Riaan Kleynhans
Open the engine

Riaan Kleynhans · Control and capabilities matrix

Where AI may act, where code decides, where a human signs.

One page, three columns, live proof. Every row links to where it runs; every number is read from the proof run, the code tables or the ledgers — nothing on this page is typed in.

Proof run
VERIFIED
2026-09-19 05:23
Tests passing
229/229
34 test files
Dictionary parity
4038 × 4
keys × locales
Ledgers active · records
·
sign in to read the tenant's ledgers
Chained records
sign in to read the tenant's ledgers
Published versions
reports, pitches, contracts

Bounded agentic execution

Models and plugins accelerate work — retrieval, language, drafting, adaptation — under the client's keys.

A model never decides a price, a risk tier, a state transition or a publication.

  • dsh plugin runtime

    Cordis-style plugins run tasks under the client's own keys, inside a zero-data-retention sandbox, every call audited.

    6 plugins registered

    Client keys (BYOK)

    Verify
  • Editorial visuals

    One Unsplash image per page by curated topic — an external API, never the client's data.

    External API, no client data

    Verify

Deterministic code and math

Every calculation, gate and state transition is tested TypeScript over captured facts.

0% model inference · unknown renders as unknown

  • Ten-dimension readiness

    Weighted score, NIST function averages, bands and gating conditions a high average can never hide.

    10 dimensions · 5 gates

    Verify
  • Use-case prioritisation

    P = V·S·A·R ÷ C·K, the 2×2 value × readiness, nine pilot gates, tier 0 prohibited.

    Verify
  • GenAI risks and EU AI Act

    Twelve NIST AI 600-1 risk records per use case; the eight-step EU classification kept separate from the internal tier.

    12 risks · 12 high-risk evidence areas

    Verify
  • Gap-to-intervention chain

    Gap → consequence → capability → intervention (four levers, minimum elements) → owner → cost → dependency → binary closure.

    16 lever elements

    Verify
  • Controls as architecture

    A control is a chain from policy to failure response with a passed test; a policy alone is a document.

    6 control planes

    Verify
  • Evidence pack and expiry

    Sections 00–11 counted as live / pending / exceptions; a passed review date turns a record pending on its own.

    12 pack sections

    Verify
  • Contract compiler and validator

    v1/contract.json built from facts; the validator recomputes the signature chain and refuses an invalid contract before publication.

    Verify
  • Verified system maps

    Typed IR compiled by a vendored renderer with layout validation in four languages; every artifact hashed.

    12 map kinds

    Verify
  • Rule-based intake

    Transcripts become fact and evidence candidates by cue rules, each carrying its sentence; nothing lands without a human Accept.

    Verify
  • Role brain and RACI rule

    Deterministic search over four disciplines; RACI with exactly one Accountable per gate, enforced on every change.

    4 roles · 40 points

    Verify
  • Gate and session state

    Done, now and later are derived from facts and signatures on every render — nothing ticks itself.

    6 gates · 7 sessions

    Verify

Human accountability

What requires a named seat, recorded in append-only, hash-chained ledgers.

Never bypassed · no autonomous publication

  • Session signatures

    Each of the seven sessions is signed by its present seats; hash-chained, authority re-checked by the ledger.

    Signs: the session's present seats

    Verify
  • Closure verification

    A gap closes only when its owner attests the binary criterion — a ledger record scoped to the gap.

    Signs: the gap's owner

    Verify
  • Handover confirmation

    Independent operation for the agreed days, confirmed by the benefits owner on a date.

    Signs: the benefits owner

    Verify
  • Contract publication

    Facilitators publish; the validator gates it; signatures come from the ledger, never the browser.

    Signs: the facilitator

    Verify
  • RACI changes

    Who is accountable changes only through the ledger, facilitator authority, one A per gate.

    Signs: the facilitator, audited

    Verify

18 of 35 capabilities apply to this deployment. Unknown counts show as a dash, never as zero.