Platform / Company brain

The company brain: one place for everything your organisation knows

A single, customer-hosted, evidence-backed model of your organisation that every Swfte platform and product is designed to be built on.

Most organisations keep what they know in dozens of places, and every new AI tool asks for its own copy. The company brain is the alternative: one governed graph of people, structure, systems, ownership and history, with an evidence status on every fact and access rules that follow the person asking. It runs in your environment as Swfte Enterprise Intelligence. The directory part is built. More sources, and the wiring into each product, are on the roadmap, and this page marks which is which.

What the company brain is

The company brain is where an organisation keeps everything it knows, in a form that machines and people can both ask. Underneath it is a graph. A person is an entity, and so are a group, an account, a service and a document. The relationships between them, who belongs to what, who reports to whom, who owns which system, are stored as edges, with the time each was true and the evidence behind it.

It is not a data lake and it is not a second copy of your systems. It holds a model of the organisation, and it points back to the sources the facts came from. It runs where you put it: on a virtual machine, on Kubernetes, or inside an air gap. The product is Swfte Enterprise Intelligence, and the same appliance is the foundation of the Swfte Intelligence Platform.

Today it reads your directory: Active Directory and LDAP, Microsoft Entra ID, Okta and Google Workspace. It turns accounts into people, keeps the structure and the history, and answers questions through a local API. Documents, systems, tickets and decisions are the next sources, and the page below says honestly where each one stands.

Sources in, brain in the middle, platforms on top

Select any part of the diagram to see what it is and whether it is built. The lists under the drawing carry the same information as text.

Read left to right. Sources feed the brain core. The core feeds the platforms. For a platform, the status describes the connection from the brain, not the product, which you can use today.

Legend

  • Built. Exists today and can be used.
  • In progress. Being built. Not yet something to rely on.
  • Roadmap. Designed for and on the roadmap. Not built. No dates are given.

Sources

Brain core

Platforms

Brain core

Entities and relationships

Built

People, groups, accounts, organisational units, service identities and devices, and the edges between them: member of, reports to, has account, in organisational unit.

Read more about Entities and relationships

Why one brain, not many silos

Every AI tool needs context. The question is whether each one gets its own copy or all of them read from one governed place.

  • One copy of context, not one per tool

    Each assistant, agent and dashboard built on its own data connection has its own idea of who owns what. One brain means one answer, with one set of access rules.

  • Access rules written once

    When every tool carries its own permissions, they drift. The brain applies what the source says about who may see what, and applies it to every reader.

  • Evidence that travels

    A fact that is observed, inferred, stale or disputed is labelled as such wherever it appears, in a chart or in an agent prompt, so nobody builds on a guess without knowing.

  • History as well as now

    Decisions are reviewed against the organisation as it was at the time. A silo that overwrites its data cannot do that.

  • One thing to switch off

    A single outbound link, a single kill switch, a single audit log. Fewer places to secure, and one place to prove what happened.

How sources connect, and where each one stands

Only the directory sources are built connectors. Documents are in progress. Everything else is designed for. We would rather show you a short honest table than a long one.

Sources the company brain connects to, and the status of each connector
SourceWhat it adds to the brainStatusNotes
Active Directory and LDAPPeople, groups, reporting lines, accounts, organisational units, service accounts and devices.BuiltRead-only account, attribute allow-list, secrets read from files. Tested against a Samba Active Directory domain controller.
Microsoft Entra IDUsers, guests, groups and managers, linked to on-premises accounts where the directory provides the link.BuiltRead-only. Accounts are resolved into one person with the evidence kept on the link.
OktaUsers, groups, status and manager.BuiltRead-only. Passwords and credentials are never read or stored.
Google WorkspaceUsers, groups, aliases, suspended and archived state and manager.BuiltRead-only. Personal data stays in the appliance.
Documents and contentText of policies, contracts and wikis, with the access list of the source copied alongside.In progressStore, chunking and access-safe search exist as libraries. Connectors and the endpoints that expose search are not finished.
Cloud, code, CI/CD, Kubernetes, databasesSystems, services and who owns them, so the brain can say more than who a person is.RoadmapDesigned for. Not built. <connector list beyond directory sources - founder to fill>
SaaS, business systems and ticketsAccounts, customers, incidents and changes, linked to services and people.RoadmapDesigned for. Not built.
Email and chatConversations where decisions are made, with per-item access rules.RoadmapDesigned for. Not built.
Decisions, constraints and processesThe reasons behind how the organisation works, with history and an owner.RoadmapDesigned for as modelled data. Not built.

