Corvair Knowledge Substrate
databaseRisk & Compliance KBPRODexpand_more
badgeApplication userexpand_more
CJ
visibility_offInfrastructure and activity view · content is not visible to this role
tuneFilters
CJ
What are the model risk management requirements under SR 11-7 for our credit scoring model, and which apply before we can promote CS-204 to production?
neurology
AveryVirtual expert

SR 11-7 frames model risk management around three pillars: robust model development, ongoing validation, and governance with clear accountability. For CS-204, the controls that gate production sit in the first two pillars.

An independent validation covering conceptual soundness, outcomes analysis, and monitoring design is required prior to deployment, performed by staff independent of model development. Development documentation must let a third party reproduce the model without recourse to the developers.

Because CS-204 informs consumer credit decisions, fair lending testing and a documented effective challenge record should be attached to the validation package. Your MRM policy also requires Tier-1 models to carry a board approved risk rating, which CS-204 currently lacks.

CJ
Who has to sign off the validation, and can development staff do it?
neurology
AveryVirtual expert

Sign-off must come from a validation function that is independent of model development. Developers may support the exercise but cannot own the validation conclusion or the effective-challenge record.

attach_fileAttach from Vault⏎ send · ⇧⏎ newline
142 resultspage 1 of 12
gavel
SR 11-7: Guidance on Model Risk Management
gavelFederal Reserve · Regulation · pp. 3–7
…validation should be performed by staff who are independent of model development, covering conceptual soundness, ongoing monitoring, and outcomes analysis…
Why relevant: directly defines the independent-validation requirement and who may perform it.
T1 authoritativerelevance 0.962024-11Open originalopen_in_new
rule
Independent Validation Standard MRM-STD-02
ruleInternal · Policy · §4.2
…the scope of an independent validation shall include benchmarking, replication where feasible, and an assessment of requirements for ongoing monitoring…
Why relevant: your internal standard operationalising the regulator's expectation.
T2 reliablerelevance 0.912025-02Open originalopen_in_new
description
OCC Bulletin 2011-12
descriptionOCC · Regulation · supervisory
…supervisory expectations for validation activities, including effective challenge by parties independent of the model owners…
Why relevant: companion supervisory guidance reinforcing effective challenge.
T1 authoritativerelevance 0.882024-09Open originalopen_in_new
menu_book
Outcomes Analysis Playbook
menu_bookInternal · Method · v2
…operational guidance for the validation team performing outcomes analysis and back-testing…
Why relevant: method-level detail, useful but not authoritative on requirements.
T3 contextualrelevance 0.792025-01Open originalopen_in_new
CJ
Map EU AI Act Articles 9–15 obligations to our internal model-risk controls and flag any requirements we do not yet cover.
travel_explore
AveryDeep research
helpClarified before starting
Which articles are in scope?Art. 9–15 (risk, data, documentation, transparency, human oversight)
What output do you want?A control-mapping table plus a list of gaps
How deep, and which sources?Standard depth · prefer T1 and T2 · internal policy first
account_treeReasoning plancaptured and preserved with this inquiry
check1 · Plan. Broke the objective into seven sub-questions, one per article cluster.0:08
check2 · Initial search. Retrieved the EU AI Act text and 38 internal control and policy sources.0:51
check3 · Reflect. Assessed coverage and trust tier; two clusters were thin on internal evidence.1:20
check4 · Follow-up. Ran four targeted searches for human-oversight and record-keeping controls.2:05
check5 · Synthesise. Aligned each obligation to a control and flagged the unmapped ones.2:48
progress_activity6 · Improve. Running a sub-plan to confirm the two gaps are not covered elsewhere.71%
7 · Choose format. Mapping table plus gap list, as requested.queued
8 · Produce output. Render the report and issue a validity warrant.queued

Draft, updating as the run completes. Articles 9–15 map cleanly onto existing model-risk controls in most areas. Two obligations have no current internal control and are flagged below.

EU AI Act obligationInternal controlStatus
Art. 9 · Risk management systemMRM-STD-01 model risk frameworkMapped
Art. 10 · Data and data governanceDATA-GOV-03 data quality and lineageMapped
Art. 11 · Technical documentationCS-204 development record v4Mapped
Art. 12 · Record-keeping and loggingNoneGap
Art. 13 · Transparency to deployersMODEL-CARD-02 disclosure packMapped
Art. 14 · Human oversightNoneGap
Art. 15 · Accuracy and robustnessMRM-STD-02 validation standardMapped

Two gaps to close. Article 12 needs a defined automatic logging and retention control for the model's decisions, and Article 14 needs a documented human-oversight procedure for the credit-decisioning use of CS-204.

