Documentation
Understand
Fiducia OS.
A guide to the platform: what Assurance is, how a finding is produced and held to account, how it is built, and how you integrate it. For a live walkthrough against your own estate, book a session.
Overview
Fiducia OS is the governance layer for the agentic enterprise. Its production offering, Assurance, is an AI-native IT risk management and governance platform built for the second and third lines of defense at regulated financial institutions. It ingests your frameworks, policies, and live operational data, maps controls to risks continuously, tests controls across the full population, and generates audit-ready evidence, replacing manual spreadsheets and point-in-time sampling.
Governance platforms ask whether AI is safe to deploy. Agent security asks whether an agent is compromised. Fiducia asks whether an autonomous action stayed within enterprise authority, risk appetite, and regulatory obligation, and produces the evidence that answers it.
The three products
Three products sit on one shared substrate. Assurance is in production and carries everything documented here. Provenance and Runtime are in development; their status is stated wherever they appear.
Assurance
In productionContinuous, population-scale control testing for the second and third lines of defense. Ingest frameworks, policies, and live data; map controls to risks; test across the full population; generate audit-ready evidence.
Provenance
In developmentKnow what can act: a registry of the AI-consuming estate, full-spectrum lineage from a decision back to the delegating executive, and shadow-authority detection.
Runtime
In developmentGovern the action: a policy decision point returning allow, allow-with-conditions, step-up, escalate, or deny, with the full derivation behind it.
How it works
Every finding travels one path, and that path is the platform's central governance control. Generation and evaluation are kept structurally separate, and no AI-generated finding, score, or recommendation reaches a human reviewer without passing structured evaluation first.
- 01Agent
Assembles context, reasons, and drafts the finding.
- 02LLM-as-Judge
Scores against calibrated rubrics. It never generates findings.
- 03Consensus
Independent agents must converge, or the finding escalates.
- 04Human in the loop
A named reviewer validates, modifies, or rejects. The decision of record.
- 05Ledger
Append-only and lineage-traced, exportable to your SIEM.
Where humans are mandatory
Human-in-the-loop is a designed control, not a fallback. Agents recommend; named people decide.
- All critical and high severity findings require human validation before escalation or reporting.
- Any compliance score below a configurable threshold triggers human review.
- Agent-recommended remediation actions require human approval before execution.
- Consensus disagreements route to qualified human reviewers.
- Any action evaluated as outside a delegated authority limit routes to the named accountable human.
The platform
Assurance runs six tiers, each operated by a specialized agent with expert humans in the loop. Most platforms stop at the first tier, an inventory or a system of record. Fiducia runs all six as one connected fabric, which is what lets a finding carry its obligation, its authority, its evidence, and its lineage in a single object.
Asset-Control-Authority Graph
Governance Graph agent
Every asset, control, identity, vendor, obligation, and delegation of authority, unified as one live, queryable model.
Real-Time Telemetry
Source-Pulled Evidence agent
Operating effectiveness pulled straight from source systems. Evidence at the source, not screenshots.
Continuous Monitoring
Control-Testing agent
Full-population pass or fail, scored per control and per asset, in real time.
Proactive Avoidance
Pre-Deploy Validation agent
Risk caught in CI/CD pipelines and infrastructure-as-code before deployments land.
Remediation Intelligence
Sustained-Closure agent
Root cause, dependencies, and suggested actions, with closure defined as control behavior held over time. The analyst stays in command.
Regulatory Update Loop
Regulation Specialist agent
Live regulatory ingestion, pre-go-live readiness, and fine-pattern signals before enforcement.
The shared substrate
Governance Graph
The asset-control-authority model that holds the institution's governance reality: obligations, risks, policies, appetite, controls, authorities, assets, actors, decisions, and evidence.
Authority & Policy Compiler
Turns regulation and internal charter into executable controls.
Decision & Evidence Ledger
Records every material action and decision in append-only, lineage-traced form.
Integration Fabric
Federates the systems the institution already runs, through read-only connectors.
See the plane-by-plane view on the platform overview.
Determinism for regulated environments
Regulators require reproducibility. A score of 78 out of 100 must mean the same thing whether it was generated by the system or assessed by a human expert. Fiducia resolves the tension between stochastic models and a deterministic mandate by wrapping the model in a governance framework, not by constraining it into uselessness.
Structured prompt templates
Every validation uses versioned templates that fix the questions, the evidence considered, the scoring criteria, and the output format.
Multi-agent consensus
For critical validations, independent agents run against the same evidence; disagreement beyond threshold escalates to a human.
LLM-as-Judge scoring
A separate judge evaluates whether findings are well grounded and consistently scored. It never generates findings, mirroring the audit model.
Human approval gates
Mandatory human validation at defined decision points, with a complete approval trail of who validated what, when, and what changed.
Authority evaluation is deterministic and involves no model at all.