Legend

  • Built. Exists today and can be used.
  • In progress. Being built. Not yet something to rely on.
  • Roadmap. Designed for and on the roadmap. Not built. No dates are given.

Sources in depth

How it stays yours: connected, private or air-gapped

The company brain is customer-hosted. The mode decides what, if anything, leaves your environment, and you can inspect it rather than take our word for it.

  • Connected

    The appliance runs in your environment and links outbound to the Swfte control plane.

    What leaves

    Health counts, coverage summaries, diagnostics and command results. Personal and restricted data stay in your environment.

    • The link is outbound only and mutually authenticated against a certificate authority pinned at enrolment.
    • Swfte can send signed, typed commands from a short allow-list that you set.
    • You can cut the link at any time with a local kill switch.
  • Private

    The same link behaviour, pointed at a control plane that you host yourself.

    What leaves

    The same as connected, to a control plane you operate.

    • Useful when policy says no vendor-hosted control plane.
    • The appliance validates every remote operation locally in exactly the same way.
    • Updates and commands remain signed.
  • Air-gapped

    No outbound connection at all.

    What leaves

    Nothing leaves. The link is never started, and enrolment is refused.

    • Updates arrive on signed media and are verified against a key pinned on the appliance.
    • Everything else works from inside your boundary.
    • The mode is a configuration choice you can inspect, not a promise in a contract.

Where it can run

  • Virtual machine with Docker

    A hardened container image and an installer with verify and uninstall scripts, for a single host.

  • Kubernetes with Helm

    A Helm chart for clusters you already run, including a migration job that runs with separate credentials.

  • Air-gapped

    An install route for environments with no outbound access, with updates delivered on signed media.

The controls the brain is built around

A single outbound link you can cut with a kill switch, signed and typed commands only, and a tamper-evident record of what happened.

  • Outbound only, and you can cut it

    The appliance never accepts a connection from the control plane. A local kill switch stops the link entirely, and each use is recorded.

  • Signed, typed commands only

    Remote operations are typed and signed. You choose which capabilities are allowed. There is no shell or arbitrary-execution capability, by construction.

  • Validated locally, fail closed

    The appliance checks every remote operation itself. If it cannot verify the signature, the expiry or the capability, it refuses.

  • Data stays by default

    Personal and restricted data are local-only by default. Secrets and credentials are never stored. What may leave is a policy you can read.

  • Signed updates

    Updates are verified before they are staged. In air-gapped mode they arrive on media and are checked against a key you pinned.

  • A tamper-evident record

    The audit log is hash-chained and anchored by signed checkpoints, so a break in the chain is detectable.

  • Isolation by tenant

    Row-level security separates tenants, and the runtime database role cannot bypass it or own the schema.

  • Never more access than the asker

    Answers are scoped to what the person asking is allowed to see. Retrieved content is treated as untrusted and cannot override policy.

How every product reads from it

The brain is meant to be the layer under the rest of the platform. Each product works on its own today. The wiring that lets each one read organisational context from the brain is on the roadmap, and the status shown is the status of that connection.

  • Cortex

    Roadmap

    Cortex answers from your files and meetings on the laptop today, with knowledge bases, MCP tools and local models. It is designed to read organisational context from the brain as well. That wiring is on the roadmap.

    Read more about Cortex
  • Nexus

    Roadmap

    Nexus captures agent actions, enforces policy in flight and traces agents today. It is designed to resolve owners, approvers and scope from the brain. On the roadmap.

    Read more about Nexus
  • Studio

    Roadmap

    Studio builds agents, chatflows and workflows today. It is designed to start an agent from what the brain knows, with owner and scope filled in. On the roadmap.

    Read more about Studio
  • Connect

    Roadmap

    Connect is the model gateway today. It is designed to take identity and routing rules from the brain, so the right people and agents reach the right models. On the roadmap.

    Read more about Connect
  • Intelligence analytics

    Roadmap

    The Intelligence Platform views, such as the graph explorer, ownership maps and coverage, read the brain. The local API already serves the data they need. The views themselves are design intent.

    Read more about Intelligence analytics
  • Agents

    Roadmap

    Governed agents are designed to ask the brain for the context they are allowed to have, and to act only through typed, approved and audited capabilities. On the roadmap.

