Governance & security

Governance, auditability, and oversight for company AI.

Maveric gives every employee a capable AI assistant — and gives you control over the data it touches, who can use what, and a full record of everything it does. Governance isn't an add-on here; it's the foundation.

Security architecture

A clear path from user request to audited action.

This is the buyer-grade control model: identity and role first, approved knowledge and connections second, action only when policy allows, and an audit event at the end.

1

Identity

The SSO or user session determines the actor. Every request starts with a known person — nothing runs anonymously.

2

Role scope

Role-based access control decides which knowledge, assistants, tools, and actions that person can reach.

3

Knowledge + Vault

Approved sources and encrypted credentials are accessed at run time — secrets are decrypted only when a step executes.

4

Approved action

Action only proceeds when policy allows. Sensitive writes can pause for human sign-off before anything changes.

5

Audit log

Actor, action, resource, timestamp, and a row-level diff are recorded automatically at the end of every write.

Where does data go?

You decide where company data lives — and what AI can touch.

Data stays in the regions and systems you choose, and credentials are never exposed.

01
Data residency (AU)
Keep data in Australia with on-shore and on-premise deployment options on Enterprise.
02
Encrypted credentials in Vault
Connection secrets are encrypted in Vault and decrypted only at run time — never shown in logs or audit trails.
03
Environments stay isolated
Development, staging, and production run with their own scoped secrets, so a test config can't reach live data.

Who can access what?

Role-based access decides what every person and assistant can reach.

Roles and groups scope who can use which assistants, knowledge bases, connections, and actions — least privilege by default. The Company Brain makes that access model something you can see, not just configure.

UserRolePermissionSkillKnowledgeConnectionActionAgent

What gets logged?

Every action is recorded — automatically.

There are no black boxes. Each prompt, data source, tool, and write leaves an accountable trail you can review.

01
Audit log on every write
Every create, update, and delete records the actor, the action, and a row-level diff — on by default, not an add-on.
02
Prompts and sources, traced
See which data sources and tools an answer drew on, so you can trace exactly how a result was produced.
03
An immutable trail
The record is captured automatically, so accountability never depends on someone remembering to switch it on.

How are tools and actions controlled?

The Assistant can only do what you let it do.

It reaches the systems you connect, within the roles you grant — and a person can stay in the loop on anything high-stakes.

01
Scoped tools via Connections
Every tool the Assistant touches is a Connection an admin set up deliberately — with the specific read and write actions it exposes chosen at connection time. There is no ambient access: a system that isn't connected simply doesn't exist to the Assistant.
02
Actions follow least privilege
Roles decide who can build, run, publish, and administer each resource. A person's Assistant inherits their role's scope — it can never act with more permission than the person sitting behind it.
03
Human-in-the-loop approvals
High-stakes writes — changing records, sending mail, moving money — can be gated behind an explicit approval step. The action pauses, a named person reviews it, and the decision is recorded alongside the run.

How can admins review usage?

Admins can see how AI is used across the company.

Oversight isn't a one-off audit. Admins can review who's using which assistants and data, and adjust access and controls as things change.

Trust & compliance

Controls your teams can review.

We keep public claims focused on what the product does: data residency options, encrypted credentials, scoped access, and audit logging.

Australian Privacy Principles

Questions

Security questions, answered.

Certifications, data residency, access control, logging, and action controls — the details your risk team asks about first.

Security review

Bring your security team to the demo.

We can walk through data residency, model-provider handling, Vault, RBAC, audit export needs, and the documents available under NDA.

Request security pack

Review our controls with your security team.

Book a demo and we'll walk your risk and compliance teams through governance, audit logging, and access controls in detail.