The AIMS owner
Records whether the organization has adopted ISO/IEC 42001, for what scope, and from when. Until that decision exists, AI work can't enter the build lane, and no requester or model can make it for them.
Veritas / The request layer for enterprise software
In Veritas a request stays one living record, from the first sentence someone types to what production shows months later. Eight kinds of people touch that record. Each one sees it from their own world.
Scroll to follow one illustrative request, VR-0412, through every seat.
Vendor invoices sit in three inboxes and we keep paying late fees.
00 Why this exists
A request travels from the person who needs it to a PM, a business analyst, a developer, the AI team, the analytics team, and back. Everyone rewrites it a little. Nobody holds the original.
Instead of
With Veritas
Nobody passes a summary along. The requester's own words stay at the top of one record, and every seat, from the PM and analyst to the developers, the AI team, and analytics, works from that record and adds to it. Changing the intent creates a new revision that goes back through the gates, not a quiet rewrite in the next team's ticket.
Hand along the record, not the story.
Vendor invoices sit in three inboxes and we keep paying late fees. Every invoice should reach the right approver within a day.
Finance wants one AI inbox for invoices to cut late fees.
REQ-7.1: extract invoice fields from a shared mailbox into the ERP.
OCR pipeline on a nightly batch job.
Added a model that auto-codes general ledger accounts.
Success = invoices digitized and OCR accuracy.
The invoices are digitized. We still pay late fees.Not what I asked for
0 of 4 intents survived · 2 invented along the wayWith Veritas: every seat reads and extends the same record.
01 The asker
You know what's wrong better than anyone. You shouldn't have to translate it into a specification to be taken seriously.
Instead of
With Veritas
Describe what you saw and what should be different, in your own words. Veritas saves it as the first line of a record and does the looking: what the organization already says about it, what already exists, which rules might apply. Follow-up questions are shaped to your request, and you can always see who it's waiting on.
What did you see?
Vendor invoices sit in three inboxes and we keep paying late fees.
What should be different?
Every invoice reaches the right approver within a day, with no late fees.
02 CIOs and IT leaders
Every department wants its own AI tool, and some are already vibe-coding one on the side.
Instead of
With Veritas
Every request comes through the same door and lands on the same board: what's waiting, on whom, and which requests may duplicate something the organization already owns or is already building. Veritas recommends priority and sequencing against your own strategy; the material portfolio calls stay yours, with your name on them.
Build less. Build the right things.
03 AI governance and compliance
You're the one who has to say yes or no to AI use cases, usually from a deck and a hallway conversation.
Instead of
With Veritas
Each request arrives with its applicability already worked out by deterministic rules against a versioned registry: is it AI, is it consequential, is it federal, is it inside your ISO/IEC 42001 scope. The authorities in force are frozen with the record. Gates pass on reviewed evidence, never on a model's confidence, and anything unproven stays unknown until someone supplies the evidence.
Applicability · deterministic rules
Gate · payment approval controls
04 Developers and coding agents
Downstream, the build doesn't start from a Slack message. It starts from a contract.
Instead of
With Veritas
The contract is compiled from the governed record: requirements, controls, no-gos, acceptance criteria, and stop conditions. Generated files are fingerprinted against it. If the contract changes, the build goes back. A coding agent gets boundaries it can check itself against and a defined place to stop instead of improvising.
Build once. Build right.
requirement: route every invoice to its approver within one business day
control: read-only access to the ERP vendor master
no_go: approve or pay an invoice
no_go: change vendor bank details
accept: every test invoice reaches the right approver
stop_if: approver unknown → hold and report
digest: sha256:9f1c…e04a locked
- no_go: approve or pay an invoice
+ requirement: auto-approve invoices under $500
05 The reviewers who sign off
Security, privacy, legal, the business owner, the deployment authority: each attests to what they own.
Instead of
With Veritas
Attestations are recorded by role, for the current review cycle, with a rationale. Which roles must sign depends on the request: AI work adds AI governance, sensitive data adds privacy, high-impact use adds legal. The person who built it can't be the one who verifies it. A waiver needs its own named approver and an expiry date, so an exception is a decision with an end, not a loophole, and ISO/IEC 42001 conformity requirements can't be waived at all.
Today these are named attestations. Authenticated identity is a prerequisite before production use.
Waiver W-3 · single sign-on integration pending
Separate approver: CISO · expires in 94 days
06 The people running it
Tools don't stop at launch. Neither does the record.
Instead of
With Veritas
Production observations attach to the same record that authorized the tool. When one is recorded as a breach of its threshold, the request reopens for review and keeps the observation that caused it. The updated assessment and contract go back to people, and the old build can't simply be redeployed: its approvals belonged to a cycle that has closed.
Invoices approved within a day threshold 90%
obs #31 88% · late fees back · recorded on VR-0412
reassessment assessment, gates, contract → back to people
redeploy build 7 blocked · approvals belong to cycle 2
07 The auditor
From the first sentence someone typed to the latest production observation.
Instead of
With Veritas
One lineage with every authority, applicability finding, control, decision, exception, and release in between, each as it stood at the time. Opening an old record never attaches today's rules to it.
Today the lineage is logically append-only. Tamper-evident storage is a prerequisite before production use.
Every point on the line is a seat you just scrolled past.
08 The domain builder
Some people turn what they know about a field into a working tool other people can rely on.
What changes
The record stays the same. What changes is the world around it: the corpus Veritas searches, the authorities in its registry, and the shape of the assessment it generates.
The flagship use case
ConstructPolicies is for restoration and reconstruction contractors researching which codes and agency rules apply to a job, with cited source passages and coverage audited per jurisdiction. It points to the sources; it doesn't issue compliance determinations.
Fire-damaged roof on a job in a very high fire hazard severity zone. What applies?
Not an illustration
We ran the same invoice request through Veritas for a fictional company, Alder & Finch Distribution, with the models switched off. These are the screens it produced.
Synthetic company, people, and data. Captured from Veritas with models switched off (deterministic fallback). Some table columns are hidden for width and local file paths are omitted.
Also at the table
Records whether the organization has adopted ISO/IEC 42001, for what scope, and from when. Until that decision exists, AI work can't enter the build lane, and no requester or model can make it for them.
Their strategy and prior decisions are what every request is compared against. Veritas recommends a disposition; they make the call, by name.
Data sensitivity is triaged at intake. If a request touches sensitive data, privacy review becomes a required sign-off before release, not a discovery after it ships.
Runs Veritas on the organization's own infrastructure, points it at approved local models, or switches the models off and keeps the workflow.
The thread through every seat
In a prompt-to-app tool, the prompt disappears the moment the app appears. Nobody asked whether it should exist, whether it already exists, what rules apply, or who is accountable.
In Veritas the ask stays one living record from the first sentence to production. The organization's own strategy, policies, and existing tools are consulted before anything is built, and people make the decisions that matter.
Built for an organization that has to answer for what it ships.
Prompt-to-app
Veritas
Where it runs
Veritas runs on your own infrastructure against approved local models. Models do the interpretation; deterministic code owns the state, the gates, and the authorization. Switch the models off and the workflow degrades to deterministic behaviour instead of disappearing.
model-assisted deterministic people
Design partners
Bring one request your organization struggles to govern, from whichever seat you sit in, and run it through the full record with us. Veritas is early: a working single-node system, not yet a production service. Attestations are named rather than authenticated, the audit lineage is not yet tamper-evident, and production observations are recorded by people rather than ingested automatically. The request followed on this page is illustrative.