Skip to main content

Purpose

Governance is not a feature of Smaya. It is the reason Smaya exists as a platform rather than a set of tools. Decisions about people carry legal weight. An organization deploying AI against them has to be able to answer three questions at any point, years later: what was decided, on what basis, and who was accountable. Smaya is built to answer all three by default.

The three rules that never move

They hold in every application, for every AI Employee, in every configuration.

Authority is bounded

An AI Employee’s effective authority is the intersection of its own declared scope and the permissions of the person who invoked it. Never the sum. It cannot reach what you cannot reach.

People decide

Outcomes that materially affect a person are made by a named human. The AI prepares evidence and a recommendation; it does not conclude. Nothing adverse is ever decided autonomously.

Interpretation is not calculation

The AI may interpret evidence. It never computes the score or applies the threshold — that arithmetic is deterministic, outside the model, and reproducible. This is what makes a result defensible.

The two artifacts

What an organization can actually put in front of a regulator, an auditor or a court.

The Decision Record

One permanent artifact per consequential decision. Available today: every score override carries a stated reason, every Decision change asks for a reason, each score records the model and prompt that produced it, and a job’s criteria lock while candidates are in flight. Upcoming: the Decision Room, which brings all of it into one permanent record per decision. Reproducible: the same inputs produce the same result, provably. That is a stronger claim than an audit log, and it is the one that matters when a decision is challenged.

The Fairness Register

Upcoming. Continuous, cohort-level fairness measurement — not a report someone runs once a year. A change that moves fairness adversely will be blocked before it reaches production. Catching it at release rather than in an audit is the difference between a control and a report.

Human oversight in practice

1

The AI Employee prepares

It gathers evidence, applies the criteria you configured, and produces a structured recommendation with its reasoning visible.
2

It asks before consequential writes

Creating a role, publishing a job and contacting a candidate wait on an approval card. Upcoming: in a role run, the evidence reaches you as a report in the Agent Inbox.
3

A named person decides

They can accept, change or reject. What they changed, and why, becomes part of the record.
4

Anything outside the charter escalates

Upcoming. Work beyond the role’s mandate routes automatically to its named owner rather than being attempted.

Oversight in an agent swarm

An agent swarm, which is Upcoming, will work between reports without asking. The protections marked Available already hold for screening and interviewing today, and will hold around every run. None of them asks the recruiter to approve routine work.

Independent review of every output

Upcoming. Every agent’s output will be independently checked by a Quality & Fairness Agent before it becomes part of the record. That reviewer is not customer-configurable — it grades the other agents, and an organization able to soften it could pass a flawed outcome through a clean scorecard. It remains fully visible and readable to you; only its settings are fixed. Today, automated checks run on every scored output and their results show in Scoring Logs, alongside manual review; see AI Observability.

Transparency to the person being assessed

Notice

People are told when AI is part of an evaluation, before it happens, and that notice is recorded as its own act.

Human review right

A person may request that a human reviews an outcome. The platform is built on the assumption that they will.

Regulatory posture

Employment decisions sit in the highest-risk category of emerging AI regulation, and bias-audit obligations already exist in several jurisdictions. Smaya is designed against that reality: evidence, fairness measurement and human accountability are structural, not configurable add-ons. Details of certifications, frameworks and data residency are in Trust & Compliance. Compliance posture is stated there rather than claimed here.

FAQs

No. Configuration can narrow authority; it can never widen it past the platform ceiling. The three rules above are not settings.
Override it. That is the expected path, and the override — with your reason — becomes part of the record. A high override rate is a signal that your criteria need recalibration, and the platform surfaces it.
Retention is set by you during configuration, against your own regulatory obligations. See Privacy & Residency.
Every retrieval is scoped to your organization. See Security for the isolation model.