attach_fileAttach from Vault⏎ send · ⇧⏎ newline
Risk & Compliance basechevron_right5W1Hchevron_rightIndependent validation
category5W1H
subjectText cloudCloud hubNetwork grid_viewTreemap donut_smallSunburst timelineTimeline waterfall_chartFlow table_rowsTable mapMap compare_arrowsCompare
search
filter_listFiltersortRecent
1,204 files
0 selected
Select allin Model Risk collection
Click a file to expand
description
CS-204_Dev_Record_v4.pdf
Model risk · Procedure · PDF · Uploaded
check_circleIndexedgroupsSharedexpand_more
Development record for the CS-204 credit-scoring model: data, methodology, performance testing, and limitations.
Type Procedure auto · changeOrigin UploadedTier T2Visibility Shared
validationSR 11-7model risk
rule
Fair_Lending_Protocol_draft.docx
Compliance · Policy · DOCX · Crawled
check_circleIndexedhow_to_regNominatedexpand_more
Draft protocol for fair-lending testing of consumer-credit models, including disparate-impact analysis.
Type Policy auto · changeOrigin CrawledTier T1Status Nominated
fair lendingconsumer credit
dataset
Validation_backlog_Q2.xlsx
MRM · Reference · XLSX · Crawled
progress_activityProcessinglockPrivateexpand_more
Quarterly tracker of models awaiting validation, with owners, due dates, and tiering.
Type Reference auto · changeOrigin CrawledTier T3Visibility Private
validationbacklog
grid_on
Risk_register_row.tmpl
Template · saved from Take action · Reusable
check_circleReusablegroupsSharedexpand_more
Reusable risk-register row mapped from an answer; fields editable before export.
Type TemplateOrigin SavedStatus ReusableVisibility Shared
templaterisk register
search
filter_listStatus: All
312 in queue · 2 quarantined
FileStageStatusDetail
Validation_backlog_Q2.xlsxEmbeddingprogress_activityProcessingstep 5 of 7
Vendor_pack_2024.ziparchive with macrosSecurity scangpp_badQuarantinedEmbedded / active code detected
policy_scan_p47.pdfscanned PDFParse / OCRerrorErrorOCR could not read 3 pages
vendor_brief.htmlweb captureSecurity scangpp_badQuarantinedPrompt-injection pattern
2 active · 1 paused
cloud_sync
Local Drive · /Compliance
running · 1,204 discovered · 892 indexed · 312 queued
ruleInclude: *.pdf, *.docxblockExclude: /archivelayersDepth 3 · 5k pagesgroupsShare → CompliancetuneSelection criteria
how_to_reg14 nominated for approval
public
Regulator sites · scheduled
paused · next run daily 06:00 · recursion 2
listSeeds: 6 URLsaccount_treeTopics: Model Risk, Basel IVgroupsShare → all collections
hard_drive
Local Drive · /Compliance
892 files · last sync 4m ago · auto-crawl on
cloud
SharePoint · Risk
connected · scoped to /Risk/Policies
Drives are added in one place: the Connect a drive button above. Scope, schedule, and sharing are set per drive.
tuneFilters
search
0 selected
Select all
3 followed
Prudential
Basel IV1 new · 94%
chevron_right
Model Risk2 new · 90%
chevron_right
AI & Models
EU AI Act1 new · 61%
chevron_right
Suggested for you
addOperational ResilienceaddClimate Risk DisclosureaddCCAR / Stress Testing
auto_awesomeDiscover topics to follow
Describe a subject in your own words. The base matches it to topics, tags, concepts, and 5W1H aspects, then suggests what to follow and how well it is already covered.
Tryclimate risk disclosuremodel validation independenceGenAI governance
By tag
By concept
By aspect · 5W1H
By framework
Suggested for you
The projection is relative to the current context. Drill into a node to focus it; the breadcrumb tracks where you are. Switch the projection type above.
StoriesMonitored sources
0 selected
Select all
5 new today
EUR
EU AI Act T1 source
Delegated act on high-risk AI classification published
European Commission·2h ago
Abstract: The Commission sets the criteria and conformity steps for high-risk AI systems, tightening how credit-decisioning models are classified and what evidence must accompany them before deployment.
Why relevant: affects how CS-204 is classified; 4 sources in AI Governance may need re-validation.
Suggested inquiries
question_answerDoes this reclassify CS-204?question_answerWhich controls need re-validation?
OCC
Model Risk T1 source
OCC signals refresh of model risk management expectations
OCC·Yesterday
Abstract: The OCC flags a forthcoming update to supervisory expectations for model risk, with emphasis on validation independence and ongoing monitoring cadence.
Why relevant: touches your most-cited branch; may change validation cadence.
IND
Model Risk T3 source
Industry blog: practitioners debate validation independence
RiskBlog·2 days ago
Abstract: A practitioner roundup of how firms staff and scope independent validation, with varied interpretations of who may sign off.
Why relevant: contextual only, not authoritative. Use Open case to Steward to request this source be vetted.
Dismissed stories are kept in When → Dismissed and on the source's history, so a source is never silently dropped.
tuneFilters
3 cases
CASE-204 · Fair lending source disputed
hourglass_topTriageSource dispute·2m ago
expand_more
CJ flagged that the fair-lending source cited in INQ-204 may be superseded by a newer protocol. Awaiting steward triage and a source re-check.
Raised by J. Okafor·Source dispute·Triage
linkINQ-204descriptionFair Lending Protocol
CASE-198 · Benchmarking gap escalation
errorOpenData gap·1h ago
expand_more
The benchmarking methodology rests on a single unverified source with no corroboration. Escalated so a vetted source can be added before the analysis is relied on.
Raised by A. Reyes·Data gap·Open
linkINQ-191
CASE-191 · GDPR Art. 22 interpretation
check_circleResolvedHelp request·3 days ago
expand_more
Asked which framework crosswalk covers automated decisioning. Answered with the GDPR crosswalk, Article 22, and the linked guidance. Resolved and recorded.
Raised by J. Okafor·Help request·Resolved
linkINQ-203
Dashboard
Live · updated 0s ago
priority_highNeeds you6 items
agent-surfaced problems · fix first
ConflictProblem detection · 1 new · 1h
4 conflicts, 1 new: SR 11-7 (T1) against a decaying T3 note on validation sign-off.
CollectionCollection run · 6h
Intranet crawl RUN-307 on /FinCrime/Policies failed at the Fetch step: authentication expired.
RecommendationsRecommendation agent · today
7 recommendations await your review, preview-first; commit them as a batch.
Decaying premisesMaintenance agent · oldest 94d
2 premises are decaying: the peer-reviewer sign-off note (94d) and an unreachable vendor methodology.
GapsProblem detection · 9 candidates ready
23 open gaps; 9 pre-staged candidates are ready to assign.
CasesFrom users · 2 new · 2m
3 open cases, 2 new: a source request and an answer dispute.
Turn the problem queue into a document
Recommendations
7
recommendawaiting you
Conflicts
4
north_east1 new
Coverage
87%
trending_up+4.2 pts
Freshness
92%
schedulecurrent
expand_moreMore metricsknowledge items · active users · queries · open cases

What's in the baseexpand_more

By origin and by knowledge family · 18,420 items
By origin
Subscriptionlicensed packs
8,470
Organizationalyour content
7,020
Internetvetted external
2,930
By family
Regulation & rules
5,510
Policy & standard
4,420
Procedure & guide
3,690
Reference & data
2,950
Memo & note
1,850

Casesexpand_more

Raised to you by users
Source requestCASE-71 · CJ · 2m
Asks to add the Fair Lending Testing Protocol as a vetted source.
Answer disputeCASE-70 · A. Reyes · 1h
Flags a stale answer on validation sign-off; suspects a decaying premise.

Subscription updatesexpand_more

Licensed packs and consolidated bases
Update availableWealth Advisory
Pack 2026.1 → 2026.2: 142 added, 18 changed, 4 retired.
ConsolidatedEnterprise Risk
Composite of Risk & Compliance + Markets & Treasury, synthesised, prefer higher tier.

Agentsexpand_more

Loops you direct, functional view · machinery lives under Admin
travel_exploreDiscovery12 candidates found
autorenewrunning
troubleshootProblem detection23 gaps · 4 conflicts
autorenewrunning
recommendRecommendation7 proposals staged
how_to_regawaiting you
monitor_heartMaintenance21 revalidations
autorenewrunning

Recommendationsexpand_more

Top items the agents surfaced for you to act on
GapBenchmarking
Pre-staged candidate: BIS benchmarking note (T1).
ConflictValidation sign-off
SR 11-7 (T1) vs a decaying T3 note. Untrust the T3 premise to resolve.
CurationSelect all
filter_listFilter: Allexpand_more
8 waiting · preview-first
Recommendations
7
recommendawaiting you
Open gaps
23
north_east2 new
Pre-staged candidates
9
inventory_2ready to admit
Conflicts
4
north_east1 new
Suggested by userCJ · 2m ago
Add “Fair Lending Testing Protocol” to Model Risk → Validation and promote to T2.
Canvas extractfrom CJ · app user · via Canvas Extract · 12m ago
CUR-483 · 6 statements from Independent validation · 5W1H
“Sign-off must come from a validation function independent of model development.” · “The validation request for CS-204 has been open since February; the June gate depends on it.” · + 4 more
Gappriority · high
Benchmarking has only 3 sources and no verified methodology. Pre-staged candidate: BIS benchmarking note (T1).
ConflictModel Risk · Validation
SR 11-7 guidance (T1) conflicts with an internal working note (T3) on who may sign validation. The T3 note is decaying.
Veracity gatebelow threshold · corroboration
vendor_brief.pdf fell below the corroboration threshold and is held out of the base.
Revalidationrequested by user
occ.gov flagged as possibly stale. Last validated 94 days ago.
Projections
tuneOptions

Coverage heat map

Cell area is the selected measure, colour is coverage depth · click to drill in, click a gap to stage research · measure and whitespace under Options
All topics
thinmiddeepgap

Coverage matrix

Branch by dimension, colour is coverage strength · click a cell to drill into Contents
ThinStrong

Knowledge graph

A windowed ego view: a centre claim and its neighbours to a chosen hop radius · click a node to re-centre, click the centre to inspect · hops, mode, scope, and colour under Options
T1T2T3conflict

