure, never a claim to understand everything. Start from the questions people actually ask and note which ones come back unknown. The source that would turn the most important unknowns into observed facts is the one to connect next.

A worked example: who owns this service?

Suppose an engineer asks who owns the payments reconciliation service. With only the directory connected, the brain can say a good deal about people. It knows the platform team exists, who is in it, who leads it and who that person reports to. It can say who sits in the on-call group and when that membership last changed, each fact observed from the directory with the time it was seen.

What it cannot do is connect any of those people to the service. Nothing in a directory says which repository holds the service, who deploys it, or which team is paged when it fails. So the honest answer today is that ownership is unknown, with the people facts it does have alongside. Once code, CI/CD and ticket collectors exist, the same question would be answered from commits, pipelines and incidents, each fact with its own status and age.

Sources: built, in progress and on the roadmap

What is connected today and what is designed for. No dates are given.

What is built, in progress and on the roadmap: Sources
CapabilityStatusNotes
Directory sync from Active Directory and LDAP, Entra ID, Okta and Google WorkspaceBuiltRead-only account and an allow-list of attributes.
Identity resolution into peopleBuiltEvidence is recorded on each account-to-person link.
Groups, reporting lines and organisational unitsBuiltGroup membership is resolved transitively.
Service accounts and devicesBuiltStored as what they are, never counted as people.
Coverage and freshness per sourceBuiltServed by the local API. Coverage views are on the roadmap.
Content store, chunking and permission-filtered searchIn progressLibraries exist with tests. HTTP endpoints are not finished.
Document and email connectorsRoadmapDesigned to carry the source’s access lists.
Code, CI/CD, cloud, Kubernetes, database, SaaS and ticket collectorsRoadmapNeeded for questions about systems and ownership.
Decisions and policies as modelled dataRoadmapDesigned for, not built.

Legend

  • Built. Exists today and can be used.
  • In progress. Being built. Not yet something to rely on.
  • Roadmap. Designed for and on the roadmap. Not built. No dates are given.

Where this fits in the loop

Sources feed the first station of the loop: everything the brain later offers to models, agents and people starts as an observation from a connected source.

The same four stations and four arrows are listed in order below.
  1. 01Company brainHolds what the organisation knows, with evidence statuses, history and access rules.(this page)
  2. 02Custom modelAdapted on data chosen from the brain, then evaluated and hardened before it ships.
  3. 03Governed agentsUse the model and read the brain, inside a Trust Profile, with approval where it matters.
  4. 04OutcomesWhat happened: approvals, corrections, results and cost, all on the record.

The four arrows

  1. Company brain to Custom model: select, sanitise, adaptRoadmap

    Choose training data from the brain, remove what must not reach a model, adapt an open-weight base. The sanitisation gateway is in progress, and the data selection and training steps are on the roadmap.

  2. Custom model to Governed agents: serve, governBuilt

    Serve the model on dedicated infrastructure behind the Connect gateway and bring agents onto it under policy. Model hosting and the gateway are built.

  3. Governed agents to Outcomes: act, recordBuilt

    Agents act within their Trust Profile, with human approval for consequential steps, and every action is recorded.

  4. Outcomes to Company brain: written back as evidenceRoadmap

    Outcomes return to the brain as new evidence with a status, and they decide when the model needs retraining. The write-back is on the roadmap.

Legend

  • Built. Exists today and can be used.
  • In progress. Being built. Not yet something to rely on.
  • Roadmap. Designed for and on the roadmap. Not built. No dates are given.

Frequently asked questions

Which sources can the company brain read today?

Four directory and identity sources: Active Directory and LDAP, Microsoft Entra ID, Okta and Google Workspace, read with a read-only account and an allow-list of attributes. Documents, email, code, cloud, databases, SaaS systems and tickets are designed for and on the roadmap, and search over document content is in progress.

Does connecting a source send our data to Swfte?

The brain is a customer-hosted appliance and its connectors read from inside your environment. Personal and restricted data stays local by default. In the air-gapped mode there is no outbound connection at all, and in the other modes the link is outbound-only and accepts only signed, typed commands.

Are passwords read or stored?

No. Passwords and other credentials are never read or stored, and the directory connector refuses to start if it is configured to read one. Values that look like secrets are removed before anything is stored, and the connector’s own access secret is read from a file you mount.

What happens when a source stops syncing?

Its facts are no longer re-observed, so once their freshness window passes they become stale. Answers built on them show the stale status and the age of the evidence instead of presenting old information as current, and coverage reporting shows the source as less fresh.

How does the brain know two accounts belong to one person?

It resolves accounts across directories using evidence such as matching identifiers, and stores that evidence on each link. When sources disagree the fact is marked disputed, and a person can see why a resolution was made and correct it if it is wrong.

Can we choose which attributes are read?

Yes. Each connector reads an allow-list of named attributes, and anything not on the list is not fetched, including attributes added to the source later. The directory connectors read names, email addresses, employee number, enabled state, groups and manager.

Does connecting our directory meet our data protection obligations?

Not on its own, and Swfte does not claim it. The brain provides technical controls and evidence, such as local-only personal data, per-person export and erase commands and a tamper-evident audit log, that help an organisation meet its own obligations. The posture depends on your use case, jurisdiction, deployment and configuration.

Which connectors are coming next?

<connector list beyond directory sources - founder to fill> Collectors for cloud, code, CI/CD, Kubernetes, databases, SaaS systems and tickets are designed for and on the roadmap, without dates. Coverage reporting is the tool for deciding which of them would close the most important gaps for your organisation.

Take sources further with Swfte

Start with one entry point. Add intelligence, agents, workflows and infrastructure as you prove value.

Ready to build with Swfte?

One platform for the agents, models and workflows your team ships. Free to start, no card required.