An independent assurance overlay above AI used in public administration — eligibility, casework triage, enforcement prioritisation, correspondence and citizen-facing service. We do not make administrative decisions and we do not set policy. We evidence that the system was authorised for the function, that the data stayed inside its sovereign boundary, that a named official owned the determination, and that the file can withstand review, appeal or audit.
Cabier does not exercise statutory discretion, does not act as the decision-maker of record and does not replace the department's own legal, privacy or audit function.
Resolved into testable control statements. Applicability is confirmed per engagement — jurisdiction, product and deployment scope all change what binds.
Administrative-law duties
A determination affecting a citizen must have stated reasons, an identifiable decision-maker and a record capable of supporting review or appeal — whether or not a model contributed to it.
Procurement and contract conditions
Assurance obligations flowed down to the vendor and evidenced in operation, not accepted once at award and left unverified.
Sovereign residency and classification
Processing, retention and inference confined to approved regions and handling levels, with the boundary tested rather than asserted in a schedule.
Privacy and information rights
Lawful basis, minimisation and access/correction rights applied to prompts, retrieved records and generated output — not only to the source system of record.
Equity and accessibility duties
Subgroup performance and accessibility of AI-assisted service tested and recorded where the system affects access to a benefit or a service.
Transparency and public reporting
A defensible public position on where AI is used, at what stage of the decision, and under whose accountability.
Each module is a vertical projection of an asset already running on the platform. No parallel store, no second evidence chain.
Administrative Decision Vault
Unified Evidence Vault
Prompt, retrieved case references, model version, output, reviewing official and final determination captured independently of the vendor console, with a file identifier that survives appeal timelines.
Sovereign Boundary Control
Sovereign AI Governance OS — residency and PII gating
Tested prevention of citizen data, classified material or case content reaching an unapproved model, region or retention path — with the refusal recorded as evidence.
Authorised Function Registry
AI Model Inventory
Which system is approved for which administrative function, at which version, under whose delegated authority, and when that authorisation lapses.
Official Accountability Log
Unified Audit Trail
An ordered record of who invoked the system, what it returned, which official accepted, amended or rejected it, and what entered the citizen's file.
Vendor Assurance Flow-Down
TPRM Workbench
Control testing over contracted AI suppliers where the department carries the statutory obligation but not the code.
A scored position across authorisation, sovereign boundary, logging, official accountability, subgroup performance, citizen transparency, monitoring and reconstruction — refreshed continuously.
A separate measure of whether citizen or classified data can leave its approved boundary at all, tested against live paths rather than contract language.
Where determinations are accumulating without stated reasons, a named official or a reconstructable record — surfaced by programme before an ombudsman or audit finding.
A scoped attestation for the accounting officer, auditor general or oversight committee, naming systems in scope, period and stated limitations.
Eight questions across the dimensions an audit, ombudsman review or judicial challenge would actually test. Answers stay in your browser — nothing is submitted, stored or transmitted.
01 · Authorisation
Is every AI system touching a citizen determination approved for a defined function, at a defined version, under named delegated authority?
02 · Sovereign boundary
Is there a tested control preventing citizen or classified data reaching an unapproved model, region or retention path?
03 · Stated reasons
Does every AI-assisted determination carry reasons that can be given to the citizen and traced to the version that produced them?
04 · Official accountability
Is a named official recorded as accepting, amending or rejecting each AI-assisted output before it affects the citizen?
05 · Equity testing
Is subgroup performance tested on a defined cadence where the system affects access to a benefit or service?
06 · Citizen transparency
Is there an approved public position on where AI is used and at what stage of the decision?
07 · Vendor flow-down
Do you hold operational control evidence from contracted AI suppliers, beyond their award-stage assurances?
08 · Reconstruction
Could you reconstruct, on request, how a specific determination was produced, within statutory appeal timelines?
Answer the questions above to see an indicative position.
Days 1–15
Scope and legal mapping
Programmes and systems in scope fixed; administrative-law, privacy and residency obligations resolved into testable control statements.
Days 16–45
Authorisation and boundary control
Function registry reconciled; sovereign residency and data-boundary controls tested against live casework paths.
Days 46–75
Reasons, equity and vendor evidence
Stated-reason traceability tested end to end; subgroup performance run on live caseload; supplier flow-down gaps named.
Days 76–90
Position and attestation
Maturity and sovereign containment positions issued, gap remediation sequenced, attestation scope agreed with the accounting officer.
Scope, residency and retention are set per engagement. Commercial terms are quoted against scope.
Start a scoping conversation