Governance and audit
Answer the examiner without opening a spreadsheet.
Control holds the model registry with validation status and review dates, the agent registry with owners and run volumes, the entitlements and segregation-of-duties model, and an immutable audit log of every human and agent action — actor, entity, workspace and timestamp.

How it works
Governance kept as a live record, not an annual exercise.
Model risk teams usually reconstruct their inventory from email and spreadsheets. Control keeps it as the operating record: the registries are what the platform enforces against, so the inventory and the reality cannot diverge.
- 01
Register the models
Every model approved for regulated use is registered with its validation status, owner and review date. A model that is not approved cannot be called.
- 02
Register the agents
Every agent is registered with a named owner, its purpose and its run volume, so an unowned agent running in production is visible rather than forgotten.
- 03
Enforce and record
Entitlements and segregation of duties are enforced at run time, and every human and agent action lands in the same immutable log.
What it produces
The evidence a second line asks for.
What Control produces is an examinable record: what is approved, who owns it, what it did, and who authorised each irreversible step.
Model registry
Models approved for regulated use, with validation status, owner and review date. Unapproved models cannot be called by any agent.
Agent registry
Agents with named owners, stated purpose and run volumes, so governance covers what is actually running.
Entitlements
Permissions inherited from your existing systems and applied at query time. A document a person cannot open cannot reach their answer.
Segregation of duties
Initiator, reviewer and authoriser kept distinct. Agents hold their own least-privilege identity and never inherit a person's approval rights.
Immutable audit log
Every human and agent action recorded with actor, entity, workspace and timestamp, in one log rather than two.
Exportable for examination
The record is retained and exportable, so responding to an examination is a query rather than a reconstruction project.
Where it stops
Control does not decide on your behalf.
Validation status, review dates, entitlements and ownership are set by the people accountable for them. Control enforces those decisions, records them and makes them auditable — it does not approve a model, grant itself a permission, or amend the log.
The log is append-only, and it holds human and agent actions in the same place. Neither can be edited after the fact, including by us.
Works with the rest of the platform
One record, one permission model, one audit trail.
Compliance
Alert triage, adverse media and a case narrative drafted for the MLRO — never filed without one.
Exceptions and service levelsOperations
Exception queues with live SLAs, and release packs that stop at the authoriser rather than past them.
Build your own agentsStudio
Compose agents against your policy sets and knowledge, evaluate them on labelled cases, and gate publish on the result.