Skip to content

Use case · Compliance · OI-1200

Audit-ready, by construction.

Compliance evidence is normally assembled after the fact — screenshots, ticket exports, a quarter of reconstruction before the audit. When the actors are autonomous agents moving at machine speed, that model collapses. Intended turns your declared business processes into first-class verification context: every autonomous action is scored against the workflow it is supposed to live inside, the decision is sealed the moment it is made, and the evidence is immutable. Conformance is continuous; the audit chain is cryptographically signed and replayable, with per-tenant public-key (JWKS) verification is live.

01 · From post-hoc finding to continuous control

A control you can only check quarterly is not a control.

Traditional compliance samples: an auditor pulls a handful of transactions and infers the rest of the population behaved. That sampling assumption breaks the instant an agent can take ten thousand actions between two audits. Intended makes the control synchronous with the action — every autonomous step is mapped to a step in your declared process before it runs, with its own confidence, and an out-of-sequence or off-script action surfaces as a live signal rather than a finding discovered months later.

Because the evidence is generated at decision time and hash-linked, there is nothing to reconstruct at audit time. You hand over a chain; the auditor replays it against the cryptographically signed records, with per-tenant public-key (JWKS) verification is live. No sampling, no inference.

02 · The OI-1200 surface

Risk & compliance is 5 canonical intents — but conformance spans all 29 domains.

The Risk Management domain (OI-1200) names the compliance and risk actions directly. But the point of conformance scoring is that it applies to every domain: a deploy (OI-100), a refund (OI-500), or a credential rotation (OI-200) is each scored against the regulated process it belongs to.

OI-1201

Risk Assessment

OI-1202

Risk Mitigation

OI-1203

Compliance Management

OI-1204

Business Continuity

OI-1205

Contract & Legal

03 · What you get

01 · Sequence conformance

Continuous score

Out-of-order or off-script actions surface as a continuous signal, not a post-hoc finding. The score moves with every decision the runtime makes.

02 · Process mapping

Intent → step + confidence

Every interpreted intent is anchored to the most-likely step in your declared workflow, each with its own confidence value carried into the decision.

03 · Evidence export

Audit chain · signed & replayable

Hand the chain to your auditor; hash-linked, content-addressed, cryptographically signed, and tamper-evident by construction. Per-tenant public-key (JWKS) verification is live.

04 · Regulatory profiles

SOC 2 · HIPAA · AML · NIST

Pre-built export profiles per regulatory regime. Domain packs add vertical-specific overlays for finance, healthcare, and critical infrastructure.

04 · Why the evidence holds without us

Provable without Intended in the loop.

The strongest claim a compliance program can make is that its evidence survives the vendor. Intended’s audit chain is content-addressed and hash-linked, and every Authority Token is an Ed25519-signed artifact verified against your tenant’s kid-pinned public key. If Intended disappeared tomorrow, the receipts in your chain would still stand — an auditor can replay every decision against the signed chain. Per-tenant public-key (JWKS) verification is live. The guarantee reduces to one line: no token, no action — and the token is the receipt. Read the security posture for key isolation detail.

Compliance — Verified workflows, audit-ready evidence | Intended