Governance & security

Governance, auditability, and oversight for company AI.

Maveric gives every employee a capable AI assistant — and gives you control over the data it touches, who can use what, and a full record of everything it does. Governance isn't an add-on here; it's the foundation.

Where does data go?

You decide where company data lives — and what AI can touch.

Data stays in the regions and systems you choose, and credentials are never exposed.

Data residency (AU)
Keep data in Australia with on-shore and on-premise deployment options on Enterprise.
Encrypted credentials in Vault
Connection secrets are encrypted in Vault and decrypted only at run time — never shown in logs or audit trails.
Environments stay isolated
Development, staging, and production run with their own scoped secrets, so a test config can't reach live data.

Who can access what?

Role-based access decides what every person and assistant can reach.

Roles and groups scope who can use which assistants, knowledge bases, connections, and actions — least privilege by default. The Company Brain makes that access model something you can see, not just configure.

UserRolePermissionSkillKnowledgeConnectionActionAgent
MEDIA PLACEHOLDERscreenshot · 16:9

Role and permission controls

An admin view showing role-based access to assistants, knowledge bases, connections, and actions.

What gets logged?

Every action is recorded — automatically.

There are no black boxes. Each prompt, data source, tool, and write leaves an accountable trail you can review.

Audit log on every write
Every create, update, and delete records the actor, the action, and a row-level diff — on by default, not an add-on.
Prompts and sources, traced
See which data sources and tools an answer drew on, so you can trace exactly how a result was produced.
An immutable trail
The record is captured automatically, so accountability never depends on someone remembering to switch it on.
MEDIA PLACEHOLDERscreenshot · 16:9

Audit log

An admin view showing a prompt/action audit trail with user, data sources, tools used, approval status, and timestamp.

How are tools and actions controlled?

The Assistant can only do what you let it do.

It reaches the systems you connect, within the roles you grant — and a person can stay in the loop on anything high-stakes.

Scoped tools via Connections
The Assistant can only read and act in the systems you connect — nothing reaches a tool you haven't approved.
Actions follow least privilege
Roles decide who can build, run, publish, and administer each resource, so people only act within what their role allows.
Human-in-the-loop approvals
Insert approval steps so a person reviews high-stakes actions before an agent executes them.

How can admins review usage?

Admins can see how AI is used across the company.

Oversight isn't a one-off audit. Admins can review who's using which assistants and data, and adjust access and controls as things change.

Trust & compliance

Controls your teams can review.

We keep public claims focused on what the product does: data residency options, encrypted credentials, scoped access, and audit logging.

Australian Privacy Principles

Questions

Security questions, answered.

Certifications, data residency, access control, logging, and action controls — the details your risk team asks about first.

Review our controls with your security team.

Book a demo and we'll walk your risk and compliance teams through governance, audit logging, and access controls in detail.