Trust & Governance · For Regulated Industries
Autonomy that survives your regulator.
Regulated buyers ask three questions of any autonomous system: who approves what, can you prove what happened, and can you trace every output to its inputs. In Sentient.AI Agentic, the answers are properties of the runtime — enforced in code, verifiable on demand — not paragraphs in a policy binder.
01 · Human in the loop
Every human decision: identified, reasoned, recorded.
Judgment stays human — and the runtime makes sure it stays accountable.
ATTRIBUTION
No anonymous approvals
Exception resolutions require an authenticated actor. Approve, route, or override — the person, the timestamp, and the decision are recorded on the exception and appended to the Evidence Ledger under a dedicated human-in-the-loop control.
RATIONALE
Overrides require reasons
Overriding an agent’s proposal without a written rationale is rejected by the API, not discouraged by a policy. The rationale travels with the evidence, so reviewers see not just what was decided but why.
GATING
Autonomy is earned, per threshold
The autonomy dial (A0–A4) is set per agent, per entity, per materiality threshold. Above threshold, agents prepare and humans release. Promotions are maker-checker approved with the supporting evidence attached.
02 · Auditability
A ledger you can test, not trust.
Every agent action and every human decision is written to the Evidence Ledger as a cryptographically hash-chained record: each entry binds its predecessor, its timestamp, its actor, and the control it ran under. Alter any historical record and chain verification pinpoints the exact broken entry.
TAMPER-EVIDENT
Chain verification on demand
The full ledger recomputes from genesis at any time — in the product UI and via API. Auditors don’t take integrity on faith; they re-run it.
POPULATIONS, NOT SAMPLES
100% testing
Because evidence is a by-product of execution, controls are tested against entire transaction populations continuously — not 25 samples at year-end.
EXPORTABLE
The evidence packet
One export produces the auditor packet: verified chain status, the complete ledger, attributed human decisions with rationales, and run-level step records.

SENTIENT CONTROL TOWER · CHAIN INTEGRITY RECOMPUTED LIVE · HUMAN DECISIONS ATTRIBUTED ON THE LEDGER
03 · Traceability
From output back to input, every time.
Every agent run decomposes into timestamped steps; every step lands on the ledger with its agent, control ID, and actor; every ledger entry carries its position in the chain. A journal, a payment, a certification — each traces back through the run that produced it to the data and policy it was produced from. The v2 runtime extends this lineage to pinned model and prompt versions per run.
The control mapping
Mechanism → framework, line by line.
| Runtime mechanism | SOC 2 (TSC) | ISO 27001:2022 | SOX / COSO | EU AI Act |
|---|---|---|---|---|
| Hash-chained Evidence Ledger | CC4.1, CC7.2–7.3 — monitoring & log integrity | A.8.15 Logging · A.8.16 Monitoring | Evidence completeness for control testing | Art. 12 Record-keeping |
| Attributed HITL + mandatory override rationale | CC2.1, CC5.1–5.3 — accountability & control activities | A.5.3 Segregation of duties | Maker-checker; management review | Art. 14 Human oversight |
| Run → step → record traceability + evidence export | CC7.x; processing integrity | A.5.28 Evidence collection | Audit trail enabling population-level testing | Art. 12, Art. 19 |
| Autonomy dial with evidenced promotions | CC3.x Risk assessment | A.5.1 Policies, operationalized | Change control on automated controls | Art. 9 Risk management · Art. 14 |
| Kill-switch, replay, observability (AgentOps) | CC7.4–7.5 Incident management | A.5.24–5.26 Incident response | Corrective action | Art. 15 Accuracy & robustness |
| SSO/RBAC inheriting ERP entitlements · customer-managed keys | CC6.x Logical access | A.5.15 Access control · A.8.24 Cryptography | ITGC access-to-programs-and-data | — |
Certification status, stated plainly: SOC 2 Type II and ISO 27001 programs are underway; ISO 42001 is on the roadmap. We publish status, not aspiration — and the mechanisms above are demonstrable in the product today.
Start the conversation
Bring your auditors.
A governance briefing for risk, audit, and compliance leaders — chain verification, attribution, and the evidence packet, demonstrated live.