Riaan Kleynhans · Control and capabilities matrix
Where AI may act, where code decides, where a human signs.
One page, three columns, live proof. Every row links to where it runs; every number is read from the proof run, the code tables or the ledgers — nothing on this page is typed in.
Bounded agentic execution
Models and plugins accelerate work — retrieval, language, drafting, adaptation — under the client's keys.
A model never decides a price, a risk tier, a state transition or a publication.
- Verifydsh plugin runtime
Cordis-style plugins run tasks under the client's own keys, inside a zero-data-retention sandbox, every call audited.
6 plugins registered
Client keys (BYOK)
- VerifyEditorial visuals
One Unsplash image per page by curated topic — an external API, never the client's data.
External API, no client data
Deterministic code and math
Every calculation, gate and state transition is tested TypeScript over captured facts.
0% model inference · unknown renders as unknown
- VerifyTen-dimension readiness
Weighted score, NIST function averages, bands and gating conditions a high average can never hide.
10 dimensions · 5 gates
- VerifyUse-case prioritisation
P = V·S·A·R ÷ C·K, the 2×2 value × readiness, nine pilot gates, tier 0 prohibited.
- VerifyGenAI risks and EU AI Act
Twelve NIST AI 600-1 risk records per use case; the eight-step EU classification kept separate from the internal tier.
12 risks · 12 high-risk evidence areas
- VerifyGap-to-intervention chain
Gap → consequence → capability → intervention (four levers, minimum elements) → owner → cost → dependency → binary closure.
16 lever elements
- VerifyControls as architecture
A control is a chain from policy to failure response with a passed test; a policy alone is a document.
6 control planes
- VerifyEvidence pack and expiry
Sections 00–11 counted as live / pending / exceptions; a passed review date turns a record pending on its own.
12 pack sections
- VerifyContract compiler and validator
v1/contract.json built from facts; the validator recomputes the signature chain and refuses an invalid contract before publication.
- VerifyVerified system maps
Typed IR compiled by a vendored renderer with layout validation in four languages; every artifact hashed.
12 map kinds
- VerifyRule-based intake
Transcripts become fact and evidence candidates by cue rules, each carrying its sentence; nothing lands without a human Accept.
- VerifyRole brain and RACI rule
Deterministic search over four disciplines; RACI with exactly one Accountable per gate, enforced on every change.
4 roles · 40 points
- VerifyGate and session state
Done, now and later are derived from facts and signatures on every render — nothing ticks itself.
6 gates · 7 sessions
Human accountability
What requires a named seat, recorded in append-only, hash-chained ledgers.
Never bypassed · no autonomous publication
- VerifySession signatures
Each of the seven sessions is signed by its present seats; hash-chained, authority re-checked by the ledger.
Signs: the session's present seats
- VerifyClosure verification
A gap closes only when its owner attests the binary criterion — a ledger record scoped to the gap.
Signs: the gap's owner
- VerifyHandover confirmation
Independent operation for the agreed days, confirmed by the benefits owner on a date.
Signs: the benefits owner
- VerifyContract publication
Facilitators publish; the validator gates it; signatures come from the ledger, never the browser.
Signs: the facilitator
- VerifyRACI changes
Who is accountable changes only through the ledger, facilitator authority, one A per gate.
Signs: the facilitator, audited
18 of 35 capabilities apply to this deployment. Unknown counts show as a dash, never as zero.