Integrations
The Integration Fabric provides more than twenty native connectors on a connect-once, govern-everything model. Assurance reads the systems you already run, produces the independent challenge evidence your second line stands behind, and pushes findings and evidence out to the tools you report from.
API-first
Every integration follows a standardized API pattern, so ingestion is consistent regardless of source system.
Read-only
Assurance operates with read-only credentials and cannot modify, delete, or corrupt operational data. There is no write path to fail open.
Continuous sync
Data is ingested continuously rather than in batch, so compliance posture reflects the current state, not a stale snapshot.
Data stays in the tenant
Ingested data is processed and stored within your tenant boundary and is never used for model training.
Reads from
- GRC platforms: ServiceNow, Archer, SAP GRC
- ITSM & CMDB: ServiceNow, BMC, Jira
- Policy repositories: SharePoint, Confluence
- Agent platforms: Agent 365, Bedrock AgentCore, Vertex, Agentforce, MCP gateways
- Regulatory feeds: Thomson Reuters, LexisNexis
- Risk & vulnerability: Riskonnect, Qualys, Tenable
- Identity & access: Okta, Entra ID, SailPoint
Pushes to
- BI & data catalogs: Tableau, Power BI, Looker, Collibra, Atlan
- SIEM, alerting & ticketing: Splunk, PagerDuty, Slack, Jira, ServiceNow, Asana
Deployment options
SaaS Cloud
Fiducia-hosted and fully managed, with tenant isolation and tenant-scoped keys. Model inference on the SaaS path is governed by the Fiducia agreement, with zero retention and no training.
Private Cloud
Deployed in your own cloud account (AWS, Azure, or GCP), using your own model gateway and tokens under your provider terms.
On-premises
Deployed inside your perimeter for the strictest data-residency requirements.
Workspace & roles
What a user sees is a workspace of linked registers, each a view onto the same Governance Graph. Six personas carry pre-defined permissions and scope to domains, so a steward for one domain sees that domain and nothing else.
Enterprise Asset Inventory
Critical IT assets annotated with criticality, environment, hosting, exposure, and business owner. A single, always-current asset and risk picture.
Issues Register
Control failures across the enterprise with severity, status, violation counts, and linked asset. Built for second-line triage.
Project Workspace
Active and completed change and architecture projects with frameworks, timelines, and compliance posture.
Risk Register
Risks linked to assets, controls, issues, and projects, with inherent and residual scoring, appetite, and treatment tracking.
Personas
IT Risk Manager
2nd line
Risk assessment, validation runs, remediation tracking, review queues, the full register workspace.
CISO
2nd line
Security control effectiveness, vulnerability posture, incident response, security metrics.
CRO
2nd line
Enterprise risk heatmap, appetite versus actual, delegated-authority exceptions, treatment status, board reporting.
Compliance Officer
2nd line
Regulatory compliance status, audit readiness, policy adherence, compliance gaps.
Internal Auditor
3rd line
Read-only access across the full governance lifecycle: findings, evidence chains, remediation trails, decision traces.
Product Owner
Admin
Portfolio, compliance scope, and validation administration.
Coverage
Coverage is maintained in bands, and a framework is listed only where its obligations are parsed to clause level and mapped to controls, so a control you enforce is already tied to the obligation it satisfies.
Supervisory (US)
OCC bulletins, Federal Reserve and FDIC interagency guidance, FFIEC IT Examination Handbook, NYDFS Part 500.
AI-specific
EU AI Act, NIST AI RMF, ISO 42001.
Sector & security
DORA, MiFID II, Basel III, ISO 27001, NIST CSF, SOC 2, CIS, GDPR, HIPAA, PCI DSS.
Browse the mapped rules on Solutions.
API
Everything available in the console is reachable through a REST API with scoped, member-bound service tokens, which is how most institutions wire Assurance into existing GRC and reporting tooling. Tokens are self-service for the Product Owner persona. Writes are limited to platform records; there is no API path that writes to a connected source system, by design.
/v1/frameworksList ingested frameworks and their clause-cited obligations.
/v1/authoritiesRead recorded delegations of authority with their terms, approver, and validity window.
/v1/validationsStart a validation run for a given scope, control set, and framework.
/v1/validations/{id}/findingsRetrieve run status and the findings it produced, with scores and citations.
/v1/findings/{id}/traceRetrieve the decision trace: context, reasoning, authority derivation, evaluation, and human decision.
/v1/issuesRead the issues register, or create an issue against an asset.
/v1/risksRead the risk register with inherent and residual scoring and treatment status.
/v1/reportsRequest an evidence pack or report; poll for completion and download.
/v1/audit-eventsRead platform audit events for a date range, actor, or object.
List endpoints are cursor-paginated, responses are rate-limited per token, and every response carries a request id to quote in a support case. Full endpoint schemas and sandbox access are available from your account team.
Core concepts
The lexicon: the words the platform uses, defined once and used consistently.
- The SeamWhere data becomes a decision.
