Platform / Intelligence / Enterprise graph
The enterprise graph: an evidence-backed, time-aware model of your organisation
A customer-hosted graph of people, groups, reporting lines and accounts today, with systems, services, documents and decisions to follow.
Underneath the Intelligence Platform is Swfte Enterprise Intelligence, a customer-hosted appliance that holds a continuously updating graph of your organisation. Every fact in it carries an evidence status and a history. This page explains what the graph is, what it holds today, how time-aware reads work, how identities are resolved into people, and how coverage is measured.
What the graph is
The graph is a model of the organisation: the things in it and the relationships between them. A person is an entity. So is a group, an account and an organisational unit. A person has accounts, belongs to groups and reports to another person. Those relationships are the edges, and they are the part that a spreadsheet or a document store cannot give you, because they are what answer questions such as who is responsible for this, and who can approve it.
It is customer-hosted. The appliance runs in your environment, in your virtual machine or your Kubernetes cluster or inside an air gap, and customer data stays there by default. It is continuously updating rather than a snapshot, so the picture follows the organisation as it changes.
It is the backbone that Cortex, Nexus, Studio and the Nexus harness are designed to read organisational context from. They ask the graph what an agent needs to know, and the agent acts only through typed, approved and audited capabilities. The wiring from those products into the graph is on the roadmap.
What it holds today, and what is designed for
The honest scope. See the table on the Intelligence Platform page for the full built and not-yet-built list.
Today: people and structure
People, groups, reporting lines, accounts and organisational units, read from Active Directory and LDAP, Microsoft Entra ID, Okta and Google Workspace with a read-only account. Service accounts and devices are stored as what they are, and are not treated as people.
Today: history
Every change is kept with the time it was true. History is insert-only, so nothing is quietly overwritten.
Today: a local API
Graph, people, groups, coverage and audit reads, scoped by token, with the tenant always taken from the credential and never from the request.
Designed for: systems and services
Cloud, code, CI/CD, Kubernetes and database collectors, so the graph can say who owns a service and not only who a person is. On the roadmap.
Designed for: business context
SaaS, business systems, documents, decisions, constraints and processes. On the roadmap.
Never stored
Passwords and other credentials. The directory connector refuses to start if it is asked to read one, and values that look like secrets are removed before anything is stored.
Evidence statuses on every fact
Each fact in the graph carries one of seven statuses: observed, corroborated, verified, inferred, stale, disputed or unknown. Observed means seen directly in a source. Corroborated means more than one independent source agrees. Verified means confirmed by an authoritative check or a person. Inferred means derived from other facts. Stale means not re-observed within its freshness window. Disputed means sources disagree. Unknown means there is no evidence either way.
The principle is evidence before inference. An answer that rests on a verified fact is a different kind of answer from one that rests on an inferred one, and the platform is built so that the difference is visible, to a person reading a view and to an agent reading context. A workflow can be told to rely on a verified owner and to ask a person otherwise.
Statuses also protect the organisation from false confidence. Disputed facts are surfaced as conflicts to resolve, not averaged away, and unknown is said plainly.
Time-aware reads: ask as of any moment
Because history is kept and never overwritten, the graph can answer questions about the past. Who was in this group last March? Who did this person report to when the decision was made? The read takes an as-of time and returns the graph as it stood.
This is the capability that makes the graph useful for review. A decision is reviewed against the organisation as it was at the time, and not as it is now, when the person has changed teams and the group has been renamed. It also supports investigation: when something went wrong, you can see exactly what the structure looked like and how it changed.
The graph also records the audit trail of the appliance itself in a hash-chained log, anchored by signed checkpoints, so that tampering with the record is detectable.
Identity resolution: one person, many accounts
People in a real organisation have several accounts: one in the on-premises directory, one in the cloud directory, one in an identity provider, one in a workspace suite. A system that treats each account as a person will count the same human four times and miss that the four are one set of permissions.
The appliance resolves accounts across directories into a single person, and keeps the evidence for each link on the link itself. Reporting lines are derived at the person level as well as kept at the account level. The result is that a question about a person is a question about the person, whichever directory the answer came from.
Identity also matters to the other direction of travel. An AI acting on a user’s behalf is resolved to that user’s principals, and it is limited to what they may see. Content in the graph can carry access rules, and reads are filtered by them inside the database. Where the platform cannot establish who is asking, it fails closed and offers only what is tenant-wide.
Coverage: a measure, never a claim of understanding everything
The platform reports coverage as a measurement: which sources are connected, how fresh each one is, and how complete the picture is relative to what it is able to see. It is never worded as the platform understanding the organisation.
This is deliberately uncomfortable. A vendor that tells you its product understands everything about your organisation is asking you to stop checking. The graph tells you what it covers and what it does not, so you know when to trust an answer and when to ask a person.
Coverage is itself a view. It is part of how the platform helps you decide which collector to connect next.
How the graph connects to the closed loop
The graph is where the loop starts and ends. Data is connected into it, every later stage reads from it, and outcomes are written back into it as evidence.
- 01 · Layer 02Connect dataBring directory data today, and more systems over time, into a graph that lives in your environment.(this page)
- 02 · Layers 02 and 03AnalyseAsk questions in plain language, explore the graph, and look for trends and anomalies.
- 03 · Layers 02 and 03VisualiseSee the organisation, usage, agents and outcomes as maps, timelines, dashboards and evidence views.
- 04 · PeopleDecideChoose the response with the owner, the approver and the evidence status in front of you.
- 05 · Layers 04 to 06BuildTurn the insight into an agent, a workflow or a packaged solution.
- 06 · Trust FabricGovernIdentity, permissions, policy, audit and human approval apply while the thing runs.
- 07 · Layer 06MeasureTrack the outcome and the cost against the reason you built it.
- 08 · Layer 02LearnFeed what happened back into the graph, so the next question starts from more evidence.(this page)
Frequently asked questions
Where does the graph live?
In your environment. It runs on a virtual machine, on Kubernetes or air-gapped, and customer data stays there by default.
What are the seven evidence statuses?
Observed, corroborated, verified, inferred, stale, disputed and unknown. Every fact carries one, and the status travels with any answer built from it.
What is an as-of read?
A read of the graph as it stood at an earlier time. History is insert-only, so a question about the past is answered from what was true then.
What sources does it read today?
Active Directory and LDAP, Microsoft Entra ID, Okta and Google Workspace. Cloud, code, Kubernetes, database, SaaS and document sources are on the roadmap.
Does it store passwords?
No. Passwords and other credentials are never read or stored. Personal data is classified and, by default, never leaves the appliance.
Does the graph claim to know everything about us?
No. It reports coverage and says unknown when it does not know. It is built never to claim it understands everything.
Take the enterprise graph further with Swfte
Start with one entry point. Add intelligence, agents, workflows and infrastructure as you prove value.