AI Copilot
AI configured for each tenant, on the provider you choose. Suggestions stay subject to review.
What it does
In a regulated GRC context the question is rarely capability. It is whether the risk register can be processed by a model the organization does not control.
The Copilot is gated on an AI provider configured and verified for your tenant. Point it at an OpenAI-compatible endpoint, including a model running entirely inside your own network. Each tenant has its own AI configuration and its own retrieval index, and the Copilot stays disabled until the provider has been verified.
It answers over your data through a defined tool layer rather than free-associating, and every draft and suggestion it produces is reviewable before it changes anything.
Ask the assistant
A conversational assistant that answers over your own data. It queries through a defined tool layer rather than free-associating over a prompt.
A tool layer means the answer comes from a query you could have run yourself, which is the only version of this a compliance function can rely on.
Which NCA ECC controls are still open in the retail perimeter?
Drafting
Draft policies, procedures, risk scenarios and report narratives, always produced as a reviewable draft rather than a published document.
The blank page is the expensive part of policy work. Review is cheap by comparison, and it keeps a person accountable for what gets published.
Suggestions
Control-gap suggestions, cross-framework mapping suggestions and risk-scenario suggestions, each explicitly accepted or dismissed by a person.
A suggestion a human accepted is defensible in an audit. A change the system made on its own is not.
Bring your own model
Configure an OpenAI-compatible provider for your tenant, including a fully local model. The Copilot stays disabled until the provider has been verified.
This is what makes AI approvable rather than merely available: where the model runs, and therefore where prompts are processed, depends on the provider you choose.
Retrieval
An optional vector-search layer indexes the platform knowledge base and your tenant content, with strict tenant isolation.
Retrieval is what lets the assistant cite your actual policy rather than a general one. Isolation is what lets you turn it on.
Usage visibility
Per-tenant AI usage reporting.
When you use your own provider, its costs are between you and that provider. Seeing what the Copilot consumed, by tenant, keeps that predictable.
Roles that live here
- Compliance Manager
- Risk Manager
- Policy Owner
- Tenant Administrator
Drawn from sixteen built-in roles, each scoped along the org tree. Access control
Related frameworks
See the Copilot running on your own model.
A 45-minute working session focused on the frameworks and requirements that matter to your organization.