Governed knowledge + action for enterprise AI
Right knowledge. Right controls. Evidence to prove it.
Charter gives AI the authoritative enterprise knowledge, standards, policies, and business rules that apply; governs the AI actions it can take; and preserves audit-ready evidence of what governed the work.
Test drive free. No card required.
What you get
AI that works the way your enterprise actually works.
Right knowledge
One authoritative source
Resolve the approved knowledge, standards, policies, and business rules that apply to the work—not whichever document happens to rank highest.
Not just relevant. Authoritative.
Right controls
Governed AI actions
Apply identity, context, purpose, business rules, approvals, and constraints before governed AI actions proceed.
Allow. Block. Constrain. Require approval.
Evidence to prove it
Audit-ready evidence
Preserve which source and version applied, the governance decision made, and the governed action observed through Charter.
Answer: “What governed this?”
How Charter works in real time
The right rule is applied before the AI acts.
Change the rule once. Govern AI everywhere that rule applies.
- 01
RESOLVE
Determine what applies
For this user, agent, request, and context, Charter resolves the authoritative knowledge and business rules that apply.
- 02
DECIDE
Make the governance decision
Evaluate the applicable rules and context to allow, block, constrain, or require approval.
- 03
GOVERN
Govern the AI action
Apply the decision to governed AI access and actions through the controlled execution path.
- 04
EVIDENCE
Create the record
Record the applicable source and version, governance decision, and governed action observed.
Two ways enterprises use Charter
Move faster in IT. Put policy into practice across the business.
Put product standards, design systems, engineering rules, business logic, application context, accessibility requirements, and QA criteria into the governed system that creates the work.
Policies should not stop at a document repository. Charter makes the approved rule available where people and AI make decisions and take governed actions.
IT + product delivery
Shift standards and rules upstream.
- Generate governed product and design briefs
- Build prototypes from approved components and standards
- Generate precise implementation plans from SIGN-enabled repositories
- Execute to reviewed plans and automate QA/UAT against the same rules
Enterprise policy implementation
Make policy operational.
- Workforce: hiring, promotion, mobility, compensation and employee policy
- Cybersecurity: access, incident response and approval boundaries
- Procurement: thresholds, vendor policy and approvals
- Marketing & sales: claims, disclosures, pricing and contract rules
Why Charter
AI doesn't need more content. It needs guardrails grounded in what actually governs your business.
Search, prompts, guardrails, Governance, Risk, and Compliance (GRC), observability, and policy engines each solve a piece of the problem. Charter connects authoritative enterprise knowledge and policy to the AI work itself—so the rule the organization approved can become the rule the AI actually works under.
Authority over relevance
Retrieval can find five relevant documents. Charter resolves the approved source and version that has authority for the work.
Policy over prompt
Prompts instruct. Charter keeps governing standards and rules outside the prompt as governed enterprise assets.
Portable by design
SIGN is open and agent-readable so governed enterprise knowledge is kept under enterprise control—not trapped inside one model, AI tool, or vendor ecosystem.
Case Study · We run on it
150+ / week
engineering points from one engineer, vs. 12–15 per two-week sprint historically
~1 month
major releases, down from ~6 months
~10×
faster design cycle with the conventional Figma handoff removed
~15 min
demonstrated automated standards/design QA review against Canon
We rebuilt how we take software from idea to production.
We put standards and rules in Canon—not buried in AI instructions or code—and automated the lifecycle around that governed source. The gains are not one isolated AI task; they compound across product, design, engineering, QA/UAT, and release.
Start with one use case
Put Charter behind the AI work where the rules matter.
Test drive Charter with one body of knowledge, one set of rules, and one AI use case—or talk through what you want to govern.
How Charter works
From enterprise authority to governed AI action.
Charter turns approved enterprise knowledge and business rules into governed context and controls that AI tools and agents can use in real time.
What Charter gives you
Right knowledge. Right controls. Evidence to prove it.
Right knowledge
Resolve the authoritative enterprise knowledge, standards, policies, and business rules that apply to this user, agent, request, and context—not simply the most relevant content.
Right controls
Use identity, context, purpose, risk, approvals, and applicable rules to govern what AI can access and what governed actions it can take.
Evidence to prove it
Preserve the exact source, policy or rule, version, governance decision, and governed action observed through Charter so the enterprise can reconstruct what governed the work later.
The system
Four parts, one governed path.
Canon
Authority
The governed source for enterprise knowledge, policies, standards, business rules, requirements, decisions, and approved operating context.
SIGN
Representation
Open, agent-readable representation of facts, relationships, rules, constraints, dependencies, and provenance.
Trellis
Control
Governance/control plane for policy decisions, permissions, approvals, escalation, enforcement, and evidence.
