GIAS dimension

Control Surfaces · Governed Intelligence Architecture

Where authority can be exercised, control must be explicit.

A control surface is any point where an AI system can influence a decision, route information, invoke a tool, change memory, trigger execution, or alter what the organization believes to be true. Ananke makes those surfaces visible, governable, and auditable.

Control thesis

Trust boundaries define where authority changes hands. Control surfaces define where authority can be exercised. In GIAS, any surface that can change state, route context, trigger action, update memory, or shape belief must be explicit, governed, and reconstructable.

Why control surfaces matter

AI does not become dangerous only when it is wrong.
It becomes dangerous when influence becomes invisible.

Input Surface

Where human intent enters the system and must be interpreted without inheriting unlimited authority.

Routing Surface

Where the system decides which model, provider, tool, memory store, or workflow receives the request.

Execution Surface

Where approved language becomes operational action through APIs, tools, databases, workflows, and external services.

Persistence Surface

Where the system decides what becomes memory, what becomes evidence, what is retained, and what must be forgotten.

Reference structure

Control surfaces are the places where governed intelligence becomes operational.

Input control surface

Where intent first enters the system.

Input is not merely text. It can carry commands, implied permissions, hidden context, injected instructions, file contents, or operational requests. The first control surface determines whether the system should treat the request as conversation, analysis, action, escalation, or threat.

Intent classification
Prompt safety
Context validation
Injection resistance

Governance control surface

Where possibility becomes permission.

The governance surface determines whether a request may proceed, be modified, escalated, deferred, denied, or routed elsewhere. This is where Rita's reference architecture becomes enforceable.

Policy evaluation
Risk scoring
Permission checks
Human escalation

Context surface

What context may influence the answer?

Memory retrieval, user profile, institutional policy, documents, previous decisions, and environmental signals must be assembled under governance.

Routing surface

Which capability receives the work?

Routing determines model, provider, tool, agent, memory store, or workflow based on risk, policy, cost, capability, and privacy requirements.

Inference surface

What does inference produce?

The model generates possibilities, but inference remains downstream from governance and upstream from review, execution, persistence, and observation.

Execution surface

Where AI touches the world.

Tool calls, API requests, database writes, notifications, external workflows, and system changes require explicit authorization.

Persistence and evidence surface

What becomes part of the record?

Persistence determines what becomes memory, what becomes evidence, what is retained, what is redacted, and what can later be reconstructed through forensic replay.

Control chain

Control is not one gate.
It is a chain of governed surfaces.

A governed intelligence architecture does not rely on a single moderation check. It evaluates authority repeatedly as identity, context, governance, inference, execution, persistence, and observation move through the system.

1. Input

Classify intent and detect unsafe instruction patterns.

2. Context

Assemble only the context permitted for this user, role, and request.

3. Governance

Evaluate policy, risk, permissions, and escalation requirements.

4. Routing

Select the approved model, provider, tool, or workflow path.

5. Execution

Allow action only within authorized scope.

6. Evidence

Preserve the evidence required to reconstruct what happened.

Operational controls

Where governance must be visible and actionable.

Admin Policy Controls

Institutional administrators need policy surfaces for roles, routing, retention, approval, and escalation.

User Consent Controls

Users need clear control over memory, data use, sharing, deletion, and personalization.

Developer Tool Controls

Engineering teams need controlled access to model routing, tool permissions, telemetry, logs, and test replay.

Compliance Review Controls

Regulated organizations need review surfaces for approvals, denials, incidents, exceptions, and audit trails.

Runtime Intervention Controls

High-risk actions require the ability to pause, block, escalate, rewrite, or require human review.

Forensic Replay Controls

Leaders must be able to reconstruct the governed path that produced a consequential outcome.

Rita + Palladium + Origin

Rita implements the control logic.
Palladium operationalizes the surfaces.
Origin gives individuals governed control.

R

Rita

Rita implements the control-surface model defined by GIAS, translating authority, policy, risk, routing, execution, persistence, and escalation into operational decision logic.

Understand Rita
Palladium

Palladium

Palladium operationalizes control surfaces for organizations through policy configuration, runtime enforcement, model routing, tool permissions, evidence capture, incident review, and forensic replay.

Explore Palladium
Origin

Origin

Origin applies governed control surfaces to the individual: memory consent, identity continuity, privacy preferences, context boundaries, and user-owned intelligence that persists above model providers.

Explore Origin

Next: Threat Model

Once control surfaces are visible,
the threat model becomes actionable.

Control surfaces show where AI can influence decisions, memory, routing, persistence, and action. The threat model defines what can go wrong at each surface — and how governed intelligence contains, records, and responds before harm scales.