AI & MODEL GOVERNANCE

Models reason. Customer authority decides.

SupraOS uses AI to retrieve, classify, reason, summarize, draft and support execution. Customer evidence, permissions, policy, approval and verification govern every consequential action.

Effective and last reviewed: 16 July 2026

How models are used

Classification and retrieval

Identify relevant records, evidence, owners, and unresolved gaps inside the approved source scope.

Reasoning and synthesis

Summarize evidence, compare conditions, prepare recovery options, and identify missing information.

Drafting and orchestration

Build work plans, internal briefs, evidence requests, proposed actions and approval packets.

Verification assistance

Compare intended and observed states, with deterministic checks protecting high-consequence actions.

Customer-controlled authority

A model cannot change the Charter, permission boundary, policy, or approval requirement.

Evidence-grounded outputs

Model output remains a proposal or inference until supported by evidence and the applicable confirmation rule.

Permission-bound execution

Models may recommend or prepare. Authority comes from the Charter, source scope, roles, permissions, policy decisions, and named approvals. A model response is not an approval event.

Evidence before action

Consequential actions require the evidence and control state defined for the workflow. Missing or contradictory evidence can hold the action rather than being silently resolved by the model.

External intelligence

Permitted sources

Customer-approved public, licensed, or customer-provided sources relevant to the workflow.

Required labels

External context carries its own source link and timestamp alongside customer-system evidence.

Operating rule

External intelligence can raise a question or support an analysis. It cannot authorize an action or expand source access.

Examples

Regulatory change, market context, customer public signals, vendor risk, public filings, or sector-specific data where approved.

Evidence required for consequential action

Consequential writes and customer commitments require customer evidence and authority.

Model and tool traceability

Execution metadata records the relevant model, tool, connector, action class, policy state, approval event, and verification result so the workflow can be reviewed later.

Customer data stays customer-specific.

SupraOS never uses customer data to train a model shared across customers.

Predict the consequence before the action.

Before an agent acts, VTWM predicts likely system changes, policy conflicts, side effects and delayed consequences. Afterward, SupraOS compares the forecast with the checked result and feeds that evidence into the next decision.

Providers and model changes

Deployment-specific providers

The specific AI or model providers enabled for a customer are disclosed in the applicable DPA, subprocessor schedule, order form, or deployment documentation before customer data is sent.

Changes remain governed

Material provider or model changes are handled through the applicable contractual, security-review, and deployment-change process.