Agents do the collection, the mapping, the testing and the drafting. Humans do the judgement. Every action carries its source, its confidence, its cost and the name of the person who signed it.
No login. Everything is fictional demo data. Press ⌘K to search anything, ⌘. for the Demo Director.
That is not a positioning line. It changes what the product can do, because the hard half — the runtime, the evaluation pipeline, the governance engine — already exists and already runs in production.
Build a GRC platform. Years later, bolt on an assistant that summarises, suggests and drafts. It helps a person work faster. It never does the work, and it cannot be governed as a worker because it was never designed as one.
Start with an agent platform already running nineteen agents across six industries, with a design DSL, an MCP Gateway runtime, seventy-three compliance checkpoints and an eight-domain governance audit. Point it at governance and risk. The agents are the labour, and governing them is a first-class module.
Enterprise GRC tools typically ship a flat menu of fifteen to twenty modules. Depth belongs inside a surface, not in the sidebar.
The position in dollars, what moved it, and the queue of things that genuinely need a person today — ordered by consequence, not by date. Board pack composed the moment you open it.
The hero object. Register, 5×5 matrix, appetite and tolerance, key risk indicators, quantification, taxonomy and treatments. Expected annual loss from real distributions, with every assumption inspectable.
Controls, continuous monitoring, question-based and requirement-based assessments, audits, one unified remediation backlog, and an evidence vault where reuse count is the number that matters.
The crosswalk: one control satisfying many regimes, computed rather than curated, with confidence, rationale and a human decision on every mapping. Plus obligations, gaps, policies, regulatory horizon and AI governance.
Critical operations and impact tolerance shaped for APRA CPS 230, third-party lifecycle and tiering, concentration and fourth-party exposure, incidents with the regulatory clock on screen, and continuity testing.
The agent fleet, a full run ledger, the human approval queue, and governance of the agents themselves. Plus Engagements — the advisory portfolio with its own delivery economics and cross-client benchmarks.
Narrow tool scope is not a limitation — it is the control. You cannot write a meaningful policy about a general assistant with broad access. You can about eight agents with four tools each.
| Agent | Job | Human gate |
|---|---|---|
| Mapper | Crosswalk & coverage. Maps controls to obligations across every adopted framework, with a confidence score, a rationale, and the specific objectives a partial match leaves unmet. | Every mapping accepted or rejected by a person |
| Prover | Evidence collection. Collects and refreshes evidence from connected systems, hashes and timestamps each artefact, attaches it to the controls it supports. | Auto below policy threshold; classified sources gated |
| Scout | Regulatory horizon. Watches regulator publications and traces each change through the obligation graph to the controls it touches. | Reviewed before it reaches the register |
| Quant | Quantification. Fits frequency and severity distributions, producing expected annual loss, a loss-exceedance curve and treatment return. | Assumptions reviewed before publication |
| Scribe | Drafting. Policies, treatment plans, assessment responses, regulator notifications and board narrative — always citing the records drawn from. | Always human-approved |
| Watch | Continuous control monitoring. Compares observed control state against its baseline, opens an issue on drift, escalates on tolerance breach. | Escalation is gated |
| Auditor | Audit support. Reproducible sample selection, workpapers drafted from attached evidence, findings written up for the lead. | Every workpaper and finding approved |
| Triage | Intake routing. Routes inbound assessments and vendor intake, pre-fills known answers, flags anything outside policy. | Auto within policy; exceptions queue |
Every run is recorded with its trigger, tool calls, reasoning steps, tokens, cost, duration, the policy checks it had to pass and the human decision on its output — replayable. Anything simulated in the demo is labelled Simulated in the interface. The production runtime is the BISTEC MCP Gateway.
“A CRO's most expensive question is is this normal? — and no single-tenant platform can answer it, because it holds exactly one data point.”
Press ⌘. anywhere in the demo. Persona, client, scenario, programme maturity and AI autonomy are all live switches on one build — so any “what if” is something to show rather than describe.
A severity-1 nine hours in, with the APRA CPS 234 seventy-two-hour clock running on screen. Watch raised it, Prover collected the evidence, Scribe drafted the notification, the CRO approved it.
Nothing built. Empty registers with honest empty states and the single action that starts the work — because every real engagement starts here, and every other demo pretends otherwise.
Set autonomy to off and walk any screen. Everything still works; the agents just stop. This is a GRC platform that happens to have a workforce, not an AI wrapper.
An agent breaches its declared tool scope. The policy engine blocks the write, rolls it back and quarantines the run before a record is touched — and you see it in the governance module.
Ninety-second executive, full platform, agentic deep dive, advisor economics, the compliance crosswalk, and incident response under a clock. The app stays clickable throughout.
Board director, CRO, risk analyst, compliance lead, internal audit, AI governance officer, advisory principal or client user — each with its own landing surface and a live permission preview.
Taxonomy workshop, adopt the frameworks in scope, connect two source systems, and Mapper proposes the first crosswalk for review. Median across the current book is nineteen days; fastest was nine.