    Read more about Agents
  • Workflows

    Roadmap

    Workflows route work to owners and approvers the brain resolves, and can be told to ask a person when a fact is stale or disputed. Designed for. On the roadmap.

    Read more about Workflows
  • Solutions

    Roadmap

    Packaged agents, workflows and policies that carry their scope and their outcome measure from the brain. Designed for. On the roadmap.

    Read more about Solutions
  • Custom models

    Roadmap

    Models adapted on data chosen from the brain, with sanitisation and consent, then evaluated, deployed and retrained as outcomes return. Hosting and serving your own weights is built. Selecting data from the brain is on the roadmap.

    Read more about Custom models

Access control: never more than the person asking

The brain is only useful if people trust it with sensitive material, and that depends on one rule: an answer is limited to what the person asking is allowed to see.

  • Who is asking

    The question carries an identity. The brain resolves that person, with all their accounts and groups, into a set of principals.

  • Filtered inside the database

    Access lists are applied in the query itself, not by hiding results afterwards. An object with an unknown or incomplete list is invisible rather than visible.

  • Agents are no exception

    An agent acting for a person gets the intersection of what the person may see and what the agent has been granted, never more than either.

  • Retrieved text is untrusted

    A passage that says to ignore the rules is data. It cannot change policy, and it is treated that way whatever model reads it.

The tenant and token scoping, the row-level isolation and the tamper-evident audit are built. Per-document access lists and the identity-aware reads that use them are in progress.

Access and governance in depth

Evidence statuses: what the brain knows, and how well

Every fact in the brain carries one of seven statuses, and the status travels with the answer. It is how the brain keeps the difference between seen, inferred and unknown.

Observed
Seen directly in a source system.
Good enough to show and to ask about. Not yet confirmed by anything else.
Corroborated
More than one independent source agrees.
A stronger basis for a recommendation than a single observation.
Verified
Confirmed by an authoritative check or a person.
The kind of fact an approval rule can safely lean on.
Inferred
Derived from other facts rather than seen directly.
Useful for suggestions. Labelled as an inference wherever it is shown.
Stale
Not re-observed within its freshness window.
Shown with its age. A workflow can be told to ask a person instead of relying on it.
Disputed
Sources disagree about it.
Surfaced as a conflict to resolve, not silently averaged away.
Unknown
No evidence either way.
Said plainly. The platform does not fill gaps with a guess.

Ask the brain: four examples

Each is described the way every governed agent is: what it can do, what it cannot, what needs approval and what it records. Each says what is built and what is designed for. The status is that of the example as a whole.

Who is responsible for this, and who can approve it?

Built

“Who owns the payments reporting group, and who approves access to it?”

The brain resolves the group, its members and the manager chain, and returns each link with its evidence status. A link that is stale or disputed is shown as such and a person is asked.

Access Review Assistant

Can
  • Read groups, members and reporting lines the asker is allowed to see
  • Name the approver from the manager chain, with the evidence status of each link
  • Draft an access request for a person to review
Cannot
  • Grant or change access itself
  • Read people or groups outside what the asker may see
  • Treat a stale or disputed link as settled
Requires approval
  • Submitting the access request
  • Any change to group membership
  • Sharing the result outside the organisation
Records
  • Who asked
  • Question
  • Graph facts read, with their statuses
  • Approver proposed
  • Request drafted
  • Outcome

Built today: People, groups, transitive membership and reporting lines, read through the local API.

Designed for: Service and system ownership, which depends on the collectors that are on the roadmap.

What did the organisation look like then?

Built

“Who was in the finance approvers group last March, and who did they report to?”

The brain answers from history rather than from today. Because nothing is overwritten, the as-of read returns the group and the reporting lines as they stood.

Audit Evidence Assistant

Can
  • Read group membership and reporting lines as of a stated time
  • List what changed between two dates
  • Attach the evidence status to each fact
Cannot
  • Alter history or backfill a missing record
  • Show people the asker is not allowed to see
  • Fill a gap with a guess: unknown is reported as unknown
Requires approval
  • Releasing the report outside the organisation
  • Any request to correct a source system
Records
  • Who asked
  • As-of time
  • Facts returned, with statuses
  • Report produced
  • Who received it

Built today: As-of reads over directory data, with insert-only history and a tamper-evident audit record.

