Policy & Governance
Is policy current, known, and actually enforced? Policy that nobody follows is a liability. IO connects each policy statement to the evidence that it holds in practice.
The signals read, and the work prescribed against them.
The summary of each is on the surface. Open one for the specific dimensions behind it.
SignalsWhat IO reads for this domain4 signal and evidence families, correlated deterministically rather than inferred.
- Policy library, versions and review dates
- Attestation and exception records
- Control ownership and change history
- Observed deviations from stated policy
PlaybooksWhat IO prescribes3 representative playbooks, each gated on prerequisites and maturity.
- Rewrite the policy the telemetry keeps hitting
- Clean up the policy exception register
- Re-approve the policies past their review date
SeatsWho lands here first3 seats read this domain before anyone else does.
- Governance, risk and compliance
- CISO
- COO
What has to move for this to have worked.
Policies past review date
Open exceptions older than their agreed window
Observed deviation rate for the targeted statement
Sessions that feed this domain.
We deliver these as part of IO Enablement Services.
Influence Ops
The InfluenceOS™ loop applied to your own programme: assess, prioritise, execute, measure, improve, with the measure agreed first.
Observed behaviour, reported culture and completed learning held as one position, and re-measured on the behaviour, not the completion record.
Detections that arrive from tooling rather than a colleague's message, and where the identity pressure is actually landing.
Which AI tools are really in use, what data reaches them, and whether the written guardrails are the ones in force.
See it before you talk to anyone.
Two quarters of recorded activity across sixteen seats. One click, no install.