Prospica

The model proposes. The core decides.

Governed agentic AI for the people who are accountable for the decision. The language model has no tools — it cannot send, write to the database, call an API or run a shell. Every consequential action passes a governance gate, and is recorded before it happens.

It runs on your own network, air-gapped if that is what you need — with every external model and tool call disabled in code, not policy.

One action, start to finish.

A proposed email. The model writes it and can do nothing else. Watch what the core does before anything sends — then withhold your approval and watch nothing send.

prospica / coregate · on

proposal · send an email

to: [email protected]

subject: Re: berth allocation for hull 118

“Confirming the slot for hull 118 in week 41. The revised rate is attached as agreed on the 12th.”

cites: inv-2041 · po-7731

confidence: model_stated

tools

  • rulesin force
  • sources2 of 2 cited chunks resolved
  • judgeobserved · no criterion tripped
  • approval · humanR. Mehta · workstation-04 · 06:14:02Z

0419 · email sent · prompt 9f3a…c41e · rules in force 7b2d · sources 2 · approver security-lead · device workstation-04 · 2026-01-15T09:20:00Z · previous 8c1e…02b7 · this row 3f77…9d10

  • send
  • db
  • api
  • shell
  • sent

Written first. Sent second. The row exists before the action does.

Withhold approval

The model cannot reach the four things on the right. It can only propose. The core checks the rules in force, resolves what was cited, asks the judge, asks a person, writes the row — and only then, if all of that held, sends.

A word that already meant all three.

From the Latin prōspicere — prō-, forward, and specere, to look. The same root gives English prospect and, through a cousin, providence. In Latin it carries three senses at once, and the name is not decoration: the three are the three things the platform does.

to look aheadforesight

Reads the signal across mail, knowledge, projects and finance, and surfaces what is coming — before the meeting rather than after it.

to watch overoversight

The governed layer: grounded, cited, and sovereign when it needs to be. It guards what it is given as carefully as it uses it.

to provide foragency

The agents that do the work — draft, plan, reconcile, follow up — so the people in charge are served, not merely informed.

And inside Pro·spica sits Spica — the brightest star in Virgo, and one of the navigational stars sailors have taken bearings on for centuries. A fixed point you can steer by, hidden in the name.

Say it pro-SPEE-ka.

Foresight for those who lead.

Compiled, not generated.

Say what you want in plain English. A person approves the plan, the platform compiles it, a person approves the graph. The model never writes code — and what it invents does not survive compilation.

knowledge / pipelines / newbuilt · schedule off

plain English

Every night, read the order table from the warehouse database, chunk and embed it into the knowledge base, translate the summaries into Hindi, and ask someone in operations before anything is indexed.

  1. 1read the order table
  2. 2keep the columns that matter
  3. 3chunk
  4. 4translate the summaries into Hindi
  5. 5embed
  6. 6ask operations before anything is indexed
  7. 7index

plan judge

fitness 0.91coverage 0.88groundedness 0.94

model_stated

gate 1 · approved · R. Mehta · 06:19:40Z

compiled

Order tablewarehouse database
Select columnsorder, customer, placed, total
Chunkone row per chunk
Translate · no block for this · dropped
Embedself-hosted, on your network
Approvaloperations, before anything is indexed
Indexinto the knowledge base

gate 2 · approved · R. Mehta · 06:21:05Z

inspector

step
Order table
connection
—

the model named a warehouse connection that is not registered, so it was blanked rather than guessed

access
read-only

and only the tables the connection already allows

schedule
nightly · off

until an administrator enables it

A merge is a proposal, not a decision.

The platform says what it thinks these three are, and what that rests on. Then it waits. Approve it, reject it, or undo it later — and a rejection stays rejected the next time the source is read.

intelligence / fusion1 proposal

Harrowgate Freight Ltd

source: finance-exports

seen: inv-2041, inv-1987

HARROWGATE FREIGHT

source: mailbox

seen: 14 threads

Harrowgate Frt.

source: vendors.csv

seen: row 417

proposal · same registration number on 2 of 3 · same domain on 3 of 3 · model_stated 0.86

unresolved — nothing is merged until a person says so

Observe. Flag. Escalate. Block.