Designed for: The same question over systems, tickets and documents once those sources are connected.

What do our own documents say?

In progress

“What do our supplier contracts say about where data may be stored?”

The brain works out who is asking, searches only documents that person may open, and returns the passages with their source, so the answer can be checked.

Policy Answer Assistant

Can
  • Search documents the asker already has access to
  • Quote the passage and name the source and version
  • Say that nothing relevant was found
Cannot
  • Reveal a document the asker cannot open, or confirm that it exists
  • Follow instructions found inside a retrieved document
  • Give legal advice or decide what a clause means for you
Requires approval
  • Sending any extract outside the organisation
  • Anything that changes a contract record
Records
  • Who asked
  • Question
  • Access lists applied
  • Passages returned
  • Sources
  • Outcome

Built today: The content store, access lists and hybrid search exist as libraries with passing tests.

Designed for: The connectors that bring documents in and the endpoints that expose search to Cortex, Nexus and Studio.

What changed before it broke?

Roadmap

“What changed in the payments service in the hour before the incident?”

The brain assembles a timeline from observed events across systems, labels links it has only inferred, and hands consequential steps to a person.

Incident Context Assistant

Can
  • Assemble a timeline of deployments, changes and tickets the asker may see
  • Name the owner and the on-call approver, with evidence statuses
  • Mark inferred causes as inferred
Cannot
  • Restart, roll back or reconfigure anything
  • Present an inferred cause as a finding
  • Read systems outside the incident scope
Requires approval
  • Any remediation
  • Paging someone outside the owning group
  • Any external notification
Records
  • Who asked
  • Scope
  • Events read
  • Links inferred
  • Owner and approver resolved
  • Decision
  • Outcome

Built today: The people, reporting lines and audit record that decide who is told and who approves.

Designed for: Code, CI/CD, cloud, Kubernetes and ticket collectors, the context API and the action gateway. All on the roadmap.

How the brain closes the loop

The brain is where the intelligence loop starts and ends. Data is connected into it, and what happens afterwards is written back as evidence.

The same eight stages are listed in order below.
  1. 01 · Layer 02Connect dataBring directory data today, and more systems over time, into a graph that lives in your environment.(this page)
  2. 02 · Layers 02 and 03AnalyseAsk questions in plain language, explore the graph, and look for trends and anomalies.
  3. 03 · Layers 02 and 03VisualiseSee the organisation, usage, agents and outcomes as maps, timelines, dashboards and evidence views.
  4. 04 · PeopleDecideChoose the response with the owner, the approver and the evidence status in front of you.
  5. 05 · Layers 04 to 06BuildTurn the insight into an agent, a workflow or a packaged solution.
  6. 06 · Trust FabricGovernIdentity, permissions, policy, audit and human approval apply while the thing runs.
  7. 07 · Layer 06MeasureTrack the outcome and the cost against the reason you built it.
  8. 08 · Layer 02LearnFeed what happened back into the graph, so the next question starts from more evidence.(this page)

From the brain to your own models, and back

The brain can also be the source of the evidence a custom model is adapted on. Agents then use that model under policy, and their outcomes return to the brain.

The same four stations and four arrows are listed in order below.
  1. 01Company brainHolds what the organisation knows, with evidence statuses, history and access rules.(this page)
  2. 02Custom modelAdapted on data chosen from the brain, then evaluated and hardened before it ships.
  3. 03Governed agentsUse the model and read the brain, inside a Trust Profile, with approval where it matters.
  4. 04OutcomesWhat happened: approvals, corrections, results and cost, all on the record.

The four arrows

  1. Company brain to Custom model: select, sanitise, adaptRoadmap

    Choose training data from the brain, remove what must not reach a model, adapt an open-weight base. The sanitisation gateway is in progress, and the data selection and training steps are on the roadmap.

  2. Custom model to Governed agents: serve, governBuilt

    Serve the model on dedicated infrastructure behind the Connect gateway and bring agents onto it under policy. Model hosting and the gateway are built.

  3. Governed agents to Outcomes: act, recordBuilt

    Agents act within their Trust Profile, with human approval for consequential steps, and every action is recorded.

  4. Outcomes to Company brain: written back as evidenceRoadmap

    Outcomes return to the brain as new evidence with a status, and they decide when the model needs retraining. The write-back is on the roadmap.

