Skip to content

The governance model

Since 0.1.0

Ajutant is built so that control isn’t bolted on, it runs through the whole platform. Here’s how the pieces fit.

People sign in with their Microsoft account, from directories you explicitly trust. Access is governed by roles and capabilities, and the same capability gates both the interface and the API.

Every conversation passes through guardrails, including PII detection and redaction. Answers are grounded in documents you control, with citations. Where assistants use tools, write actions can be held for approval.

Changes to assistants move through drafts and versions, optionally behind approval, with a kill switch for emergencies. Everything of consequence is written to an immutable audit log.

The platform runs in your own cloud tenant. Documents, conversations, and models stay under your control, with classification, lawful basis, and retention available for regulated data.

The monitoring area and the reporting space let you see usage, cost, failures, and feedback, so governance is observable, not just asserted.