Use case · Compliance · OI-1200
Audit-ready, by construction.
Compliance evidence is normally assembled after the fact — screenshots, ticket exports, a quarter of reconstruction before the audit. When the actors are autonomous agents moving at machine speed, that model collapses. Intended turns your declared business processes into first-class verification context: every autonomous action is scored against the workflow it is supposed to live inside, the decision is sealed the moment it is made, and the evidence is immutable. Conformance is continuous; the audit chain is cryptographically signed and replayable, with per-tenant public-key (JWKS) verification is live.
01 · From post-hoc finding to continuous control
A control you can only check quarterly is not a control.
Traditional compliance samples: an auditor pulls a handful of transactions and infers the rest of the population behaved. That sampling assumption breaks the instant an agent can take ten thousand actions between two audits. Intended makes the control synchronous with the action — every autonomous step is mapped to a step in your declared process before it runs, with its own confidence, and an out-of-sequence or off-script action surfaces as a live signal rather than a finding discovered months later.
02 · The OI-1200 surface
Risk & compliance is 5 canonical intents — but conformance spans all 29 domains.
The Risk Management domain (OI-1200) names the compliance and risk actions directly. But the point of conformance scoring is that it applies to every domain: a deploy (OI-100), a refund (OI-500), or a credential rotation (OI-200) is each scored against the regulated process it belongs to.
Risk Assessment
Risk Mitigation
Compliance Management
Business Continuity
Contract & Legal
03 · What you get
Continuous score
Out-of-order or off-script actions surface as a continuous signal, not a post-hoc finding. The score moves with every decision the runtime makes.
Intent → step + confidence
Every interpreted intent is anchored to the most-likely step in your declared workflow, each with its own confidence value carried into the decision.
Audit chain · signed & replayable
Hand the chain to your auditor; hash-linked, content-addressed, cryptographically signed, and tamper-evident by construction. Per-tenant public-key (JWKS) verification is live.
SOC 2 · HIPAA · AML · NIST
Pre-built export profiles per regulatory regime. Domain packs add vertical-specific overlays for finance, healthcare, and critical infrastructure.
04 · Why the evidence holds without us
Provable without Intended in the loop.
The strongest claim a compliance program can make is that its evidence survives the vendor. Intended’s audit chain is content-addressed and hash-linked, and every Authority Token is an Ed25519-signed artifact verified against your tenant’s kid-pinned public key. If Intended disappeared tomorrow, the receipts in your chain would still stand — an auditor can replay every decision against the signed chain. Per-tenant public-key (JWKS) verification is live. The guarantee reduces to one line: no token, no action — and the token is the receipt. Read the security posture for key isolation detail.