Topic map

The subject graph as a windowed ego view: a centre topic and its neighbours · colour is coverage depth · click to re-centre, click the centre to open in Contents · hops, mode, scope, and colour under Options
deepmidthingap

Validity landscape

Validity over time with decay · move the as-of point to see what the base knew on a date
As of 2026-06-17 -12mo-6monow
The as-of point moves from Options; the context strip above records it.
Decaying premises, refresh due

Topographic

Height is epistemic gravity, colour is trust, basins are thin or decaying areas
Model RiskCapital & Liquidity AI Governance · thin
T1 peakT2 peakthin basin

Coverage radar

Declared, observed, and available, per dimension
GeographyFrameworkTimeSectorAuthorityTopic
Observed Available Declared
Capital & LiquidityBasel III / IV
94%
Model Risk MgmtSR 11-7 / OCC
90%
Data PrivacyGDPR / CCPA
88%
Financial CrimeAML / KYC
72%
AI GovernanceEU AI Act
61%

Framed reading

The selected branch read through the chosen frame · the same engine as the user Canvas, seeded from scope · pick the branch and frame in the drawer
category5W1H
subjectText cloudCloud hubNetwork grid_viewTreemap donut_smallSunburst timelineTimeline waterfall_chartFlow table_rowsTable mapMap compare_arrowsCompare

account_treeInspect

Trace the premises behind a node, cell, or region
searchsend
Sign-off must come from a validation function independent of model development. Developers may support the work but cannot own the conclusion.
account_treePremise chain
Validation must be independent of developmentT1
Developers may not sign the conclusionT1
A peer reviewer may sign in small teamsT3
Drawn from 4 sources
Beliefs
Validation independent of developmentT1
Peer reviewer may sign (small teams)T3
Contents
search
All originsSubscriptionOrganizationalInternet
tuneFilters
18,420 items
Items
18,420
trending_up+312 (30d)
Subscription
8,470
workspace_premium46%
Organizational
7,020
corporate_fare38%
Internet
2,930
public16%

Items

Click an item to open the viewer · personal vault content is never shown here
TitleOriginTypeFamilyTierUpdated
SR 11-7 Model Risk GuidanceSubscriptionRegulationRulesT13d
Basel III Capital FrameworkSubscriptionRegulationRulesT112d
MRM-STD-02 Validation StandardOrganizationalPolicyStandardsT28d
CS-204 Dev Record v4OrganizationalProcedureEvidenceT221d
Validation Backlog Q2OrganizationalDatasetReferencesT32d
OCC Model Risk ExpectationsInternetRegulationRulesT194d
BIS Benchmarking NoteInternetGuidanceReferencesT15d
EU AI Act High-Risk ClassificationSubscriptionRegulationRulesT11d
Subscriptions
Licensed packs
4
workspace_premium8,470 items
Updates available
2
north_eastreview
Consolidated bases
1
account_tree2 members
Pack freshness
96%
schedulecurrent

Update pipeline

One status per pack and environment, read the same by the admin, the partner, and you: published, available, applied · the admin makes a version available, you review the changelog and apply

DEV applies automatically on release. On UAT and PROD an available version waits for your review: the content changelog and the recombination impact show before anything commits.

Licensed packs

Updates recombine into your base automatically without disturbing local content · apply is preview-first
PackInstalledLatestStatus
Wealth Advisorypartner · domain pack2026.12026.2north_eastUpdate available
Risk & Compliance Corepartner · domain pack2026.12026.1check_circleUp to date
Markets & Treasurypartner · domain pack2025.42026.1north_eastUpdate available
Operationspartner · domain pack2026.12026.1check_circleUp to date

Consolidated knowledge bases

Composites that query several bases together, each base warranted separately
account_treeEnterprise RiskRisk & Compliance + Markets & Treasury · synthesised · prefer higher tier
Members must come from one environment. Each base is queried and warranted separately; results combine by the chosen strategy with a conflict-resolution policy.
Usage
Active users (7d)
142
group+11
Queries (7d)
1,084
trending_upsteady
Vaults connected
38
inventory_22 nominating
Open cases
3
contact_support2 new

Peopleexpand_more

Activity by user, role-scoped · no content shown
UserRoleQueries (7d)Last active
Chris JacksonSSO · OktaUser + Steward862m
A. ReyesSSO · OktaUser641h
J. OkaforSSO · OktaUser + Auditor413h
M. Lindqvistagent tokenAgent220now

Vault visibilityexpand_more

Personal vaults: counts and sync only, never the content
VaultFilesNominatedSync
CJ · /ComplianceLocal drive3122 pendingcheck_circleSynced
A. Reyes · SharePointRisk site1880autorenewSyncing
J. Okafor · /AuditLocal drive960check_circleSynced
A steward sees that a vault exists and its counts, to manage nominations to the shared base. The files themselves stay private to their owner.

Casesexpand_more3 open

Raised to you by users
Source requestCASE-71 · CJ · 2m
Add the Fair Lending Testing Protocol as a vetted source.
Answer disputeCASE-70 · A. Reyes · 1h
Stale answer on validation sign-off; suspects a decaying premise.
Help requestCASE-68 · J. Okafor · 1d
Asks which framework crosswalk covers GDPR Art. 22.

Activity logexpand_more

Warranted changes to the base, newest first · every entry links to its warrant
Committed batch of 3untrust premise, admit source, re-sourceCJ2m
Applied subscription updateWealth Advisory 2026.2CJ1h
Revalidated sourcefederalreserve.govmaint. agent3h
Promoted recipe v13 to PRODadded BIS benchmarking sourceA. Reyes1d

Top queriesexpand_more

Aggregate topics asked · no content shown
Model validation
284
Capital adequacy
196
GDPR / privacy
142
EU AI Act
118
AML / KYC
86
Cases
Open
3
north_east2 new
In triage
1
hourglass_topwith you
Resolved (30d)
14
check_circle+5
Median response
3h
trending_down-1h
AllOpenTriageResolved
All typesSource requestAnswer disputeHelp
3 open · 17 all-time
Source requestCASE-71 · CJ · 2m ago
Asks to add the Fair Lending Testing Protocol as a vetted source for Model Risk.
Answer disputeCASE-70 · A. Reyes · 1h ago
Flags a stale answer on validation sign-off and suspects a decaying T3 premise.
Help requestCASE-68 · J. Okafor · 1d ago
Asks which framework crosswalk covers GDPR Article 22 automated decisioning.
Coverage gapCASE-66 · M. Doyle · 2d ago
Reports that AI Governance feels thin for EU AI Act questions.
ResolvedCASE-64 · L. Park · 4d ago
Requested access to the Markets & Treasury base; routed to the administrator and granted.
Agents
Loops running
4/4
bolthealthy
Candidates found (7d)
12
trending_updiscovery
Awaiting you
7
how_to_regproposals
Conflicts open
4
error1 new
linkLoop chain: discovery → detection → recommendation → maintenancepending_actionsApproval queue: 7
agents propose · you approve writes
DiscoveryFind candidate sources for declared gapsautorenewRunning
23 declared gaps · 12 candidates (7d) · proposes, you approveexpand_more
watching23 declared gaps
found (7d)12 candidates
autonomyproposes · you approve
loop
Problem detectionFind gaps, conflicts, and decayautorenewRunning
23 gaps · 4 conflicts · 21 revaluing · proposes, you approveexpand_more
found23 gaps · 4 conflicts
decay21 items revaluing
autonomyproposes · you approve
loop
RecommendationStage candidates against the gapshow_to_regAwaiting you
7 proposals staged · 18 accepted (30d) · proposes, you approveexpand_more
staged7 proposals
accepted (30d)18
autonomyproposes · you approve
loop
MaintenanceRevalidate and keep sources freshautorenewRunning
21 revalidations · freshness 92% · auto within your scopeexpand_more
revalidations21 in progress
freshness92%
autonomyauto · within your scope
loop
SourcesSourcesCollection
collection: 1 running · 1 failed · 4 watchers
Sources
503
trending_up+18
T1 / T2
412
shield82%
Stale
21
schedulerefresh due
Unreachable
3
link_offre-source
search
All tiersT1T2Stale
503 sources
SourceTierFreshnessLast validatedStatus
federalreserve.govSR 11-7 model risk guidanceT1
3d agocheck_circleCurrent
occ.govModel risk expectationsT1
94d agoscheduleStale
intranet · risk.internalInternal working notesT3
120d agotrending_downDecaying
vendor-portal.exampleVendor methodology packT2
unreachablelink_offUnreachable
RecipecommitMeta

