Skip to main content
Connic

Operational records for
AI governance.

Keep preliminary assessments, operational controls, and metadata-only evidence attached to the AI system and its real implementations.

Read the governance docs
Preliminary assessment
version 3approved

Pinned catalog · reviewer rationale retained

Evidence snapshot
SHA-256 6f29c3...f62a

Immutable · metadata only

  • Human oversightconfigured
  • Disclosure verificationneeds evidence
  • Incident proceduregap
Preliminary readiness record, not a legal determination or certification.
AI system scope

Govern the AI system across its implementations

An AI system is a project-scoped record independent of any single agent. Link the environments, deployments, and agents that implement it so evidence follows the real operating surface as it changes.

  1. 1

    Register

    Describe the use case, owner, geographies, affected persons, and implementation links.

  2. 2

    Assess

    Record an immutable, versioned answer set against a pinned catalog version.

  3. 3

    Review

    Approve with rationale, a supported provider or deployer role, and uncertainty acknowledged.

  4. 4

    Operate

    Work generated controls, transparency records, monitoring plans, and incidents.

  5. 5

    Export

    Capture a metadata-only snapshot and stream its hash-verifiable archive.

Turn the latest approved assessment into work

Controls retain the governing article, applicability rationale, accountable implementation type, status, evidence state, and change history.

  • Applicable control recorded without an implementation.

    gap
  • The control is marked as needing supporting evidence; evidence status is tracked separately.

    needs_evidence
  • Implementation recorded; evidence links are tracked separately.

    configured
  • Exception recorded with its required rationale.

    not_applicable
Explicit ownership

Connic · Customer · Shared · External

Refreshing re-derives controls from the current latest approved assessment while preserving prior changes.

Article 50 documentation

Track disclosure policy and application delivery separately

The governance record captures what your organization says it implements and the evidence that supports that statement.

Connic records
  • Disclosure copy, locales, placement, frequency, and display mode
  • Customer implementation and upstream-provider evidence
  • Attested applications and supporting verification
Your application delivers
  • User-facing disclosures and synthetic-content marking
  • Any prompt, response, stream, or connector-traffic modification
  • Prefixes, banners, metadata, or media watermarks

AI Governance supports documentation and evidence workflows. It does not provide legal advice, make legal determinations, issue certifications, or replace professional counsel.

Evidence archive

Export an immutable, hash-verifiable evidence archive

A snapshot is an immutable, metadata-only capture scoped to selected systems and environments, with an optional time window.

manifest.json · excerpt
{
  "snapshot_id": "8f2d3e43-90ab-4f7b-a218-687719b0c6e3",
  "content_sha256": "6f29c3e8a1095cbd1bd9f645cb7b355b16837e97b1dbca38344752103fddf62a",
  "scope": {
    "system_id": "5403e168-b9fd-4e42-8556-8a68d97d899c",
    "environment_ids": ["1cb302be-64d7-4c08-9d25-337a6897cb82"],
    "telemetry_scope": {
      "runs": "system_agent_environment_pairs",
      "approvals": "system_agent_environment_pairs",
      "judges": "system_agent_environment_pairs"
    },
    "time_from": "2026-07-01T00:00:00Z",
    "time_to": "2026-07-31T23:59:59Z",
    "metadata_only": true
  },
  "record_counts": {
    "systems": 1,
    "assessments": 1,
    "controls": 3,
    "transparency_policies": 1,
    "transparency_applications": 1,
    "monitoring_plans": 1,
    "incidents": 0
  },
  "telemetry_file": "telemetry-summary.json",
  "raw_prompt_or_output_content_included": false
}
  • Immutable

    Snapshots cannot be edited or deleted and persist for the project lifetime.

  • Content-addressed

    The canonical payload and every data or report artifact listed in the manifest carry SHA-256 hashes.

  • Portable

    The ZIP includes a human report, canonical JSON, collection CSV and JSON, and a manifest.

  • Scope-aware

    Coverage records selected environments, time range, retention, and missing evidence.

  • Privacy-bounded

    Summary telemetry is included without copying raw prompt or output content into the archive.

Hashes detect changed content. They are not signatures, do not establish who published an archive, and do not certify legal sufficiency. Review the evidence and governance boundaries.

Frequently Asked Questions

No. Approval preserves a reviewed preliminary assessment and its rationale. It is not a legal determination or certification. Final classification, reporting deadlines, and legal sufficiency remain your responsibility in consultation with your counsel.

It is a project-scoped governance record for a use case, independent of any one agent. It can link the environments, deployments, and agents that implement the system so telemetry, transparency evidence, and incidents attach to the right scope.

Controls are generated from the latest approved assessment. Each control retains its governing article, applicability rationale, implementation owner, implementation and evidence statuses, linked product evidence, and change history. A not-applicable status requires an exception rationale.

No. Connic records disclosure policies, attestations, and supporting evidence. It does not modify prompts, responses, streams, or connector traffic; inject banners or metadata; or watermark media. Your organization implements and delivers those disclosures in its application.

No. Snapshots are metadata-only and exclude raw prompts and model outputs. They include structured governance records plus scoped run, approval, and judge telemetry, along with coverage metadata for unavailable or missing evidence.

AI Governance is an Enterprise entitlement. Access is divided across compliance.view, compliance.manage, compliance.export, and compliance.incidents.manage project permissions. The same workflow is available through project-scoped REST routes under /v1/projects/{project_id}/compliance.