- The join between the data estate and the AI estate. Both run well alone. The unmanaged place between them is where AI failures actually happen, and today no one owns it.
- The EstateEverything that can read data or act.
- Datasets, models, copilots, agents, service accounts, and third parties. If it can read or act, it is in the estate, and it is in scope.
- The Consequence GapThe time between an action and its effect.
- Old controls all depended on this gap being wide enough for a person to step in. Autonomy closes it to zero, which is why controls that review after the fact stop working.
- Standing AuthorityWhat an agent may do while idle.
- The real surface of autonomy is not what an agent is doing now, it is what it is allowed to do at any moment. Standing authority is the access that sits there waiting to be used or abused.
- The Authority LadderFive rungs of what a system may do.
- From read only, to suggest, to act within reversible bounds, to consequential action, to self directed inside a mandate. Every step up is declared and recorded, never a default.
- Shadow AutonomyTools quietly gaining the power to act.
- A copilot that starts writing back. A workflow that starts deciding. Authority no one granted on purpose, accumulating faster than any audit can catch.
- The Attribution TripleWhich agent, for whom, under what authority.
- Every action answers all three or it does not commit. It is the minimum record that makes an autonomous action accountable to a person and a policy.
- Blast RadiusHow far one confused agent can reach.
- Least privilege is not hygiene here. It is the containment boundary that decides whether one compromised agent touches one account or ten thousand.
- The Trust GateNothing reaches a model until it clears.
- A single checkpoint between the data estate and any model, asking three questions: is it sensitive, is it sound, do we know where it came from.
- The Kill SwitchStop one action, or everything, at once.
- Immediate, total, and tested. An agent that cannot be stopped is an agent that cannot be deployed. Not a feature. The precondition for deployment.
- Living EvidenceProof that writes itself.
- The audit trail is a byproduct of governed execution, current the moment anyone asks. Not a binder assembled for an exam, and never stale.
- Proof on DemandThe exam becomes a query.
- Ask the system a question a regulator would ask, and the record answers with the dossier and the evidence attached.
- The Governance GraphThe live map that ties it all together.
- Every dataset, model, agent, control, and rule, connected. Pull one node and see everything it touches. Impact analysis becomes a gesture instead of a project.
- The Examination SurfaceEvery question an examiner can ask.
- The full set of questions a regulator could put to you, and whether you can answer each one right now. Fiducia shrinks the unanswered part of that surface to nothing.
Frequently asked
What is Fiducia?
Fiducia is the governance layer for the agentic enterprise. Its production offering, Assurance, is an AI-native IT risk management and governance platform built for the second and third lines of defense at regulated financial institutions. It ingests your frameworks, policies, and live operational data, maps controls to risks continuously, tests controls across the full population, and generates audit-ready evidence, replacing manual spreadsheets and point-in-time sampling.
Do we have to replace our GRC platform to use Fiducia?
No. Fiducia reads from your GRC platform, ITSM, CMDB, and the rest of the estate through read-only connectors, and produces independent challenge evidence alongside them. Institutions typically run both, with Fiducia as the evidence and assurance layer, and revisit the system-of-record question at their own pace.
How is this different from an AI security tool that blocks agent actions?
A security tool blocks on anomaly, when behavior looks wrong. Fiducia evaluates against institutional authority, so an outcome cites the rule, the control, the appetite clause, and the obligation behind it. Both are useful and neither replaces the other, and security telemetry can be a source into the governance graph. Assurance evaluates and evidences actions today; enforcing at the moment of action is the Runtime plane, which is in development.
Does Fiducia write anything back into our systems?
No. Connections are read-only, and write-capable credentials are rejected at setup. Where an outbound integration creates a ticket or a message in another system, that action runs under credentials you supply for that integration and is subject to that system's permissions.
Is our data used to train models?
No, in any deployment model. The platform documentation sets out the full position, including the terms that apply to model serving.
Can the AI close a finding or change a risk rating on its own?
No. Agents propose, people decide. Every finding arrives with the rule it maps to, its pass or fail, and the evidence behind it, and the decision you record in the review queue is the decision of record.
Will the same question always get the same answer?
The governance outcome is designed to be reproducible: the same control assessed against the same evidence and methodology produces the same result, and the methodology itself is versioned. Authority evaluation is deterministic and involves no model at all.
How do we explain a finding to an examiner?
Open the finding's decision trace and export it. It carries the context, the reasoning, the authority derivation from control to appetite clause to obligation, the evaluation, and the human decision. It is the chain most examiners ask for.
What is the difference between shadow AI autonomy and shadow authority?
Shadow autonomy is the risk that an agent acts beyond its authorized scope. Shadow authority is the measurable instance: an action for which no valid delegation path existed at that moment. The first is a category of concern; the second is a finding you can act on.
Need help?
Visit Support for channels, how cases are classified, and what to send, or book a working session to walk it against your own estate.
More in the documentation
See it on your own estate.
A 30 minute working session against a control, an agent, or a rule you already answer to.