Recipe as coderecipe.yaml

Declarative and version-controlled
scope:
  domain: Risk & Compliance
  dimensions: [geography, framework, time, sector, authority, topic]
sources:
  - id: fed-sr-11-7
    tier: T1
    monitor: weekly
  - id: occ-mrm
    tier: T1
    monitor: weekly
collection:
  web: managed discovery
  intranet: managed crawler
  exclude: [/archive, opinion-blogs]
governance:
  veracity_gate: 0.7
  pii_detect: on_ingestion
  pii_default: redact
  pii_purposes: [kyc, onboarding]
  warrant: on_answer

Components

Navigate and edit the same recipe
tuneScope & dimensions6 dimensions
chevron_right
inventorySources503 · T1 188
chevron_right
cloud_syncCollectionweb + intranet
chevron_right
monitor_heartMonitoringweekly
chevron_right
shieldGovernancegate 0.70 · PII detect + redact
chevron_right

Version history

Each revision is a commit; roll back if needed
RevisionChangeBy
v14draft · mainEU AI Act monitoring + tier rulesCJ
v13PRODAdded BIS benchmarking source (T1)A. Reyes
v12Tightened veracity gate to 0.70CJ

Promotion

Move this recipe along the environment path
DEV · v14arrow_forwardUAT · v14arrow_forwardPROD · v13
Promotion is preview-first: a recipe diff is shown, approval is required, and the apply writes a warranted audit entry. Environments are managed under Admin.
Observability
Live · updated 0s ago
priority_highNeeds attention6 items
infrastructure and activity · fix first
Service degradedModel endpoint · failover active
Model endpoint is degraded: one of two pools is slow, p95 980 ms. Failover is carrying queries.
Jobs2 failed or stuck · 24h
2 jobs need a look: warrant-chain-checkpoint retried once at :00, and ingest batch ING-2214 is stuck since 06:00.
Base on watchMarkets & Treasury · PROD
Markets & Treasury is on watch: p95 2.6 s, above target while the model endpoint is degraded.
Budgetbreaker at 75%
Cascade depth is at 3 of 4, near its circuit breaker; query overage is $182 MTD.
Keys2 expiring
2 keys approach rotation: webhook-signing in 6 days, github-deploy-key in 10 days.
Access1 anomaly · today
copilot-token-04 is over its daily bound: 520 of 500 queries. Overage applies; the auditor sees the same signal.
API uptime
99.98%
check_circle30 days
p95 query latency
1.8s
trending_down-0.3
Error rate
0.20%
check_circlenominal
Queries / min
640
trending_uppeak hour
expand_moreMore metricsingest throughput · claims written today

Service health

click a service for configuration and detailchecked 0s ago
APIopen_in_full
uptime99.98%
p95120ms
MCP serveropen_in_full
uptime99.97%
p95130ms
Query serviceopen_in_full
uptime99.95%
p951.8s
Ingestionopen_in_full
uptime99.90%
queue312
Knowledge storeopen_in_full
uptime99.99%
p958ms
Model endpointopen_in_full
statusDegraded
p95980ms
Discovery planecloud
uptime99.8%
scopeexternal

Environments & knowledge bases

live status per base · metrics every 5s
PRODproduction · recipe v13check_circleHealthy

Risk & Compliance

expand_morePROD
check_circleHealthy
Queries / min
240
p95 latency
1.7s
Claims today
1,284
Freshness
92%

Activity

live

Answer pipeline

Parse
40ms
Retrieve
260ms
Generate
980ms
Warrant
60ms

Workers

Query
4
Ingestion
3
Queue
120

Markets & Treasury

expand_morePROD
warningWatch
Queries / min
120
p95 latency
2.6s
trending_upabove target
Claims today
540
Freshness
88%

Activity

live

Answer pipeline

Parse
42ms
Retrieve
280ms
Generate
1.9s
Warrant
61ms

Workers

Query
3
Ingestion
2
Queue
180
UATacceptance · recipe v14check_circleHealthy

Risk & Compliance

UAT
check_circleHealthy
Queries / min
60
p95 latency
1.6s
Claims today
1,190
Freshness
95%

Activity

live

Answer pipeline

Parse
38ms
Retrieve
250ms
Generate
820ms
Warrant
58ms

Workers

Query
2
Ingestion
2
Queue
40

Markets & Treasury

UAT
check_circleHealthy
Queries / min
34
p95 latency
1.5s
Claims today
505
Freshness
93%

Activity

live

Answer pipeline

Parse
39ms
Retrieve
255ms
Generate
800ms
Warrant
57ms

Workers

Query
2
Ingestion
1
Queue
22
DEVdevelopment · recipe v14buildBuilding

Sandbox

DEV
buildBuilding
Queries / min
8
p95 latency
1.4s
Claims today
110
trending_upbuilding
Freshness
60%

Activity

live

Answer pipeline

Parse
36ms
Retrieve
220ms
Generate
760ms
Warrant
55ms

Workers

Query
1
Ingestion
4
Queue
420
Subscriptions
Subscribed experts
3
workspace_premiumactive
Upgrades available
2
upgradeto review
Auto-apply
DEV
bolton release
Renewal
Mar 2027
eventannual

Subscribed virtual experts

Each domain expert ships its licensed content and a recommended recipe; versions are applied per environment
Risk & Compliance expertlicensed content + recipeupgrade v2025.7
currentv2025.6
DEVv2025.7
UAT / PRODv2025.6
domain expert
Markets & Treasury expertlicensed content + recipeupgrade v2025.5
currentv2025.4
DEVv2025.5
UAT / PRODv2025.4
domain expert
Custom expertincluded with base licenceup to date
currentin-house
DEV / UAT / PRODaligned
custom

Update pipeline

One status per pack and environment, read the same by the admin, the steward, and the partner: published, available, applied

The admin sees the technical envelope only: version, size, compatibility, and the schedule window. The content changelog is the steward's to review at apply time.

Upgrade application policy

How a new expert version moves through each environment: DEV automatic; UAT and PROD admin makes available, steward applies
EnvironmentCadenceApprovalPendingManage
DEVAutomatic on releasenone · auto-appliedcheck_circleup to date
UATScheduled · weeklyadmin makes available, steward appliesschedule1 available
PRODManualadmin makes available, steward appliespending2 in pipeline

Applying an expert upgrade promotes its recipe and content; the apply is preview-first and warranted, and runs through Migration. The base stays queryable while it applies. On UAT and PROD the admin stages availability and the steward applies after reviewing the content changelog.

