Why Cabier
The honest answer is not that the existing tools are bad. It is that none of them was built to answer the question supervision actually asks: was the control working, on this date, across every domain it touches — and can you show me. That is the layer we occupy.
Three sets already exist. None of them holds the proof.
We describe the landscape by what each set is built to do, not by who sells it. Each set is competent inside its own boundary. The gap sits between them — nobody is accountable for whether the control was actually working, across domains, on the date supervision asks about.
Holding the register. Workflow, task routing, questionnaire cycles and reporting over a stable taxonomy the institution maintains itself.
The record states that a control exists and that someone attested to it. It does not independently establish whether the control was working on the date in question.
We do not replace the register. We read it, test what it asserts, and hold the evidence that makes the assertion defensible.
| The question | Platforms of record | Point tools | Advisory | Cabier |
|---|---|---|---|---|
| Where does the assurance come from? | Self-attestation captured in a workflow | Domain telemetry inside one boundary | Practitioner judgement at a point in time | Evidence bound to a control, tested on a defined cycle, with the test result retained |
| What happens between review cycles? | The record stays as last saved | Alerts fire without institutional consequence | Nothing, until the next engagement | Control state continues to move, and the resilience position moves with it |
| Can one failure be traced across domains? | Only where the taxonomy already links them | No — each tool ends at its own edge | By manual analysis, per engagement | Traversal over a typed dependency graph, with weight and confidence on every relationship |
| What does an examiner receive? | Exported reports and status fields | Tool screenshots and extracts | A report with a date on it | A scoped pack of the underlying evidence, with lineage back to the obligation |
| How is judgement retained? | In free-text fields | Not retained | In the consultant who left | Encoded as control logic and decision records the institution keeps |
Positions describe the design intent of each category as we encounter it in engagements. They are not a benchmark of any named provider.
What we hold to
Assurance is a control, not a document
Every claim on this platform resolves to a control, an evidence specification and a test result with a date. If it cannot be evidenced, it is not presented as assurance.
One dependency graph, not twelve registers
Obligations, controls, applications, data, models, third parties and accountable people sit on a single typed graph, so a failure can be traced to its consequence rather than argued about.
Provenance is explicit
An asserted mapping, an adapter reading and a model suggestion are never treated as the same evidence. Weight and confidence travel with every relationship.
Senior judgement, installed
The practitioner view that would normally leave with the engagement is encoded as control logic and decision records the institution keeps.
Governance sits above the rails
We do not operate settlement, custody or model infrastructure. We hold the oversight layer over it — which is why independence is intact when supervision asks.
Scope discipline
We decline work we cannot evidence: no policy digitisation, no authoring services, no assurance claims over systems we cannot observe.
Read the method, not the claim
Everything above is documented. The scoring method, the trust gates that govern agentic work, and the control library are published so the position can be examined rather than accepted.
See it against your own estate
A walkthrough runs against a live control set, not a slide deck. Bring the finding or the obligation you are currently arguing about internally.