Platform / Governance

The Trust Profile

Every AI system should have an identity, permissions, policies, controls and evidence. The Trust Profile is the design for where they live together, so governance happens inside the AI rather than in a document beside it.

Example: Customer Service Agent 017

Illustrative and designed for. The platform has a policy engine, approvals and a hash-chained run ledger today, as separate parts. It does not yet keep one Trust Profile record per agent, and fields such as risk level and owner are not yet stored together on an agent.

Identity
Customer Service Agent 017
Owner
Customer Operations
Risk level
Medium
Approved models
Model A / Model B
Data classification
Confidential
Data residency
EU
Permitted systems
CRM / Knowledge Base / Ticketing
Allowed actions
Read / Recommend / Draft
Restricted actions
Account modification / Refund
Human approval
Required for refunds above threshold
Retention
Defined organisational policy
Audit
Full action trace
Policy set
Corporate AI Policy / Customer Data Policy

Decisions the platform is designed to take

The policy engine returns allow, redact, ask or deny at its control points today, and applies only to runs that have a policy attached. Escalation exists in separate approval gates, and warn is part of the design.

  • Allow

    The action is within policy and proceeds.

  • Deny

    The action is outside policy and is blocked.

  • Warn

    The action proceeds and a warning is raised to the owner.

  • Filter

    The content is modified, such as redacting sensitive fields.

  • Escalate

    The case is routed to a person or team with context.

  • Require human approval

    The action waits for a named approver.

Traceability

Each outcome can be traced back along one chain.

  1. Data
  2. Model
  3. Agent
  4. Decision
  5. Action
  6. Outcome

Swfte provides the technical controls, governance mechanisms and evidence required to deploy AI within an organization's applicable regulatory, security and policy requirements. The exact posture depends on the customer's use case, jurisdiction, deployment and configuration.

Questions

What is a Trust Profile?

A design for one record attached to every AI system, giving it an identity, permissions, policies, controls and evidence. Today those controls exist as separate parts of the platform and are not yet joined into a single record; the policy engine applies to runs that have a policy attached.

How is this different from guardrails?

Guardrails ask whether something should be blocked. Governance asks who is acting, allowed to do what, under which policy, with which data and model, at what risk and oversight, and whether it can be proven.

Related

Ready to build with Swfte?

One platform for the agents, models and workflows your team ships. Free to start, no card required.