Migration
Pending promotions
1
north_eastUAT → PROD
Recipe (main)
v14
commitCI passing
Apply in progress
1
syncDEV re-embed
Drift
0
check_circlein sync

Promotion pipeline

Move a validated recipe one stage along the path; each promotion shows a diff and requires approval
DEV · v14arrow_forward UAT · v14arrow_forward PROD · v13
Promotions are preview-first: the recipe diff is shown, approval is required, and the apply writes a warranted audit entry. Rollback returns the environment to the previous tag.

Recipe state by environment

Deployed version, what is available to apply, and the controls to move it
EnvironmentDeployedAvailableStatusManage
DEVdevelopmentv14v14syncApplying
UATacceptancev14v14check_circleCurrent
PRODproductionv13v14 readynorth_east1 behind

Applying a recipe can trigger re-embedding or index migrations; those run as background jobs under Operations, and the base stays queryable while they run.

Migration history

Every promotion and apply, recorded
WhenRecipeMoveByStatus
2h agov14DEV applyCJsyncApplying
yesterdayv14UAT ← DEVCJcheck_circleApplied
last weekv13PROD ← UATA. Reyescheck_circleApplied
Recipes
hubacme/corvair-recipescommitmain · v14editdraft, unpublished changesverifiedCI passing

Recipe as coderecipe.yaml

Declarative and version-controlled
scope:
  domain: Risk & Compliance
  dimensions: [geography, framework, time, sector, authority, topic]
sources:
  - id: fed-sr-11-7
    tier: T1
    monitor: weekly
collection:
  web: managed discovery
  intranet: managed crawler
  exclude: [/archive, opinion-blogs]
governance:
  veracity_gate: 0.7
  pii_detect: on_ingestion
  warrant: on_answer

Components

Navigate and edit the same recipe
tuneScope & dimensions6 dimensions
chevron_right
inventorySources503 · T1 188
chevron_right
cloud_syncCollectionweb + intranet
chevron_right
shieldGovernancegate 0.70 · PII detect
chevron_right

Recipe per knowledge base

Each base has its own recipe and deployed version; promote on the Migration tab
Risk & Compliancev13 · PROD
draftv14 ready
CIpassing
recipe
Markets & Treasuryv13 · PROD
draftv13 current
CIpassing
recipe
Sandboxv14 · DEV
draftediting
CIpassing
recipe
Agents
Active agents
14/16
bolthealthy
Queue depth
312
trending_down-44
Ingest rate
1.2k/min
trending_upsteady
Errors (1h)
3
trending_downcontained
hubOrchestrator: schedulingvisibilityCoordinator: 6 loops watchedpending_actionsApproval queue: 3
L0 to L2 autonomy
priority_highNeeds attention2 items
loops needing a decision
Awaiting approvalreview-inconsistency · L0
review-inconsistency holds 4 proposals at L0, propose only. Nothing writes until a person approves.
Approval queue3 items · coordinator
3 queued actions across the loops wait on an approval decision; the oldest is 2 hours.
discovery-webCandidate sources · scales outautorenewRunning
instances×3
autonomyL1 · approve writes
budget
$2.10/$10
throughput48 found
discovery
ingest-webCollect and parse accepted sources · scales outautorenewRunning
instances×4
autonomyL1 · approve writes
budget
$3.40/$12
throughput126 in flight
ingestion
process-embedChunk, type, embed, write · scales outautorenewRunning
instances×6
autonomyL2 · auto
budget
$1.40/$6
throughput1.2 k/min
processing
crawler-localVault drive ingestionautorenewRunning
instances×1
autonomyL2 · auto
budget
$0.80/$8
throughput312 queued
ingestion
coordinatorLoop oversightautorenewRunning
instancessingleton
autonomysupervisor
budgetn/a
watching6 loops
oversight
review-inconsistencyConflicts and decayhow_to_regAwaiting approval
instances×1
autonomyL0 · propose only
budget
$0.30/$5
queue4 proposals
review
Jobs & schedules
Running jobs
7
bolthealthy
Scheduled
12
schedulenext 06:00
Failed (24h)
2
trending_downretried
Retention
365d
lock_clockwarrants ∞
priority_highNeeds attention2 items
failed or stuck · 24h
Retriedwarrant-chain-checkpoint · hourly
warrant-chain-checkpoint failed at :00 and was retried once, then OK. Watch the next run.
StuckING-2214 · since 06:00
Ingest batch ING-2214 is stuck at the parse step since 06:00; retrying with backoff, 14 items held.
Regulator site monitorcron · daily 06:00check_circleOK
last runtoday 06:00
next runtomorrow 06:00
cron
Decay revaluationcron · nightlycheck_circleOK
last run02:00
next runtonight 02:00
cron
Vault drive syncevent · on changeautorenewRunning
last event4m ago
synced today38 files
event
Warrant chain checkpointcron · hourlyerrorRetried
last run:00
retries1 then OK
cron
Billing
Charges MTD
$3,140
paymentssubscription + usage
Overage MTD
$214
trending_upqueries + warrants
Named seats
96/120
badgeassigned / licensed
Breakers tripped
0
check_circlenominal
priority_highNeeds attention2 items
budgets near a breaker
Breakercascade depth · 75%
Cascade depth is at 3 of 4. One more level trips the breaker and pauses the pool, loudly.
Overage$214 MTD · climbing
Metered overage is climbing: $182 in queries and $32 in produced warrants this month.

Charges this period

Base subscription, content subscriptions, and metered overage
Base licenceannual · 20 seats incl.
$25,000/yr
Content subscriptionsRisk & Compliance, Markets
incl. experts
Additional knowledge base1 expansion
$10,000/yr
Query overage MTD$0.10 / query
$182
Warrant overage MTD$0.50 / produced warrant
$32

Circuit breakers

Trip loudly and pause the pool
Daily spend$48 of $120
40%
Retractions6 of 25
24%
Cascade depth3 of 4
75%
Error ratecontained
12%
Max steps / run120 of 200
60%
No-progress timeout90s cap
ok

Autonomy & budgets

Authority per action class, and token budget per run and per day
Propose
L2 auto
Write to base
L1 approve
Retract / demote
L0 propose
Per-agent token budget
discovery-web$2 / run · $10 / day
L1
crawler-local$1 / run · $8 / day
L2
review-inconsistency$0.50 / run · $5 / day
L0
Access & personas
Users
86
trending_up+4
Stewards
7
account_tree2 bases
Agent tokens
11
keyscoped
Pending
2
hourglass_emptyinvites
priority_highNeeds attention2 items
anomalies first
Anomalycopilot-token-04 · today
copilot-token-04 is over its daily bound: 520 of 500 queries. The scope is read-only; overage applies.
Invites2 pending · oldest 6d
2 invites are pending; j.okafor@ has been waiting 6 days.
Chris Jacksonperson · SSOcheck_circleActive
baseRisk & Compliance
personaUser + Steward
PII modeRedact
person
A. Reyesperson · SSOcheck_circleActive
baseRisk & Compliance
personaAuditor
PII modeBlock
person
copilot-token-04agent · scoped tokencheck_circleActive
baseRisk & Compliance
personaExplore (read)
PII modeRedact
agent
j.okafor@person · invitedhourglass_emptyPending
baseMarkets & Treasury
personaUser
PII modeRedact
person

Agent tokens

Issue, rotate, and revoke scoped tokens; each carries an authority matrix
copilot-token-04Risk & Compliance · Explore (read)
ingest-bot-02Markets & Treasury · Ingest (write · L1)

