We define reasoning the way computer science does: the systematic evaluation of multiple signals to reach a defensible conclusion. Three tiers, each independently deployable, each fully transparent.
The engine
Regulated buyers can run Tier 1 alone and get a complete, fully deterministic engine with no generative AI anywhere in the decision path. Innovation-led organisations can run all three.
The lifecycle
Detection feeds the platform; the platform owns the policy, workflow, decision, mitigation and remediation model that follows.
Entitlement, HR, usage and runtime events from the systems you already run.
A versioned rule evaluates risk, peers, blast radius, scope and context together.
Revoke, approve with mitigation, accept risk or dismiss — signed and non-repudiable.
Executed against the target connector automatically or by a reviewer, with rollback.
Every state transition written to an immutable, reproducible audit record.
Event state moves OPEN → IN_REVIEW → DECIDED → MITIGATING → REMEDIATING → CLOSED, with SUPPRESSED, MERGED and EXPIRED as terminal branches. Transitions are enforced server-side; reviewers cannot skip states, and every transition writes an audit record.
The policy model
Deterministic in practice
A control states its own failure condition in plain terms, carries a category and a risk level, declares what it depends on, and reports the exact population that failed on the last run. Nothing about the outcome is opaque.

Deployment
Request an architecture briefing — a working session on tier configuration for your regulatory posture.