Operational Trust

Test what is ready for AI. Enforce what is allowed.

Operational Trust validates and certifies the enterprise capabilities available to AI, then enforces current organisational authority whenever governed work proceeds.

AI has no identity or authority of its own. Every action remains attributable to an identified person acting under an active Business Role—the approved job function under which that person is performing the work.

Governance must reach execution

Two questions. Both must pass.

Is the capability ready?

Certification addresses readiness for a defined scope.

May this person use it now?

Runtime authorisation addresses the current execution.

Certified does not mean currently authorised. Authorised does not make an uncertified capability ready.

Establish the operating boundary

Human authority stays outside the model.

Operational Trust evaluates verified identity, active Business Role, organisational authority, business scope and Dimensions, existing permissions, policy conditions, capability certification and approval state.

The active Business Role establishes responsibility. Dimension values identify the records inside that responsibility. Protection rules apply that scope across systems, and governance certification tests that it holds across connected relationships.

Business Role

Who is responsible. The approved job function under which the person is performing the work.

Dimensions

Which records are in scope. Reusable business boundaries such as region, legal entity, customer, project or amount. Reusable boundaries avoid role explosion.

Protection rules

Where the scope applies. Searches, retrieved context and capability requests respect the same business boundary.

Authority comes from current customer-controlled identity, role, permission and approval state—not from model input. AI cannot expand authority through a prompt, retrieved document or model decision.

Validate before AI use

Test behaviour— not policy documents.

Enterprise Knowledge defines business meaning, relationships, authoritative sources and approved business capabilities. Operational Trust does not create those definitions. It validates whether the configured definitions and controls behave as expected.

The relevant customer business and technical teams inspect schemas, mappings, cross-system relationships, Dimensions, protection, capability definitions, authentication, execution behaviour and end-to-end results.

Wrong mapping

Could supply the wrong customer or agreement context.

Wrong Dimension behaviour

Could expose information outside the permitted region.

Wrong operation behaviour

Could reach the wrong system or produce an unexpected result.

Failures remain visible and must be corrected before affected capabilities become eligible for governed use.

Certify bounded readiness

Readiness is scoped. Never assumed forever.

Operations

Datasource operations pass validation, integration and end-to-end tests. AI does not use an operation whose execution behaviour has not been verified.

Business meaning for AI use

Business meaning and exposed capabilities are complete enough for governed work. AI does not act from incomplete or ambiguous context.

Governance

Access rules determine who may see or use what under which business conditions. Data or operations do not cross the intended person, role or Dimension boundary.

Part of deployment and promotion readiness

Integrators validate and certify capabilities as they are prepared for an environment. Material changes return the affected scope through certification before promotion or wider AI use.

Enforced according to the environment

When applicable trust gates are enabled, denied or review-required results block the configured publication, promotion, Role Assistant exposure or Runtime path. The customer platform team confirms each environment’s gates and enforcement settings.

Test before release

A generated candidate cannot approve itself.

Business and technical teams test the intended outcome, sources, knowledge behaviour, role and permission scope, governed operations, approval paths, Evidence requirements and safe handling of missing or denied conditions.

Only an approved version becomes eligible to be made available.

Representative business cases
Missing information
Denied and unsafe conditions
Approval paths
Evidence requirements
Human release approval
Authorise every current execution

Pre-release testing does not grant live authority.

Operational Trust verifies who is acting, the active Business Role and Dimensions, permitted information, capability eligibility, approval state and whether the specific operation may proceed.

Operational Trust

Authorises the current person and work.

Enterprise Runtime

Decides execute, wait, complete or safe stop.

System of record

Applies its native controls and remains authoritative.

Example: customer renewal

A commercial exception without bypassing pricing authority.

An account team wants a Renewal Assistant to prepare renewals while current human authority remains enforceable.

Define
Enterprise Knowledge supplies the approved customer and agreement meaning, pricing rules, authoritative sources and the capability for requesting a commercial exception.
Validate
Teams test mappings, regional Dimensions, permissions and operation behaviour. A wrong agreement or ignored regional boundary fails validation.
Certify
Operational Trust certifies the corrected capability only for its validated operation, environment and business scope.
Test and approve
The Renewal Assistant candidate is tested with missing information, excessive discounts and denied approvals. Generation cannot approve the candidate.
Authorise now
Operational Trust checks the account manager’s active Business Role, region, current permissions and approval state. Certification alone does not authorise the request.
Proceed or fail closed
Enterprise Runtime may execute, wait for approval, preserve denial or stop safely. AI cannot present denied or incomplete work as completed.
Preserve the result
The pricing or customer system remains authoritative. Evidence Fabrix can record the checks, human decision and resulting business outcome.

Certification alone does not authorise the request. This is the difference between describing a control and enforcing it during real work.

Fail closed

Cannot verify means do not execute.

Missing or conflicting information is not permission. If identity, scope, permission, policy, certification or approval cannot be established, governed execution does not proceed.

Ask for required information
Wait for authorised approval
Preserve an explicit denial
Stop safely

AI cannot rewrite a rejected or incomplete operation as success.

Responsibility boundary

What Operational Trust does not replace.

The customer identity provider
Source-system permissions
Business owners and approvers
Enterprise Knowledge definitions
Formal risk and compliance programmes
Independent assurance
Enterprise Runtime decisions
Systems of record

It makes customer-controlled authority, readiness and protection enforceable when AI participates in enterprise work.

Business value

From paper governance to enforceable work.

Know what is ready

Identify capabilities genuinely ready for governed AI use.

Block unsafe use

Stop uncertified, out-of-scope or currently unauthorised operations.

Keep authority human

Explain allow, deny, wait and safe-stop outcomes.

Fail safely

Do not proceed when identity, information, approval or policy cannot be verified.

Reduce proof effort

Connect validation and certification to operational outcomes.

Paper governance explains what should happen.

Operational Trust determines what is allowed to happen.