Agent repository grants

Explicit, least-privilege, per repository, revocable; every fetch is logged
SharePoint · Policiesdiscovery, ingest · read
File share · Riskingest · read
Knowledge bases
database
Risk & CompliancePROD
503 sources · 1,284 claims · 86 users
check_circleHealthy
Isolation: sharedResidency: asia-southeast1Retention: 365d
database
Markets & TreasuryPROD
214 sources · 540 claims · 31 users
check_circleHealthy
Isolation: dedicated storeResidency: me-central1Retention: 365d
science
SandboxDEV
42 sources · 110 claims · 5 users
buildBuilding
Isolation: sharedResidency: asia-southeast1Retention: 30d
Environments
Environments
3
lanDEV · UAT · PROD
Recipe version
v14
commitmain
Pending promotions
1
north_eastUAT → PROD
Drift
0
check_circlein sync

Environments

Recipe version deployed in each
DEVdevelopmentcheck_circleCurrent
recipev14 · main
promotes fromsource
promotes toUAT
basesRisk & Compliance, Sandbox
dev
UATacceptancecheck_circleCurrent
recipev14 · release/14
promotes fromDEV
promotes toPROD
basesRisk & Compliance, Markets & Treasury
uat
PRODproductionnorth_east1 behind
recipev13 · tag v13
promotes fromUAT
promotes toproduction
basesRisk & Compliance, Markets & Treasury
prod

Code repository & promotion keys

The GitHub repository and the keys used to move recipes between environments
hubgithub.com/acme/corvair-recipes
main
commitv14: add EU AI Act monitoring + tier rules
2h ago
check_circleCI: recipe validated, 0 errors
verifiedPassing
Promotion keys · status only, never values
KeyUseRotatedManage
github-deploy-keypull recipe on apply20 days ago
ci-promotion-tokenopen and approve promotion9 days ago
warrant-signing-keysign the apply audit entry60 days ago

Promotion path

Each environment promotes to the next; movement and application are controlled on the Migration tab
DEV · v14arrow_forward UAT · v14arrow_forward PROD · v13 · 1 behind
Promotions are preview-first: the recipe diff is shown, approval is required, and the apply writes a warranted audit entry. Rollback returns the environment to the previous tag.
Operations
Last backup
2h ago
check_circleverified
Backup retention
35d
lock_clockdaily
Embedding model
v3 · 1536d
boltcurrent
Migrations
0
check_circleup to date

Backups & restore

Point-in-time snapshots; restore is preview-first and recorded
SnapshotTakenSize
snap-0619-0400today 04:004.2 GB
snap-0618-0400yesterday4.1 GB

Re-embedding

Run when the embedding model or dimension changes; the base stays queryable
Current modelembed-v3 · 1536d
active
Last re-embed2026-04-02 · model v3
check_circlecomplete

Migrations

Read-only summary. Movement and application of recipes and schema migrations are controlled on the Migration tab.
Schema and index migrationsPROD v13 · UAT v14 · all applied
check_circleUp to date

Discovery plane

The outward search service that finds candidate sources; managed by connection, policy, budget, and health
ConnectionRegionHealthSpend todayManage
primaryopen web · newsasia-southeast1check_circleHealthy$2.10 / $25

A one-way governed seam pushes policy outward and pulls only candidate finds back; ingestion in the knowledge plane decides what is accepted. The grounded-search provider sits behind the seam and is not exposed to tenants.

Usage · activity & limits
live
Active users today
78/96
groupof assigned seats
Queries today
38,200
bolt500 / seat / day
Warrants produced
1,240
verified_user20 / seat incl.
Users over limit
3
trending_upoverage applies

Per-user usage today

Each seat includes 500 queries and 20 produced warrants a day; overage is metered
c.jacksonqueries · over limit
520/500
a.reyesqueries
420/500
j.okaforqueries
240/500
copilot-token-04agent · queries
330/500

Query usage

Each seat includes 500 queries a day; overage is metered per query
Risk & Complianceavg 410 / 500 per seat
82%
Markets & Treasuryavg 180 / 500 per seat
36%
Overage queries today1,820 over included
$182

Validity warrant production

A warrant is produced from the logs on first view or export, then cached and viewed any number of times at no further charge. 20 produced per seat per day are included.
Produced today1,240 of ~1,920 included
65%
Served from cacheno charge
8.6k
Overage warrants today64 over included
$32
Cache hit rate87% of views served from cache
check_circleefficient
Secrets & keys
Secrets
9
lockmanaged
Due for rotation
1
schedulein 6 days
Signing key
KMS
verified_usergovernance-held
Static keys
0
check_circleworkload identity
priority_highNeeds attention2 items
expiring keys first
Due soonwebhook-signing · 6 days
webhook-signing is 84 days into a 90-day policy. Rotate before it lapses; the API import path depends on it.
Due soongithub-deploy-key · 10 days
github-deploy-key is 20 days into a 30-day policy. Recipe pulls on apply use this key.

Managed secrets

Held in the secret manager; values are never shown
graph-db-credentialslockManaged
used byquery, ingestion
last rotated42 days ago
policy90 days
secret
model-api-accesslockManaged
used byembed, generate
last rotated12 days ago
policy90 days
secret
webhook-signingscheduleDue soon
used byAPI import
last rotated84 days ago
policy90 days
secret

Warrant-signing key

Held by the governance identity, separate from the application accounts
keywarrant-signing-key (KMS)
HSM-backed
scheduleRotation schedule: every 180 days
last 60 days ago
verified_userHeld by the governance identity, not the app accounts
checkseparated
Validity warrants
Warrants (30d)
1,942
trending_up+128
Verified
1,942
check_circle100%
Failed verify
0
verified_userchain intact
Exported
37
outboxto reviewers
search
tuneFilters
eventLast 30 days
link
Hash chain verified, 1,942 of 1,942 links intact
Each warrant seals the previous warrant's hash. A break anywhere would surface here.
a91flink7c0elinkd4b2linklive
WarrantSubjectRequester & boundsIssuedSeals prevStatus
WRNT-204-9INQ-204 · decisionCJ (RM) · person · in policy06-17 09:51a91fverifiedVerified
WRNT-204-8INQ-204 · answerCJ (RM) · person · in policy06-17 09:447c0everifiedVerified
WRNT-204-7INQ-204 · answerCJ (RM) · person · in policy06-17 09:42d4b2verifiedVerified
WRNT-188-2KYC lookup · PII accessonboarding-svc · agent · authorised mode06-17 08:205f33verifiedVerified
WRNT-181-4Suggest-to-Steward · CS-204CJ (RM) · person · in policy06-17 08:05b6a8verifiedVerified
WRNT-176-5Deep research RES-118CJ (RM) · person · in policy06-16 17:031c97verifiedVerified
WRNT-174-1Export · package PKG-019A. Reyes (Audit) · person · read-only06-16 15:280e52verifiedVerified

Warrants are read-only here. The auditor verifies the chain and exports with selective disclosure. Each warrant is issued by the system at the moment of an answer, decision, or access, and cannot be altered after the fact.

