What it does, and what it will not do.
Eight mechanisms, in the order they run. Each one has an artifact behind it, and each one has a boundary we name here rather than in the demo.
The record.
What the system knows about how your firm decides, and where every piece of it came from.
Exception Register
The rule nobody wrote down, on the record, with the name of whoever decided it.
The policy says twelve business days. For this client it is a partner review, and that decision exists in exactly one email. Writguard makes it a typed record: the exception, its authority tier, the person who decided it, and the sentence it came from. It is then served ahead of the policy it overrides. Exceptions are one of four node types in the record, not a tag on a document.
exception extraction measured at 0.500 precision and 0.500 recall against a frozen synthetic truth pack. Retrieval of exceptions already in the record is a separate measurement: recall@5 1.000 against a baseline’s 0.833.
Authority Tiers
A signed policy outranks a chat message. By rule, not by model.
Every fact in the record carries an authority tier, A1 to A5: a signed engagement letter at the top, an unattributed chat message at the bottom. When two sources disagree the tier decides which one serves, deterministically, before ranking. No language model is asked to judge which document your firm considers binding.
open any served rule and read its tier and its decider on the same line.
Chain of Custody
Every fact carries the sentence it came from, and the address to open it.
Not a link to a document. The quoted line, the source locator, the tier and the timestamp, attached to the fact itself and carried per line into the compiled skill. A rule that has been replaced is kept as history and never served as current, so you can read what it used to be and when it changed. Citations are addresses: brain:// locators that resolve.
read a rule aloud with its citation, then open the citation.
The writ.
What your agents receive, and whose name is on it.
Skill Compiler
Skills, compiled from the record. Nobody types them.
Two role surfaces come out of one subgraph with zero hand editing: provenance, role scope and forbidden tools are all derived from the record rather than written by a person. Each bundle carries the capability boundary this company is named for — per step, what the agent owns, what it may draft, and what it may never touch, with forbidden tools removed and asserted negatively. Change a governed rule, recompile, and behaviour changes while the generated test packs still pass.
change the twelve-day rule to ten, recompile, and diff the bundle.
Approval Packet
Nothing consequential commits without a named human on the record.
An action arrives as a packet: what it will do, on whose authority, with its evidence attached and a named approver. Approve it and it commits with that name bound to it. An unauthorised approver is rejected deterministically, not warned. A contradiction arrives the same way, so a challenge to a live rule queues for a person while the rule it challenges keeps serving, rather than overwriting it.
watch a challenge sit pending while the policy it disputes continues to answer.
Amendment
Correct it once, with your name on it. Everything compiled after that carries the change.
A correction is not a note in a chat window that disappears. It enters the record as governed knowledge, with an approver, a timestamp, a source quote and an authority tier, and every skill compiled from that point on reflects it. On our synthetic tenant a correction reached a case the system had never been shown, twice, where an ungoverned playbook memorised the case it was given instead. On real company data this has not been tested, and we do not claim it.
one synthetic fixture tenant · novel-Exception corrections · a correctable pool of three · n = 2. Eight of eight thresholds, pre-registered and sealed before the run. Six registrations were consumed; three measured NOT MET.
The guard.
What happens when someone asks for something they may not have.
Scope Lock
The permission is in the query, not a filter after it.
Two people ask the same question. The partner’s key returns the payroll figure with a citation. The staff key never has that figure in hand at any point in the request, because permission is enforced in SQL before anything is generated. The second answer therefore carries zero source references rather than a tidied version of the first.
one synthetic fixture tenant, 36 frozen questions, one frozen grader. Zero permission leaks against the baseline’s one.
Refusal Contract
Out of scope returns nothing. Not a softened answer, not a redacted one.
A refusal is a designed state with its own surface: a solid block where the value would have been, and zero source references behind it. The asker learns that something exists and that it is not theirs, which is the honest answer, and the content never enters the request at any point.
this is the permission refusal, and only that. A refusal for insufficient evidence was built, measured, and rejected on the evidence; it is not in the product and not claimed here.
Six more, one line each.
Real, and narrower than a section of their own.
- One Door Every surface, whether the app, an MCP client or an agent, arrives through one permission implementation, with an audit row per call.
- Portable Record Your brain is markdown and git you can read, diff and take with you.
- Cost Census It prices the job before it spends a cent, and it is provably unable to spend while doing it.
- Quarantine Untrusted content stops at a deterministic boundary, before any model.
- Supersession The old rule is kept as history and never served as current.
- Fail-Closed Reconcile An incomplete enumeration writes zero deletions, and proves it with an identical record digest.
What none of this does.
Every mechanism above has a boundary. They are collected here so you do not have to find them in the demo.
- Our connectors are file adapters. A live mailbox connector is not something you switch on; the first integration is work we would do with you.
- It does not compose answers. The gateway returns governed sources with citations, and a guard in the build enforces that. It is a boundary, not a gap.
- Nothing here has been measured on a customer’s data, because there are no customers. You would be the first.
- The correction loop is proven as a mechanism at the scope printed under it, and not beyond it. We do not claim the system gets better on its own, because we have not shown it.
- Answer quality in Arabic is measured at 0.333. Retrieval is language-agnostic; answers are not.
- Tested to 3,000 documents, not 300,000. We do not know where it degrades.
- No SOC 2, no ISO 27001, no penetration test. We describe the controls and never the badge.
We would rather you found the limit here than in the demo.