Architecture

Your AI can change. Your enterprise boundary does not.

AI Fabrix keeps business context, identity, permissions, authority, governed operations and Evidence within one customer-controlled architecture—entirely inside your organisation's own Azure tenant.

Star Icon
Build without restriction
Star Icon
Execute through verified human authority
Star Icon
Entirely inside your Azure tenant
01
Verified identity
02
Applicable context
03
Capability verification
04
Governed execution
The Architectural Law

AI has no authority of its own.

Every action runs on behalf of an identified person and remains within that person's existing organisational authority and access.

What is preserved

AI Fabrix does not replace the organisation's existing identity, permissions, approvals or system controls. It preserves them when AI participates and executes only approved capabilities under verified human authority.

What cannot happen

Prompts, models and retrieved content cannot create new authority.

Explore The Architecture

One foundation. Seven architecture views.

Each view answers one architecture question in plain language. Start with how enterprise meaning is defined, then follow how work is decided, authorised, performed and proven.

01

Enterprise Model

How connected systems become explicit, reusable business meaning for AI-assisted work.

02

Runtime & Execution

How each governed continuation is evaluated, executed, completed or stopped safely.

03

Trust & Security

How verified human authority and existing enterprise controls remain in force.

04

Deployment & Ownership

How AI Fabrix operates entirely within the customer's own Azure tenant.

05

Enterprise Systems

How governed data contracts connect existing authoritative enterprise systems.

06

Evidence & Observability

How results, Evidence and technical logs remain distinct and inspectable.

07

Independence & Exit

How models and interfaces can change through explicit contract boundaries.

The Operational Firewall For AI

Open development around the platform.
One governed path into the business.

Customers can build any application, interface, model or business logic around AI Fabrix. Where AI reaches enterprise information or operations, it can request only approved capabilities on behalf of an identified person.

01

Declared capabilities

Approved connected-system definitions specify the only enterprise information and operations available to AI.

02

Next-step decision

The runtime evaluates the active person, case and current business context, then selects one permitted next step — or stops safely.

03

Authority check

Operational Trust, the authority-control layer, checks identity, permissions, scope and approvals before an operation reaches the connected system. Raw APIs and credentials stay behind the boundary.

04

Inspectable record

Relevant requests, authority decisions, completed steps and actual outcomes remain available for audit.

Trust From Request To Result

Existing enterprise controls stay authoritative.

AI Fabrix uses the identity, access, approval and business controls the organisation already operates. The receiving enterprise system continues to enforce its own permissions and remains authoritative for the result.

01

Verified identity and active role

02

Applicable business context

03

Runtime decision

04

Capability verification

05

Governed execution

06

Validated result

Runtime

Determines the next permitted continuation for the active person and case.

System of record

Accepts, rejects and records the business transaction under its normal controls.

Secure Azure Deployment

Choose the network controls your environment requires.

Every edition runs in the customer's Azure tenant. Network controls for regulated environments must be selected, configured and verified by the customer.

Customer Azure boundary

Your tenant · your identity · your keys · your systems · your models

Marketplace deployment → tenant activation → readiness verification. Administration differs by edition: Community and Standard use the deployment controller; Enterprise also gives the customer direct control of the deployed Azure resources.

Network profiles

Public and private profiles selected during deployment

PostgreSQL, Storage and Key Vault remain behind the governed platform boundary, and infrastructure secrets are generated into Key Vault. Enterprise customers can apply customer-managed Azure networking. Private ingress, egress, DNS and connections to AI services and enterprise systems remain explicit architecture choices.

Architecture Principles

Deterministic control where AI touches the business.

01

Runs entirely inside the customer's own Azure tenant

02

Marketplace deployment is activated and verified before operational use

03

Infrastructure secrets are generated and stored in Azure Key Vault

04

Public and private network profiles are selected explicitly

05

Private profiles do not silently fall back to public access

06

AI receives no independent identity, authority, credentials or access

07

Enterprise applications remain the systems of record

08

Relevant payloads, decisions and outcomes remain inspectable for audit

Result, Evidence And Logs

Three distinct records. One inspectable chain.

Results, Evidence and technical logs are kept separate so each can be inspected for what it actually proves.

01

Execution result

The validated result of a specific run, including a rejection, failure, safe stop or incomplete outcome — not only successful work.

02

Evidence

Business-significant facts, controls, human decisions and outcomes that have passed the required validation before they can be reused.

03

Audit and operational logs

Technical activity and relevant inbound and outbound payloads retained for security, traceability and operations.

Models and interfaces can change. Human authority and enterprise control remain.

Your AI remains interchangeable.
Your enterprise foundation remains yours.

Build without restriction. Execute through verified human authority.