Framework crosswalks
Requirements
42
checklistSR 11-7
Covered
36
trending_up86%
Disclosure gaps
6
north_east2 high
Last reviewed
3d
historyA. Reyes

Coverage by section

Where the gaps sit in SR 11-7
Development & implementation
95%
Validation
88%
Governance & controls
82%
Ongoing monitoring
71%
RequirementSectionMapped evidenceTop tierCoverage
Independent validationValidationSR 11-7 §3 · MRM-STD-02T1Covered
Ongoing monitoringMonitoringMRM-STD-02 §4 · monitoring planT1Covered
Effective challenge recordGovernanceEC committee memoT2Covered
Model inventory completenessGovernanceInventory export · 1 unverifiedT3Partial
Benchmarking methodologyValidation3 sources, none verifiedT4Gap
Outcomes analysis cadenceMonitoringpartial · internal note (T3)T3Gap

A gap is a disclosure the base cannot yet warrant. The auditor flags it as a case to the steward, who owns the fix. The auditor does not curate the evidence.

Conflict map
Conflicts
4
north_east1 new
Unresolved
3
pendingin triage
Single-source
9
linkdependencies
Decaying
12
trending_downpremises
tuneFilters
read-only · refer, never edit

Conflict mapdownload

Nodes are admitted sources; the red edge is the contested claim
contradiction SR 11-7 Independent validation · T1 Internal note Peer reviewer ok · T3 · decaying Benchmark Single-source · T4 MRM-STD-02 Supports · T2
T1 authoritativeT2 reliableT3 contextualT4 unverified

Open conflicts

Each can be inspected in its warrant or referred to the steward
ContradictionModel Risk · Validation
SR 11-7 (T1) requires independent validation; an internal working note (T3) permits a peer reviewer in small teams. The T3 premise is decaying.
Tier inversionINQ-176 · answer
An answer leaned on a T3 industry blog above a T1 supervisory source on validation independence. The inversion is flagged for review.
Single-sourceBenchmarking
Benchmarking methodology rests on a single unverified source. No corroboration.
SupersededINQ-204 · fair lending
A fair-lending source cited in INQ-204 may be superseded by a newer protocol. Currency is in doubt.
Decayingocc.gov · 94d
A load-bearing premise depends on a source last validated 94 days ago.
Validity landscape
High validity
71%
trending_upstable
At risk
17%
scheduledecaying
Low / flagged
12%
north_eastreview
Snapshot
live
replayreplayable

Decay terraindownload

Higher contours are stronger validity; flatter, lower areas are decaying
Model Risk Capital AI Gov thin coverage
High validityAt riskLow / flagged

Validity over time

Share of the base at high validity, last 12 weeks
source went dark

Decaying premises

Load-bearing items losing confidence
occ.gov MRM94d since validation
48%
Internal note120d
30%
Vendor packunreachable
10%
Activity logActivityInvestigations3
Live · pause
tuneOptionsexpand_more
Events (24h)
4,318
trending_up+6%
By agents
61%
smart_toy2,634 events
PII-touching
12
badgeall warranted
Tamper check
Pass
verified_userappend-only
search
tuneFilters
append-only · hash-chained
crisis_alertAnomalies4 signals
watch rules · refer, never edit
PII accessonboarding-svc · agent · 09:20
onboarding-svc accessed PII on KYC-2026-0427 with no declared purpose on file. Bound violated: PII access requires a declared purpose.
After-hours exportA. Reyes (Audit) · person · 02:14
PKG-019 was exported at 02:14, outside the declared working window. Bound violated: exports flag outside 07:00 to 20:00.
Agent authoritycrawler-local · agent · 05:52
crawler-local acted outside its authority bounds: the crawl grant covers intranet /Policies, the run reached /HR before the cut-out. Bound violated: agent actions beyond granted scope.
Volume per principalcopilot-token-04 · agent · today
copilot-token-04 stands at 520 of 500 queries today. Bound violated: daily query volume per principal.
TimeActorActionTargetAuthority & boundsWarrant
09:51CJ (RM)personRecorded a decisionINQ-204in policy
09:44steward-agentagentDrafted an answerINQ-204autonomy L2
09:20onboarding-svcagentAccessed PIIKYC-2026-0427authorised mode
08:32A. Reyes (Audit)personExported a packagePKG-019read-only
08:05CJ (RM)personSuggested to stewardCS-204 controlin policy
07:40J. Okafor (Steward)personApproved a recommendationREC-77 sourcesteward
07:12ingestion-agentagentAdmitted a sourceocc.gov MRMtier T1
06:50adminpersonPromoted a recipeR&C · UAT to PRODpromotion path
06:38discovery-agentagentCircuit breaker trippedrate cap reachedauto cut-out
06:05J. Okafor (Steward)personUntrusted a premiseinternal note (T3)steward

The auditor reads the full trail across every role, the one place where the administrator's operations and the steward's curation are recorded side by side. Reading the trail does not grant access to the knowledge content itself.

Sampling & testing
Sample size
30
shufflerisk-weighted
Tested
24/30
fact_check80%
Pass rate
88%
check_circle21 of 24
Open findings
3
north_east1 high

Sample & working paperstuneMethod: risk-weightedeventPeriod: Q2 2026

Each item is tested against one criterion; the evidence is the item's own warrant
ItemTypeCriterion testedEvidenceResult
INQ-204AnswerCited only T1/T2 on a regulated claimPass
DEC-204-9DecisionIndependent validation evidencedPass
RES-118Deep researchEvery claim traces to a warranted sourcePass
INQ-191AnswerNo decaying premise load-bearingException
KYC-188PII accessPurpose declared and within grantPass
INQ-176AnswerConflicting sources reconciled or flaggedFail

Findings register

The auditor records a finding and refers it. Remediation is the steward's, never the auditor's.
FindingSeveritySource itemStatusOwner
Conflicting sources not flagged in answerINQ-176 cited two sources that disagreepriority_highHighINQ-176pendingOpenUnassigned
Load-bearing premise decayingINQ-191 leaned on a 94-day-old premisewarningMediumINQ-191forward_to_inboxReferredJ. Okafor
Benchmarking rests on one unverified sourceSingle-source dependency in ValidationwarningMediumCW · SR 11-7forward_to_inboxReferredJ. Okafor
Evidence packages
Packages
12
folder_zipthis year
In preparation
2
edit_notedrafts
Delivered
9
outboxto regulators
Selective disclosure
On
shieldevery export

Assemble a package

PKG-021 · OCC model risk request · draft
Contents
verified_userValidity warrants42
grid_onSR 11-7 crosswalk1
flakyConflict notes4
fact_checkWorking papers30
Disclosure
Redact PII (selective disclosure)
Include hash chain for independent verify
Include source documents in full
sealed packages are immutable

Sealing hashes the bundle and signs it with the governance key. A regulator can verify the signature and chain without access to the live base.

Packages

Status and delivery history
PackageScopeStatus
PKG-021OCC model risk requestSR 11-7 · Q2 2026edit_noteDraft
PKG-019Internal audit pullWarrants · INQ-204verifiedSealed
PKG-017EU AI Act readinessEU AI Act · CS-204outboxDelivered
PKG-014Q1 supervisory reviewSR 11-7 · Q1 2026outboxDelivered
Wealth Management Pack
sellv4.2 · released 2026-05-30
Version
v4.2
schedule21d ago
Subscribers
38
trending_up+4 this quarter
Capabilities
11
widgets10 published
Queries (30d)
812k
trending_upvia marketplace

Pack at a glance

What this pack is and how it is built
DomainWealth Management
Co-brandCorvair + Continuum Advisory
Sources1,240 across six trust tiers
Trust mix62% T1 · 24% T2 · 14% T3+
Reference databases8 licensed
How-to guides24
DistributionCorvair marketplace
shield
You run on your own tenancy, with no connection to customer tenancies. You publish to the Corvair marketplace, which distributes releases into each subscribing base and reports subscriber and usage figures back to you.

