Platform / Governance
The Trust Profile
Every AI system should have an identity, permissions, policies, controls and evidence. The Trust Profile is the design for where they live together, so governance happens inside the AI rather than in a document beside it.
Example: Customer Service Agent 017
Illustrative and designed for. The platform has a policy engine, approvals and a hash-chained run ledger today, as separate parts. It does not yet keep one Trust Profile record per agent, and fields such as risk level and owner are not yet stored together on an agent.
- Identity
- Customer Service Agent 017
- Owner
- Customer Operations
- Risk level
- Medium
- Approved models
- Model A / Model B
- Data classification
- Confidential
- Data residency
- EU
- Permitted systems
- CRM / Knowledge Base / Ticketing
- Allowed actions
- Read / Recommend / Draft
- Restricted actions
- Account modification / Refund
- Human approval
- Required for refunds above threshold
- Retention
- Defined organisational policy
- Audit
- Full action trace
- Policy set
- Corporate AI Policy / Customer Data Policy
Decisions the platform is designed to take
The policy engine returns allow, redact, ask or deny at its control points today, and applies only to runs that have a policy attached. Escalation exists in separate approval gates, and warn is part of the design.
Allow
The action is within policy and proceeds.
Deny
The action is outside policy and is blocked.
Warn
The action proceeds and a warning is raised to the owner.
Filter
The content is modified, such as redacting sensitive fields.
Escalate
The case is routed to a person or team with context.
Require human approval
The action waits for a named approver.
Traceability
Each outcome can be traced back along one chain.
- Data
- Model
- Agent
- Decision
- Action
- Outcome
Swfte provides the technical controls, governance mechanisms and evidence required to deploy AI within an organization's applicable regulatory, security and policy requirements. The exact posture depends on the customer's use case, jurisdiction, deployment and configuration.
Questions
What is a Trust Profile?
A design for one record attached to every AI system, giving it an identity, permissions, policies, controls and evidence. Today those controls exist as separate parts of the platform and are not yet joined into a single record; the policy engine applies to runs that have a policy attached.
How is this different from guardrails?
Guardrails ask whether something should be blocked. Governance asks who is acting, allowed to do what, under which policy, with which data and model, at what risk and oversight, and whether it can be proven.