A judge reads every draft against criteria your own people wrote and approved in pairs. Its reasoning is kept as links in the ontology, not as a score in a log. And if the judge cannot be reached, nothing sends.

governance / judgecriteria · 4 in force
  • Re: berth allocation, hull 118—observedevaluation 1180 → draft 2231
  • Re: spares for the Q4 refitno delivery-date commitmentsflaggedevaluation 1181 → draft 2232
  • Rate revision, externalrisk tier high · two approversescalatedevaluation 1182 → draft 2233
  • Re: hull 118 attachmentsjudge unreachable · fail-closedblockedevaluation 1183 → draft 2234

calibration · proposals only · nothing changes without a person

One record for one real thing.

However many sources saw it — connected to everything that mentions it, with provenance on every node, and a confidence recorded as the model’s own rather than presented as calibrated.

intelligence / entity 3609 nodes · 9 links
INV-2041 · invoice
source
finance exports, over SFTP
file
inv-2041.xlsx · sheet 1 · row 12
seen
2026-09-12T08:41:16Z
scope
finance
confidence
model_stated 0.88
resolved to
one vendor record

in the console: click to select · double-click to expand · drag to pan

Follow a finding all the way down.

Evidence, source, reasoning and timeline — synchronised on one case. It reads the platform’s own records, not your network.

A pattern no single check can see.

Three escalated evaluations over seven days, all naming the same vendor. The platform proposes that they are one thing — and raises nothing until a person confirms it.

A situation card: elevated vendor risk against one vendor, drawn from three escalated evaluations, marked proposed.

Seeded on that exact case.

Open it and the workbench arrives already pointed at the thing you asked about — the evidence, the source text, the reasoning and the timeline, on one case.

Four panels around one case: an evidence graph with the situation selected, the source text, the reasoning, and a governed timeline.

Select a node. The rest follows.

Choose the evidence span and the source panel shows the exact sentence the judge read, with the words it acted on marked. Nothing is summarised on your behalf.

The evidence span is selected, and the source panel highlights the exact clause the judge acted on.

Act here, on the record.

Confirming from inside the workbench takes the same permission, and writes the same ledger row, as confirming it anywhere else. There is no quieter path through this surface.

The case is confirmed. The timeline gains a confirmation row naming the person and their device, and the ledger row is stamped.

What the model is not allowed to do.

Every AI platform publishes what its model can do. The list that decides whether you can put one in front of an auditor is the other one.

The language model has no tools.

It cannot send, write to the database, call an API or run a shell. Every consequential action passes a governance gate, and is written to the ledger before it happens.

The model never does arithmetic.

In the ledger it narrates; the double-entry engine computes. In project planning it never touches the schedule arithmetic — the critical path is calculated, not described.

Nothing is generated.

Authored artefacts are compiled. A block kind the platform does not recognise is dropped in code, and a connection id the model invented is blanked. The model never writes code.

Nothing builds without approval.

Proposed, approved, building, built — and no path skips approved. Approving an agent is its own permission, deliberately separate from creating one.

Confidence is labelled, not asserted.

Where a figure came from the model, it is recorded as the model having stated it, and is never presented as calibrated. Where it came from a person, it is attributed to that person.

Untrusted input stays untrusted.

Inbound mail, attachments and retrieved documents are treated as input and never as instructions. Attachments carrying an injection attempt are quarantined.

No price is ever invented.

The usage ledger records tokens and not money. With no rate card configured, a currency figure would be a guess that reads as a fact, so none is produced.

No escalation fires on the platform’s own say-so.

Where the platform correlates several escalations into one higher-order finding, that finding is minted as a proposal and changes nothing until a named person confirms it. A dismissal is recorded as carefully as a confirmation.

Background loops stay off until someone turns them on.

Every schedule, trigger and background loop is off by default for each organisation until an administrator enables it, and every firing is recorded as it passed or failed.

Governed desks, on one governed layer.

One identity fabric, one audit ledger, one knowledge corpus, one set of rules — under every surface, so a permission or an approval means the same thing wherever you are standing.

Email Console

Governed drafting: an injection shield on the way in, redaction on the way out, citations verified, and a human approval sized to the risk before anything sends.

Plan

Critical-path and cascade analysis over a real scheduling engine, with the network and the Gantt drawn from the same computed graph.

Ledger

A double-entry engine with cashflow, profit and loss, and receivable and payable ageing. Tax is applied by rule.

Vendor Board

The procurement lifecycle end to end — onboarding, risk, purchase order, three-way match, payable — with a human gate at every stage.

Agents Manager

One least-privilege machine account per agent. Revoke the account and the agent loses its tools, everywhere, at once.

