Solutions · AI Harness & Governance

    Governance and security built into the foundation.

    An AI agent harness gives a model tools, memory, permissions, and a safe agent runtime. Chiri adds governance and security by design.

    01 · The problem

    Governance added later does not remain reliable.

    Most teams build the AI first. They add governance after a buyer demands it. This process creates a separate policy layer. The original system cannot support governance by design.

    Ungoverned agents that can act in the world are a liability, not an asset. Regulated and mid-market buyers cannot accept a policy applied after the fact.

    For years, AI governance meant a binder of principles and ethics statements that nobody could test. Regulators, and reality, now ask what you can prove, not what you promised. They want to know what the system did, when it happened, and who approved it.

    02 · The harness concept

    The model is the brain. The harness is the body that lets it act safely.

    A model reasons, and that is all it does. A model needs a body to turn reasoning into work. The body holds tools and memory. It runs actions safely. It also controls permitted actions. That body is the harness.

    Agent equals model plus harness. Reliability, safety, and control are won in the harness. That is why governance and security can be part of the foundation, instead of a layer added later.

    CHIRIFIG. 02 · THE AI HARNESSTHE HARNESSModelreasoning1Orchestration2Memoryshort / long3Tools45ExternalSystemsCRM·DB·SaaS6observation / feedback7pre-execution check.CALLOUTS1 reasoning engine2 orchestration3 memory4 tools5 governed checkpoint6 external systems7 feedback loopCHECKPOINTpolicy check · before executionOne checkpoint between thought and action.The harness lets the model act. Every proposed action passes one governed checkpoint.

    03 · The governance foundation

    The foundation every application inherits.

    These controls are essential and available from the start. Applications inherit them by design. We describe them plainly because they already support production systems.

    Login, roles, and authorization

    The system uses hybrid RBAC and ABAC (role-based and attribute-based access control). Its policies build on each other. Row-level security supports these policies and blocks access by default during failures. The foundation makes each access decision once. Applications do not rebuild these decisions.

    Immutable logging and audit

    The append-only log accepts new entries. It prevents changes and deletions. It captures each system state before and after every change. The audit record starts on day one. Chiri does not add it later.

    PII and data controls

    The foundation handles sensitive data controls once. Each application uses the same protections. Teams do not rebuild these protections for each application. Chiri builds the platform to enterprise and regulated-industry standards. The platform supports HIPAA readiness. Chiri has extensive experience with enterprise security, healthcare, and financial services.

    Data ownership and no data access

    You own your business processes and the solutions built for them. Chiri hosts and operates the platform and never looks at your data. The MSSA, a legal agreement, sets that boundary. Your proprietary context, the edge that sets your business apart, stays yours.

    The evidence chain

    Governance becomes real the moment it produces evidence. Every important step, a data access, a tool call, a human approval, becomes a link you can inspect later. It works like a chain of custody in law and accounting. That is what "auditable" means in practice. It is not a story about why the model chose an output. It is a record of what happened, when it happened, and who approved it.

    CHIRIFIG. 03 · ACCESSSUBJECT · Nº 44IDENTITYa.riveraROLEanalystDEPTfinanceREGIONus-eastCLEARstandardATTRS3 activeAUTHENTICATED · SCOPEDPOLICYrole+attrsPOLICYCHECKrequestscoped readRESOURCE · rowsrow_01 region=us-eastrow_02 region=eu-west×row_03 region=us-eastrow_04 region=apac×row_05 region=us-eastrow_06 region=eu-west×row-level scope · only entitled rows pass1231 subject record 2 policy checkpoint 3 protected resourcesolid = request dashed = policy grey row = deniedAccess is decided at a single checkpoint.Roles and attributes meet policy. Only the rows a subject is entitled to pass through.
    CHIRIFIG. 04 · THE LEDGERAPPEND-ONLY · WORM · CLIENT-OWNEDappendno edit / delete outBREAKdownstream invalidatedNº 0731k.chent 14:22:01prev roothash 3e9aNº 0732r.diazt 14:22:02prev 3e9ahash 77c2Nº 0733k.chent 14:22:03prev 77c2hash a91fNº 0734a.riverat 14:22:04prev a91fhash c40dNº 0735m.wongt 14:22:05prev c40dhash 1b8einvalidatedNº 0736r.diazt 14:22:06prev 1b8ehash f5a2invalidatedarrow = append (write-once) chain = hash of previous break = tamper detectedNothing is edited. Everything is appended.Every action is sealed to the one before it. Alter any entry and the chain breaks; the client owns it.
    CHIRIFIG. 05 · RUNTIME CHECKPOINTAgentreasoningblocked vectorCHECKPOINTINPUTOUTPUTModel / ToolsexecutionloggedledgerINSPECTEDinputoutputtool callMAPPEDEU AI ActNIST AI RMFBLOCKED1 vector · system uparrow = traffic band = inspected (in / out) × = blocked vector tick = loggedOne vector closed, not the system.Inputs and outputs are inspected at runtime. One vector is closed, the system stays up, all logged.

    04 · Chiri Glacier

    Chiri Glacier: stop bad actions before they execute.

    Glacier is real-time infrastructure security. It works at the infrastructure level. It checks each proposed action before execution. Glacier stops a dangerous action before it runs. It does not flag the action after execution.

    A dangerous action can move data outside an authorized boundary. It can also damage a system of record. A tool call can also exceed application policy. Glacier sits below the application layer. It catches these actions from any agent, model, or workflow. The application does not need to predict the risk.

    Glacier stops bad actions instead of only logging them. Detection after execution shows past events. Glacier stops the action before execution. The record shows prevented actions and completed cleanup.

    glacier · before executionexecutionGlacier checks it before it runscleared, proceedscontrast · detect after the factno check before it runsalready executed, already damagingflagged after the facttoo lateprevented, not cleaned up afterward

    05 · The runtime Clamp

    The runtime Clamp: contain one attack vector, keep the system up, and map to the law.

    Surgical runtime containment

    The runtime Clamp inspects AI input and output during operation. It stops one compromised path without stopping the full system. The Clamp contains that path while other paths continue.

    Compliance mapping

    The Clamp compares system actions with the EU AI Act and other compliance requirements. The EU AI Act is the first binding law in this area. This comparison shows whether system actions match legal requirements. It supports your compliance work. It does not provide certified legal compliance or legal advice.

    06 · The impact

    Auditable, defensible AI you can put into production.

    You deploy AI with provable governance. Applications inherit authorization, audit, and isolation by construction. Teams deliver faster with a defensible foundation. The system creates the record by design. You can answer questions from regulators, auditors, and boards.

    The foundation exists so people can trust the systems they run. They can focus on higher-value work, instead of policing an ungoverned tool.

    More companies improve shared security and hardening. You receive those improvements. Chiri isolates your proprietary data, processes, and advantage. Chiri never pools or shares them. Chiri builds your AI Harness & Governance solution. You own it. Your solution improves over time.

    Put governed AI into production.

    Talk to us about what governed and secure looks like for your environment.