Every high-impact decision has a name behind it.
Approval gates, exception handling, rollback procedures, provenance, chain of custody, and evidence packs are designed to support accountable decision-making across the platform.
- Step 1Request
- Step 2Policy eval
- Step 3Risk threshold
- Step 4Reviewer assigned
- Step 5Decision
- Step 6Execute or block
- Step 7Evidence seal
Timeouts, escalation, rollback, and emergency pathways are configurable.
Modification visibly breaks the chain. Tamper-evident, not tamper-proof.
Human approval gates and governance structure
High-impact, ambiguous, or exception-triggering actions require explicit human review and approval before execution. Reviewers are assigned per overlay based on sensitivity, jurisdiction, and operational context — typically executive sponsors, compliance officers, IT/security leads, and operational reviewers.
- Approval-gate assignment. Named reviewers per overlay, scoped to sensitivity and jurisdiction.
- Multi-stage review workflow. Cross-border transfers, policy exceptions, emergency overrides, and cryptographic migrations pause at review gates.
- Rationale documentation. Every approval, denial, or modification is accompanied by a recorded reason; reviewer identity, timestamp, and policy state are logged.
- Cryptographic signing. Approvals and exception workflows are cryptographically signed and chained to an immutable evidence ledger.
- Exception and rollback. Denials and reversals invoke rollback procedures where supported and capture supporting evidence for post-hoc review.
- Continuous oversight. Quarterly assurance reviews and periodic audits analyze exception frequency, approval latency, and rollback events.
- Beneficiary control. The beneficiary organization retains ultimate authority over approval chains, evidence access, exception thresholds, and operational continuity. All governance boundaries are documented and reviewable.
The ECIA-7 review workflow
Consequential actions pass through seven checkpoints. Each checkpoint is a documented decision — not an automated pass-through — and is recorded on the evidence chain.
- Gate 1EligibilityIs the requester authorized for this class of action at all?
- Gate 2ClassificationWhat is the sensitivity and jurisdiction of the data or system in scope?
- Gate 3IntentWhat is the stated purpose, and does it match the requested action?
- Gate 4ApprovalWhich named reviewer(s) must sign; do they have the standing to sign?
- Gate 5ActionBounded execution with least-privilege scope and, where supported, a rollback token.
- Gate 6EvidenceImmutable record of decision, rationale, signatures, and outcome linked into the chain.
- Gate 7AuditPeriodic sampling, quarterly assurance reviews, and metric analysis of gate performance.
What the evidence chain produces
A composed suite of outputs is engineered for institutional accountability, regulatory alignment, donor assurance, and incident reconstruction. Outputs are cryptographically signed, immutable, and exportable for audit, board review, or funder reporting.
- Decision records. Reviewer identity, timestamp, rationale, policy version, and outcome.
- Exception ledgers. Every override, denial, and reversal with linked justification and rollback state.
- Cross-border transfer logs. Jurisdictional context, classification, and approval chain for each movement of data.
- Cryptographic migration records. Algorithm changes, key rotations, and phased-migration checkpoints.
- Assurance metrics. Approval latency, exception frequency, rollback usage, and gate-effectiveness trend data.
- Evidence packs. Composed bundles for board, funder, regulator, or incident-response review.
Geography alone does not establish legal compliance.
- evt.access.decision · deny
- evt.data.classify · ambiguous
- evt.vendor.drift · widened
- evt.workflow.review · approved
- Board risk summary
- Donor assurance report
- Regulator-ready evidence index
- Exception register
