Governance
Human authority, by architecture.
This page is written to be forwarded. It states plainly what agents can never do, how maker–checker is enforced, what the audit trail contains, and where data lives. Every claim on this page is verifiable; anything not yet achieved is labelled planned.
1 · The authority model
Axiom Minds separates proposal from approval at the architecture level. Agents hold no execution authority for consequential steps; approval authority is held by named humans and cannot be delegated to an agent.
- Propose actions, drafts, and reconciliations
- Orchestrate handoffs between systems and teams
- Route decisions to accountable owners
- Surface approvals with evidence attached
- Approve or sign any consequential step
- Execute before a human signature releases execution
- Edit, reorder, or delete audit entries
- Override a human decision
2 · Maker–checker, mapped
The discipline your regulators already require, enforced structurally. The maker may be an agent or a person; the checker is always a named human with authority under your delegation matrix.
3 · Audit trail & evidence
Every proposal, routing, approval, send-back and override is written as an append-only, hash-chained entry: actor, action, timestamp, evidence references, and the policy checks in force at that moment. Entries are exportable in formats your auditors accept.
- Append-only — no entry can be edited or deleted, by anyone
- Hash-chained — tampering breaks the chain visibly
- Named actors — every signature maps to a person, every proposal to an agent identity
- Exportable — evidence packs for internal audit, statutory audit, and regulators
4 · Data residency & DPDP stance
Built for the compliance requirements of Indian enterprise and structured to meet global governance standards.
India-resident deployment
Customer deployments are designed for India-region hosting, with data residency documented per engagement. Sector-specific residency requirements (RBI, IRDAI) are addressed in the deployment architecture, not as an afterthought.
DPDP Act 2023
On this website: no tracking before consent, purpose limitation on form data, a named grievance contact, and a documented deletion path — see the privacy policy. In the product: personal data processing follows the same consent and purpose-limitation discipline.
Access & logging
Role-based access mapped to your delegation matrix; administrative actions logged to the same append-only trail as workflow actions.
Global alignment
Control design references SOC 2 and ISO 27001 control families and tracks the EU AI Act's human-oversight requirements for high-risk systems.
5 · Certifications roadmap
We publish only what is true. Certifications appear here as planned until the certificate is issued — then, and only then, the label changes.
Questions risk teams ask.
What can Axiom Minds agents never do?
Agents never approve, never execute consequential actions before a human signature, never edit the audit trail, and never override a human decision. This is architectural, not configurable.
Is this the same as human-in-the-loop?
No. Human-in-the-loop is a pipeline-architecture term. Axiom Minds implements human authority: a governance model in which a named, accountable human signs off on every consequential outcome, enforced by maker–checker structure and a sealed audit trail.
How is the DPDP Act 2023 handled?
Consent before any tracking, purpose limitation on form data, a named grievance contact, and a documented data-deletion path — set out in the privacy policy.
Which certifications do you hold today?
None yet — and we say so. SOC 2 Type II and ISO 27001 are planned; the roadmap above is updated only when a certificate is issued.
Forward this page. Then let's talk.
If your risk team has a question this page doesn't answer, we want to hear it — governance questions make the product better.