Any advice is welcome for our product launch - acipta.ai
An agent inventory is a snapshot of the present. Governance of consequential automated decisions is a question about the past: which agent acted, what permissions did it hold at that moment, which controls applied then, what evidence did it rely on, was an exception made, who approved it. Permissions change. Models get deprecated. Policies get revised. The agent itself is rewritten. A governance posture that documents current state has, by construction, no answer to any question about a decision made before the last change — which is to say, no answer to any question a regulator is likely to ask.
This is the same problem acipta was already built to solve for human compliance decisions, arriving at much larger scale from a different direction. That is a genuinely fortunate position for a company to be in, and it is not an accident: the architecture was designed around the durability of the record rather than the convenience of the workflow, which makes it indifferent to whether the decider was a person or a process.
We've been on the other side of the audit
Most compliance software is built by people who have read about audits. Ours is built by three people who have sat in them — on the side of the table where someone asks a question about a decision made two years ago, and the honest answer is "I think so, let me find out."
That sentence is the whole company. Everything acipta does is an attempt to make it unnecessary.
There is a particular species of dread familiar to anyone who has run a regulated program. It is not the fear of having done the wrong thing. It is the fear of having done the right thing and being unable to demonstrate it. The control ran. The review happened. The exception was approved by someone senior and reasonable. And then eighteen months later a regulator, a plaintiff's counsel, or an incoming auditor asks which version of the page was that who approved it, and what were they looking at when they did — and the record is a screenshot in a shared drive, named final_v3_USE_THIS.png.
We are not building a workflow tool that happens to store evidence. We are building evidence machinery that happens to have a workflow. The distinction sounds academic until the day it isn't, and every one of us has had that day.

Replies