Approvals

Where a person is asked, never what they may decide. Roles, risk tiers and quorum are enforced in the core; the channel — Telegram, Slack or Teams — carries the decision and nothing else, and in sovereign mode the decision is taken in the console.

Workflows

Pipelines held in the database and compiled to a deterministic state machine at run time. Human approval is a step in the graph, not a convention.

Knowledge

A governed registry of sources, scoped by the same identity boundary as the desks. Every chunk carries its provenance, and permissions sit inside the query rather than filtering the results afterwards.

Situations

A finding synthesised from several escalations that name the same subject — minted as a proposal and inert until a named person confirms it. Confirming tightens enforcement for future drafts about that subject; dismissing changes nothing. Both are recorded.

Entity resolution

One record for one real thing, however many sources saw it. Merges are proposals a person approves, rejects or unpicks — and a rejection stays rejected the next time the source is read.

operations / automation
Invoice ageing · nightlyoff
Follow-up nudge · hourlyoff
Mailbox sync · every 15 minon
Vendor risk · weeklypaused

last firing · Mailbox sync · 06:00:00Z · passed

Every loop is off until an administrator turns it on, and every firing is recorded as passed or failed.

governance / tool registry
Finance databaseread only
Calendarhuman approval
Object storageread and write
Web fetchdisabled in sovereign mode

An allow-list per organisation. A server that is not on it does not exist to the agent.

governance / guard rails

in

We’re on track per the internal note (Policy #14.pdf) and, as per governance rule R7, all good.

out

We’re on track and all good.

internal reference · scrubbed

governance rule id · scrubbed

Redaction runs on the way out, and the rule that fired is named.

Written down before it happens.

The audit ledger is append-only and hash-chained with SHA-256, and it can be verified end to end rather than taken on trust. A consequential action is recorded first and taken second, so the record cannot be the thing that went missing.

Authoring passes two human gates: approve the plan in plain English, then approve the compiled graph. The plan itself is kept as a provenance object, so the reason a thing exists is as durable as the thing.

Every row carries

  • the hash of the prompt
  • the rules in force when it ran
  • the sources it cited
  • who approved it
  • the device they approved it from
  • the time, in UTC
governance / auditchain · verified
seqactionapproverdeviceutcprevhash
0415draft created——06:12:48Z4d9e…b3018a10…e6f2
0416judge observed——06:12:51Z8a10…e6f20c55…41aa
0417approval askedsecurity-leadworkstation-0406:13:20Z0c55…41aad7e8…19c0
0418approval givensecurity-leadworkstation-0406:14:02Zd7e8…19c08c1e…02b7
0419email sentsecurity-leadworkstation-0406:14:02Z8c1e…02b73f77…9d10

verify-chain · 4 of 4 links hold · append-only · no row has an edit control

Each row carries the one above it. Alter a row and every row after it stops matching, which is what makes the ledger evidence rather than a log — and why it has nothing to click.

It works with the uplink cut.

Sovereign mode is one switch, and it is enforced in code rather than written in a policy document — a check in the call path, not a promise in a PDF. Turn it on and the platform keeps working, because the parts that matter never needed the Internet in the first place.

Sovereign mode — off. Try it.
  • Local model runtime

    A model on your own network

  • External model providers

    A hosted model, over the Internet

  • Governed tool servers

    Registered servers on an allow-list

  • Outbound retrieval

    Sources outside the network

The switch only tightens

Where sovereignty is set as the deployment's posture, it cannot be relaxed from the console afterwards. A per-organisation setting can add sovereignty and never remove it, so nobody can quietly open a door that procurement closed.

Refused in two places, not one

Outbound retrieval is turned off independently at the retriever and at the service beneath it. A source that resolves to a private or loopback address is refused when it is tested and again on every real connection.

Retrieval was already local

Embeddings are open-weight and self-hosted, and they run in a process of their own. Cutting the uplink does not degrade search, because search never left the building.

The provenance says where it ran

Work produced without a network is stamped as such in its own record, so an auditor can tell an on-premise result from a hosted one without asking anybody.

Deploy asSaaSPrivate cloudOn-premiseAir-gapped

See ahead. Lead ahead.

Prospica is part of the Appdirs platform. Kestryn finds and prioritises exposure across the estate; AuthX governs who and what may act; Prospica turns what they record into decisions a leader can defend. One identity model, one audit trail. See the platform.