Decision Passport logoDecision PassportVerifiable AI governance

Use cases

Decision provenance for security and AI governance teams

Decision Passport is designed for workflows where a recommendation is useful only if stakeholders can later prove what was reviewed, approved, revoked, or superseded.

Release risk, dependency drift, test posture, rollback readiness

Security release gates

Create a durable passport for AI-assisted ship/no-ship recommendations so reviewers can prove which release decision was approved.

Severity, exploit evidence, internet exposure, patch availability

Vulnerability triage

Turn urgent triage into a verifiable decision record without publishing private exploit details or customer impact notes.

Model version, policy version, reviewer action, decision status

AI governance

Give risk, legal, and audit teams a reliable way to inspect whether an AI-assisted decision changed after review.

Tool risk, policy match, sensitive action, human approval requirement

Agentic policy control

Use decision passports for agentic workflows that need policy gates before sensitive tool use or external action.

Common operating pattern

The agent prepares a structured recommendation, the backend hashes the canonical object, and a reviewer makes the accountable lifecycle decision. The public verifier checks integrity without receiving private evidence.

Not a data dump

The product is intentionally narrow. It does not publish prompts, raw logs, customer identifiers, source code, or private vulnerability details. It publishes proof that a governed decision object still matches the approved passport.