Legend

  • Built. Exists today and can be used.
  • In progress. Being built. Not yet something to rely on.
  • Roadmap. Designed for and on the roadmap. Not built. No dates are given.

Build models for your domain

Go deeper

Five pages, each with its own question.

  • Sources

    How documents, conversations, code, infrastructure, identity, business systems and decisions are designed to flow into one evidence-backed graph, and which of them are connected today.

  • Knowledge graph

    The graph at the centre of the company brain: entities and relationships, kept with their history, an evidence status on every fact, and a tamper-evident record of what the appliance did.

  • Access and governance

    How identity, access lists, tokens, tenant isolation, data policy and audit keep what the brain knows inside the limits your organisation already sets.

  • Ask your company

    What asking the company brain means, how an answer is built and checked against who is asking, and what you can ask today versus what is designed for.

  • Agents on the brain

    Why agents need the company brain, how they are designed to get context and act through approved capabilities, and what is built today versus designed for.

Specifics we have not published yet

We would rather leave a gap than invent a detail. These are for the founder to fill before they are stated on the site.

Connectors beyond directory sources
<connector list beyond directory sources - founder to fill>
Availability
<availability - founder to fill>
Pricing
<pricing - founder to fill>
Marketplace listings
<marketplace listings - founder to fill>

Frequently asked questions

What is a company brain?

It is one governed place that holds what an organisation knows: people, structure, systems, ownership, documents and history, as a graph with an evidence status on every fact. Swfte products are designed to read from it instead of each keeping their own copy of your context.

Is it built today, or is this a vision?

Part of it is built. The time-aware graph, directory sync from Active Directory, LDAP, Entra ID, Okta and Google Workspace, identity resolution, the local API, the outbound link with a kill switch and the packaging are built. Document search and sanitisation are in progress. Other sources and the wiring into each product are on the roadmap. We give no dates.

Where does my data live?

In your environment. The appliance runs on a virtual machine, on Kubernetes or air-gapped. Personal and restricted data are local-only by default, and passwords and credentials are never stored. In connected mode only health counts, coverage summaries, diagnostics and command results leave.

How is this different from RAG or a knowledge base?

A knowledge base stores content for people, and RAG fetches passages for a model. The brain models the organisation itself, with entities, relationships, history, evidence and access rules, and retrieval over documents is one way of reading it. It can answer who owns something or who was in a group last March, which a pile of passages cannot.

Which sources can it connect to?

Active Directory and LDAP, Microsoft Entra ID, Okta and Google Workspace are built. Documents are in progress. Cloud, code, CI/CD, Kubernetes, databases, SaaS and business systems, tickets, email and chat, and decisions are on the roadmap. <connector list beyond directory sources - founder to fill>

Can the AI see things the person asking cannot?

No. Answers are limited to what the asker may see, and an agent acting for someone gets the intersection of their access and its own grants. Where the brain cannot establish who is asking, it offers only what is visible to the whole tenant.

What happens if I want to switch it off?

A local kill switch stops the outbound link at once, and each use is recorded. In air-gapped mode the link is never started at all. Personal data can be exported or erased per person, and retention can be set so deleted people are replaced by a pseudonym.

Does Cortex, Nexus or Studio read from it today?

Not yet. Each product works on its own today. The wiring that lets them read organisational context from the brain is on the roadmap, and we say so on every page where it matters.

Is it compliant?

We do not claim that, and no platform can on its own. The brain is built for compliance-by-design: it provides technical controls, governance mechanisms and evidence, such as access limits, an audit trail and per-person export and erase commands, that help an organisation meet its own obligations. Swfte provides the technical controls, governance mechanisms and evidence required to deploy AI within an organisation's applicable regulatory, security and policy requirements. The exact posture depends on the customer's use case, jurisdiction, deployment and configuration. Swfte does not hold a SOC 2 report, an ISO 27001 certificate or a HIPAA BAA today. A SOC 2 Type I audit is in preparation; the trust page lists what is in place and what is in progress.

What does it cost, and when is it available?

<pricing - founder to fill> <availability - founder to fill> Talk to our team for the current position.

Across every layer

These ideas apply to every layer of the platform.

Give every AI product one brain to read from

Start with one entry point. Add intelligence, agents, workflows and infrastructure as you prove value.

Ready to build with Swfte?

One platform for the agents, models and workflows your team ships. Free to start, no card required.