What it does and does not do
Platform
The platform holds assessments, a scored reading with its gaps, roadmaps and learning paths, reports, a register of AI tools and vendors, and a dated log. Nothing is scanned. Every input is typed in or answered.
Read in fullCollapse
The platform holds six things: the assessments your people answer, a scored reading of where the organization stands with the gaps behind it, the roadmaps and learning paths generated from those answers, the reports built out of them, the register of AI tools and vendors somebody has entered, and a dated log of who did what. Every input arrives the same way, typed in by a person or answered in an assessment. Nothing is scanned, no configuration is read, no network traffic is observed, no model is tested, and no tool is discovered that your own people did not enter or adopt from the shared catalog. What it produces is an explicit, dated, attributable account of what your organization knows about its own AI use, which is a different thing from watching it.
the one way in
not inputs
- scanned
- configuration read
- network traffic observed
- model tested
- tool discovered
- the one way in, and the six stores
- not inputs: nothing is observed

Readiness assessment
Required roles
Creating, activating, and archiving need a consultant or company_admin. A contributor is shown individual-level assessments only.
Capabilities
Questions your own people write, with types, descriptions, and branching, authored at executive, department, or individual level, answered one response per person.
Limits
No instrument ships, so a new account has zero assessments. Completion is calculated on request, and two different formulas are in use.
Read in fullCollapse
Capabilities
A readiness assessment is a set of questions somebody in your organization writes and puts in front of the people who know the answers. Each question carries its own type, description, options, and branching rules, so what gets asked next can depend on the answer just given. Assessments are authored at one of three levels, executive, department, or individual, and the level decides who is shown the assessment. Answers are recorded per person, a response holding one answer per question, and a question can also collect ideas from the people answering, with votes on those ideas.
Limits
No instrument ships with the product. A newly provisioned account has zero assessments, and the questions are written by your consultant or your own admins. A level controls who is shown an assessment and nothing more, so no assessment is attached to a department and none carries a department field. Completion is calculated when something asks for it rather than stored, and two different formulas are in use, one over the responses that were started and one over an expected population of people times active assessments, so a completion figure means little without the formula that produced it.
Required roles
Creating, activating, and archiving an assessment requires a consultant or a company_admin, both roles you assign inside your own account, and editing one adds a condition the other three do not carry, that the assessment is still a draft. Our staff can do the same through a site_admin account, which sits outside every customer organization and is not a role you can give anyone in yours. Answering an assessment is governed separately, and a contributor is shown individual-level assessments only.

The secure score
Required roles
Generating and adjusting need a consultant or company_admin, never site_admin. Viewing extends to an executive or department head.
Capabilities
One number for the organization, holding a model reading and a reviewer reading, blended 0.6 to 0.4, with severity-rated gaps carrying NIST subcategories.
Limits
There is no score per department, per assessment, or per level, and no comparison against anything outside your account.
Read in fullCollapse
Capabilities
The secure score is one number for the organization, generated over every assessment in the account and stored with the date it carries. It holds two readings side by side, the model's score with its confidence and its written reasoning, and a reviewer's own score with notes, and where both exist the final score is the model's times 0.6 plus the reviewer's times 0.4, rounded, weights that are constants in code rather than a setting; where only one exists, that one stands. Gaps sit on that same record, each carrying a severity and, where one survived validation against a stored taxonomy of 4 functions, 19 categories, and 72 subcategories, a NIST AI RMF subcategory. Marking gaps addressed adds a severity-weighted bonus, critical counting 4 down to low counting 1, capped at 15 points, and records who marked each one and when.
Limits
There is no score per department, per assessment, or per level. The record has no department column, and even the department readiness report renders the one organization-wide figure. The score is also not a comparison against anything outside your account, since there is no industry average, no peer cohort, and no path by which another client's data reaches it. A score does not mean a control was tested: it reads what people answered, how much of the assessment was completed, how many people sit in each department, and which ideas were voted for, and when the model returns something that cannot be parsed it stores no number at all rather than a guess.
Required roles
Generating a score and adjusting one are limited to a consultant or a company_admin, both roles you assign inside your own account, and neither path admits a site_admin, the account our staff hold outside every customer organization. Adjusting is refused as well while a generation is still running. Regenerating an existing score runs through a different check and does admit our staff alongside those two roles. Viewing the score and exporting it as a PDF extend to executives and department heads.