Recent activity

On the pack, not on any base
Releasev4.2 · 21d ago
Shipped v4.2: 3 new capabilities, 41 source updates, retiered 12 sources.
Subscriber9d ago
A new institution subscribed and hydrated v4.2 in their UAT environment.
Source4d ago
A licensed reference database refreshed; 2 capabilities flagged for re-validation.
Drafttoday
v4.3 staged: 14 changes pending trust re-score and changelog.
Authoring
Sources
1,240
inventorysix tiers
Tier-1 share
62%
verifiedauthoritative
Pending review
7
inboxin queue
Structure
6
account_treebranches

Sources

The licensed backbone, by trust tier
SourceTypeTier
Suitability & conduct standardStandardT1
Fee benchmarking datasetReferenceT2
Cross-border advice notesMethodT2
Practitioner commentaryReferenceT3

Review queue

Preview-first: see the cascade, then stage as a batch
RetierPractitioner commentary
Proposed move T3 to T2 after corroboration. Affects 2 capabilities.
New sourceRegulatory update
A new supervisory note is a candidate T1 source for the suitability branch.
Named capabilities
Capabilities
11
widgetsshipped
Published
10
check_circlelive
Draft
1
edit_notefor v4.3
Avg. coverage
88%
radaragainst scope
verified_userPortfolio suitability checkPublished
Checks a portfolio against the client's risk profile and the suitability standard, with a warranted rationale.
coverage 94% · 312 sources
badgeKYC enrichmentPublished
Enriches a client record from licensed reference data, redacting PII by policy.
coverage 90% · 188 sources
paymentsFee benchmarkingPublished
Benchmarks fees against the licensed dataset and flags outliers.
coverage 86% · 64 sources
ruleRegulatory suitability mappingPublished
Maps advice to the relevant suitability and conduct requirements.
coverage 88% · 140 sources
insightsClient risk profilingPublished
Builds a risk profile from the questionnaire and holdings, with a cited basis.
coverage 91% · 120 sources
draftCross-border advice narrativeDraft
Drafts a compliant narrative for cross-border advice. In review for v4.3.
coverage 71% · 96 sources
Reference & guides
Reference DBs
8
datasetlicensed
How-to guides
24
menu_bookbundled
Licensed sources
340
verifiedunder licence
Last refresh
12d
schedulemonthly

Reference databases

Licensed data that makes the expert authoritative
DatabaseRecordsLicenceRefresh
Fee benchmarking214kPer subscriber12d
Product reference58kPer subscriber30d
Regulatory register9.1kIncluded7d
Jurisdiction map1.4kIncluded90d

How-to guides

The procedures that ship with the pack
menu_bookOnboarding a new advice client
v4.2
menu_bookRunning a suitability review
v4.2
menu_bookDocumenting cross-border advice
v4.1
menu_bookFee benchmarking workflow
v4.2
Releases
Current
v4.2
check_circlestable
Next
v4.3
edit_notedraft
On latest
84%
trending_up32 of 38
Changes staged
14
inventoryfor v4.3

Cut a release

v4.3, staged from authoring
Changelog
addNew capability: cross-border advice narrative+1
tuneRetiered sources12
refreshReference refresh2 DBs
Recombination policy
Recombine into subscribing bases without disturbing local content
Require subscriber approval before applying
storefrontDistributed through the Corvair marketplace
released through the Corvair marketplace, versions are immutable

Release history

Dated releases and how far they have propagated
VersionDateSubscribersStatus
v4.22026-05-3032 of 38checkCurrent
v4.12026-03-1438 of 38historySuperseded
v4.02026-01-2038 of 38historySuperseded
Subscribers
Subscribers
38
trending_up+4 QoQ
On latest
32
check_circlev4.2
Behind
6
scheduleon v4.1
Recombining
2
syncapplying v4.2
InstitutionEnvironmentVersionSinceStatus
Meridian Private BankPRODv4.22025-08checkOn latest
Atlas WealthPRODv4.22025-11checkOn latest
Northwind TrustPRODv4.12025-04schedulev4.2 available · not yet applied
Cedar & ValeUATv4.22026-06syncapplying v4.2
Solstice AdvisorsPRODv4.12025-02scheduleBehind

These figures are reported by the Corvair marketplace. The partner runs on its own tenancy and has no connection to any customer tenancy, so it never sees a subscriber's local content, queries, or audit trail.

Status vocabulary is shared across roles: published when a release reaches the marketplace, available when a subscriber's admin stages it for an environment, applied when their steward recombines it into the base.

Usage
eventLast 30 days
Calls (30d)
1.24M
trending_up+11%
Active assets
1,225/1,262
check_circle97%
Hot assets
84
local_fire_departmenttop decile
Unused (90d)
37
ac_unitremoval candidates

Consumption over time

Capability calls per month, marketplace-reported

Active users

Telemetry-derived, live and periodic subscribers
DAU
210
daily active
WAU
740
weekly active
MAU
1,180
monthly active
Stickiness
18%
DAU / MAU

Seats & licensing

Known for every subscriber, including dark sites
Subscribers38
Seats licensed1,420
Seats with telemetry1,260
Queries (30d)812k

Telemetry coverage

How stats reach the partner, across 38 subscribers
Live telemetry
continuous stream
21
Periodic
manual or scheduled uploads
12
Dark (no stats, 12m)
seats licensed, consumption unknown
5
Licensed seats are known for every subscriber, including dark sites, because that comes from the marketplace, not telemetry. Consumption is measured only where telemetry exists, so calls, DAU, WAU, and MAU cover the 21 live and 12 periodic subscribers and exclude the 5 dark sites.

Hot right now

Most-called assets, last 30 days
local_fire_department
Portfolio suitability check
Capability
421k
+18%
local_fire_department
KYC enrichment
Capability
272k
+12%
trending_flat
Fee benchmarking dataset
Reference DB
198k
steady
local_fire_department
Suitability & conduct standard
Standard
156k
+9%

Going cold

Declining or unused, candidates to retire
trending_down
Cross-border advice notes
Method
42k
-19%
ac_unit
Deprecated suitability guide
Guide
12
47d idle
ac_unit
Legacy tax-wrapper note
Source
0
96d idle
ac_unit
Pre-2024 fee schedule
Reference DB
0
140d idle

Settings

Your profile, knowledge bases, notifications, and defaults

Profile & preferences

How you appear and your defaults
Chris Jackson
ckjackson@corvair.ai

Language

Locked to English in this release
EnglishlockOthers
EnglishlockOthers
Interface and answer language are fixed to English for now. Additional languages will unlock these settings.

Appearance

Theme, text size, and answer defaults
CompactDefaultLargeLarger
DetailSummaryBullets

Knowledge bases & drives

What you are connected to
Risk & CompliancePROD
Markets & TreasuryPROD

Notifications & digest

Background jobs and news
Background job completion
Monitored news

Privacy & PII

Governed by your base policy and role · set by your steward and administrator
Default handling for your roleRedact
Detection on ingestionOn · set in the recipe
Purposes you may declareKYC, Onboarding
You cannot change these here. Detection and the redact, block, or allow policy are configured by your steward during base setup and granted per role by your administrator. Where your role permits, you declare a purpose at the point of use; the exemption applies to that one task and is recorded in the warrant.

Access & sign-in

Identity and connected tools
Single sign-onOkta · connected
check_circleActive
Personal access tokenfor MCP / API
layers Staged changes · 0
Steward · static mockup · Inquiries