Purpose
Governance is not a feature of Smaya. It is the reason Smaya exists as a platform rather than a set of tools. Decisions about people carry legal weight. An organization deploying AI against them has to be able to answer three questions at any point, years later: what was decided, on what basis, and who was accountable. Smaya is built to answer all three by default.The three rules that never move
They hold in every application, for every AI Employee, in every configuration.Authority is bounded
An AI Employee’s effective authority is the intersection of its own declared scope and the permissions of the person who invoked it. Never the sum. It cannot reach what you cannot reach.
People decide
Outcomes that materially affect a person are made by a named human. The AI
prepares evidence and a recommendation; it does not conclude. Nothing adverse
is ever decided autonomously.
Interpretation is not calculation
The AI may interpret evidence. It never computes the score or applies the threshold — that arithmetic is deterministic, outside the model, and reproducible. This is what makes a result defensible.
The two artifacts
What an organization can actually put in front of a regulator, an auditor or a court.The Decision Record
One permanent artifact per consequential decision. Available today: every score override carries a stated reason, every Decision change asks for a reason, each score records the model and prompt that produced it, and a job’s criteria lock while candidates are in flight. Upcoming: the Decision Room, which brings all of it into one permanent record per decision.
Reproducible: the same inputs produce the same result, provably. That is a stronger claim than an audit log, and it is the one that matters when a decision is challenged.
The Fairness Register
Upcoming. Continuous, cohort-level fairness measurement — not a report someone runs once a year.
A change that moves fairness adversely will be blocked before it reaches production. Catching it at release rather than in an audit is the difference between a control and a report.
Human oversight in practice
1
The AI Employee prepares
It gathers evidence, applies the criteria you configured, and produces a structured recommendation with its reasoning visible.
2
It asks before consequential writes
Creating a role, publishing a job and contacting a candidate wait on an
approval card. Upcoming: in a role run, the evidence reaches you as a report
in the Agent Inbox.
3
A named person decides
They can accept, change or reject. What they changed, and why, becomes part of
the record.
4
Anything outside the charter escalates
Upcoming. Work beyond the role’s mandate routes automatically to its named owner rather than being attempted.
Oversight in an agent swarm
An agent swarm, which is Upcoming, will work between reports without asking. The protections marked Available already hold for screening and interviewing today, and will hold around every run. None of them asks the recruiter to approve routine work.Independent review of every output
Upcoming. Every agent’s output will be independently checked by a Quality & Fairness Agent before it becomes part of the record. That reviewer is not customer-configurable — it grades the other agents, and an organization able to soften it could pass a flawed outcome through a clean scorecard. It remains fully visible and readable to you; only its settings are fixed. Today, automated checks run on every scored output and their results show in Scoring Logs, alongside manual review; see AI Observability.Transparency to the person being assessed
Notice
People are told when AI is part of an evaluation, before it happens, and that notice is recorded as its own act.
Human review right
A person may request that a human reviews an outcome. The platform is built on the assumption that they will.
Regulatory posture
Employment decisions sit in the highest-risk category of emerging AI regulation, and bias-audit obligations already exist in several jurisdictions. Smaya is designed against that reality: evidence, fairness measurement and human accountability are structural, not configurable add-ons. Details of certifications, frameworks and data residency are in Trust & Compliance. Compliance posture is stated there rather than claimed here.FAQs
Can we configure our way around these controls?
Can we configure our way around these controls?
No. Configuration can narrow authority; it can never widen it past the platform ceiling. The three rules above are not settings.
What if we disagree with a recommendation?
What if we disagree with a recommendation?
Override it. That is the expected path, and the override — with your reason —
becomes part of the record. A high override rate is a signal that your
criteria need recalibration, and the platform surfaces it.
How long is the record kept?
How long is the record kept?
Retention is set by you during configuration, against your own regulatory
obligations. See Privacy & Residency.
Can you see our data?
Can you see our data?
Every retrieval is scoped to your organization. See Security for the isolation model.
Related
- AI Employees. Where the charter is defined.
- Responsible AI. The human-review standard.
- Auditability. What an auditor can retrieve.