Roadmaps and learning paths
Required roles
Generating needs a consultant, company_admin, or site_admin, once completion meets the threshold. Publishing needs the owner or company_admin.
Capabilities
Generated items, typically six to twelve, by phase and priority, each carrying one of five categories plus a validated NIST function and subcategory.
Limits
The platform holds no training material and tracks no completion, so an item is a title and a description with no course behind it.
Read in fullCollapse
Capabilities
A roadmap is a generated list of items, typically six to twelve, organized by phase and priority and scoped to whichever assessments you point it at. Each item is a title and a written description carrying one of five categories, security, governance, operations, technology, or training, plus a NIST function and subcategory that has to pass validation to survive. Items can be assigned to departments, given an implementation status once the roadmap is published, and carry file attachments, each one holding a malware scan status. A learning path is the same kind of record generated separately, its items organized by subject across generative AI, predictive analytics, data readiness, decision integration, and responsible AI, over four phases.
Limits
A learning path is not assigned by role: the function that creates one takes no role, and no role track or training level exists in the schema. The platform holds no training material and tracks no completion of any, so an item is a title and a description with no course, lesson, or curriculum behind it, and whether a roadmap contains a training item at all is the model's choice at generation time. Nothing chases the work either, since department assignment is per item rather than per person, and an item's implementation status changes when somebody sets it.
Required roles
Generating a roadmap or a learning path requires a consultant or a company_admin, both roles you assign inside your own account, or a site_admin account held by our staff, and it is refused until assessment completion meets the configured threshold. Publishing requires the roadmap's owner or a company_admin, so a consultant who did not create it cannot publish it, and our staff can publish it as well.

Reports
Required roles
Compiling needs a consultant or company_admin. An executive, department head, or contributor with view access can export.
Capabilities
Five fixed templates, assembled section by section with each section accepted or edited by a person, reviewable through four lenses, exportable as PDF.
Limits
The department readiness report prints only a department name and member count, and its progress and gap sections are organization-wide.
Read in fullCollapse
Capabilities
Five report templates ship, and each one is a fixed list of sections. The five templates are the executive overview, the board summary, the NIST compliance report, the remediation plan, and the department readiness report. A report is assembled section by section, each section accepted or edited by a person, and it cannot be finalized until every section has been accepted. The gap summary prints the NIST subcategory beside each of the top ten unaddressed gaps, wherever a subcategory passed validation. A report can be reviewed again through one of four lenses, executive, technical, compliance, or plain English, and a final or published report exports as a PDF.
Limits
The department readiness report is thinner than its name suggests, because its department section prints the department's name and member count while the progress and gap sections in it are organization-wide, including the single organization-wide score. A full-report review returns suggestions and changes nothing on its own, so the text moves only when someone accepts an edit. No report compiles on a schedule, and none appears without a person asking for it.
Required roles
Compiling a report requires a consultant or a company_admin, both roles you assign inside your own account, and it does not admit a site_admin, the account our staff hold outside every customer organization. Publishing is limited to the person who owns the report, and our staff can publish one as well. An executive, a department head, or a contributor with view access can export a final or published report as a PDF.

Vendors, tools, and cost
Required roles
Entering or editing tools and vendors needs a consultant, company_admin, or site_admin. An invited vendor edits one record.
Capabilities
A register of tools and vendors your people enter, with cost normalized to a monthly figure, department allocation, and redundancy flagged inside a category.
Limits
Nothing discovers a tool, because there is no scan, no OAuth introspection, and no spend feed. No return on investment is computed anywhere.
Read in fullCollapse
Capabilities
The register holds what your people enter or adopt from the shared catalog: each tool with its vendor, category, cost terms, license count, and a status of active, inactive, or evaluation, and each vendor able to hold contracts with renewal windows, documents with expiry dates, quotes, evaluations, and a risk tier. Cost analysis is computed the moment you ask for it, converting every tool to a monthly figure, which is what makes two differently priced tools comparable: monthly, quarterly, and annual subscriptions, per-user pricing multiplied by the license count, one-time costs spread over twelve months, usage-based pricing, and free tools at zero. Departments can be allocated a percentage of a tool's cost, and where no percentage has been set, that view charges the department the full cost. Redundancy is reported where two or more active tools in the same category share at least one department, with the potential saving shown as their total minus the cheapest of them.
Limits
Nothing discovers a tool, because there is no scan, no OAuth introspection, no network observation, and no spend feed, and the monthly usage figures for active users and sessions are typed in by a person with every field optional. Approval belongs to the shared catalog, where our staff review a submitted vendor or tool before it becomes visible to everyone, so your own register carries no approval state, no approver, and no approval date, and activating or deactivating a tool is a lifecycle switch that records none of the three. Two same-category tools held by different departments produce no redundancy finding. No return on investment is computed anywhere, because cost is never joined to scores, roadmaps, or outcomes, and where the cost analysis suggests looking at whether wider adoption of a tool used by one department would improve its return, it works out no such figure.
Required roles
Entering a tool or a vendor by hand and editing one afterwards requires a consultant or a company_admin, both roles you assign inside your own account, or a site_admin account held by our staff. Recording a month of usage takes the same permission. A vendor you invite gets a login inside your account once the invitation is accepted, and that login can edit the single vendor record its contact email or accepted invitation matches. Viewing tools and the cost analysis extends to executives.

What the record keeps
Required roles
The activity log is readable by a company_admin only, plus our staff through a site_admin account.
Capabilities
A log that cannot be rewritten, where rows refuse updates and deletes, recording who caused each change, written from 102 explicit call sites.
Limits
Authentication is not logged at all, and logging is explicit, so the vendor lookup and the two report review paths write no generation record.
Read in fullCollapse
Capabilities
Actions are written to a log that cannot be rewritten, where rows refuse updates and deletes and each one records who caused it and what changed. Score generations and regenerations, a reviewer's adjustment with the score before and after, gaps marked addressed or reopened, and changes to assessments, responses, questions, ideas, reports, roadmaps, files, tools, vendors, users, and departments are all recorded, from 102 explicit call sites in the code. An AI generation is kept as its own record wherever the code writes one, holding the type, the prompt and the assembled system prompt, the model identifier, the raw result it returned, and the prompt, completion, and total token counts. Department standing persists only as leaderboard snapshots, whose adoption score averages assessment completion and roadmap implementation in equal halves, and those are written when somebody opens the leaderboard rather than on a schedule, so a day when nobody looks leaves no snapshot.
Limits
Authentication is not logged at all, with no login, logout, failed login, password reset, or MFA event recorded, so this is not a login audit trail. Logging is explicit rather than automatic, which means the record is what the code writes and no more: the vendor lookup and the two report review paths, one working section by section and one over the whole report, call the model without writing a generation record, and their tokens go uncounted. The stored system prompt is also not byte for byte what went to the provider, because an organization-level safety prefix is added at call time and is not kept. The log itself does not sit in a database of its own either, since it lives in the shared platform database with a tenant identifier on every row, and a read of your account's log filters on that identifier.
Required roles
The account's activity log is readable by a company_admin, the only role inside your own account that can open it, so an executive, a consultant, a department head, or a contributor cannot. Our staff can read it as well, through a site_admin account that sits outside every customer organization.
What the platform does not do
It does not sit in the path of a live request, block a call, or apply a guardrail. It watches nothing over time, so there is no alerting.
Read in fullCollapse
Two limits belong to the platform as a whole rather than to any one of the six sections. It does not sit in the path of a live request, block a call, enforce a policy, or apply a guardrail. And it does not watch anything over time, so there is no continuous monitoring, no alerting, and no drift detection, and nothing is recomputed on a schedule except two checks for expiring vendor contracts and documents. Every other limit is stated beside the capability it belongs to, in the section that owns it.