MCP
Interface
Governed interface for approved AI tools and agents to access knowledge, systems, tools, and actions.
In real time
Resolve. Decide. Govern. Evidence.
- 01
Determine what applies
Resolve authoritative content by identity, entitlement, context, purpose, applicability, and version.
- 02
Make the decision
Evaluate the applicable business rules and governance policy.
- 03
Govern the action
Apply the control to the governed access or action.
- 04
Preserve evidence
Maintain the source, version, decision, and observed governed action.
See the difference
A $75K vendor approval should not depend on what the AI happened to retrieve.
An AI-assisted purchasing workflow needs more than the procurement policy text. Charter resolves the current procurement policy, delegation-of-authority rule, the requestor's identity and authority, and the transaction context. If the applicable rule requires executive approval above $50K, Trellis can require that approval before the governed action proceeds. Charter preserves the policy and version that applied, the governance decision, and the action observed through the governed path.
The point: the enterprise can later answer, “What governed this?” Charter preserves governance evidence; it does not itself make a legal-compliance determination.
The operating principle
Standards & rules belong in Canon—not buried in AI instructions or code.
Capabilities can call the governed rule when they need it. When the rule changes, the rule changes once. Product workflows, design automation, engineering agents, QA, business processes, and skills can resolve the current standard instead of carrying separate copies.
Skills are a result of this architecture, not the source of truth. A skill knows how to perform a capability; Canon holds the standards and business rules that govern how your enterprise expects that capability to be performed.
Use cases
Start with the AI work you already need to control.
Charter is most valuable where the answer, decision, or action must follow an approved standard, policy, business rule, or operating practice—and where you need to know what governed it later.
IT + product delivery
Build faster without making standards optional.
Move the standards into the system creating the work. Automate the predictable parts. Keep human review where judgment belongs.
I need to…
Take a feature from idea to production faster
Generate product/design briefs to governed standards, build the prototype from approved components, generate a code-specific implementation plan, execute to the reviewed plan, then automate QA/UAT against the same criteria.
Uses: product standards + design system + SIGN-enabled repos + engineering rules + acceptance/QA standards
Try Product Delivery →I need to…
Build a design that is already on-standard
Generate working designs and prototypes from governed tokens, components, usability rules, brand standards, and accessibility requirements—without a separate Figma-to-development recreation step.
Also audit an existing design or live site against the same design and accessibility floor.
Try Design →I need to…
Stop AI from guessing how our codebase works
SIGN-enable repositories so AI can reason across actual architecture, interfaces, dependencies, standards, and code context before generating an implementation plan.
Then audit code for standards and business-rule drift.
Try Engineering →I need to…
Find business rules hiding in code
Scan application logic and reconcile what the software actually enforces against the rules the enterprise has formally governed.
Find code-only rules, undocumented constraints, drift, and likely defects before implementation becomes permanent policy.
Try a Rule Audit →I need to…
Make accessibility part of design—not a late audit
Put governed accessibility requirements into the component and design standards that generate the work, then run automated checks against the same requirements.
Reduces downstream remediation while preserving human review for conformance and judgment.
Try Accessibility Governance →I need to…
Keep every AI capability current when rules change
Keep business rules in Canon and let agents, automations, and skills resolve them at runtime instead of embedding rule copies inside prompts and instructions.
Change the governed rule once; consuming capabilities do not need to be rewritten just because policy changed.
Try Rule Governance →Business policy implementation
Turn policy from a document into something AI can actually work under.
These are the use cases where leaders should immediately recognize: “I need to do that.”
Workforce / HR
Make hiring, promotion, and mobility AI use the rules that actually apply
Give AI the approved role criteria, skills definitions, hiring/promotion policies, decision rights, and applicable workforce requirements encoded in Canon—and preserve what governed the recommendation or workflow.
Example: before an internal-mobility recommendation is presented, resolve the current eligibility, role, skills, and policy criteria for that employee/context.
Try Workforce Governance →Cybersecurity
Apply security policy before an agent takes a governed action
Resolve incident-response rules, access policy, tool permissions, approval boundaries, and escalation requirements before Trellis-governed actions proceed.
Also audit access-control practice against the policy in force.
Try Cybersecurity →Procurement
Make approval thresholds and vendor rules follow the transaction
Answer who can approve what, apply vendor policy and evaluation criteria, and route governed actions for approval when thresholds or conditions require it.
No more guessing which policy or delegation rule applies.
Try Procurement →Marketing + Communications
Catch claim, disclosure, and brand violations before content publishes
Ground AI in current claim rules, disclosures, voice, and brand standards—and audit drafts against those standards before release.
The governing rules stay external to the prompt and can change independently of the drafting capability.
Try Marketing Governance →Sales
Give every rep the current approved pricing and policy answer
Ground AI-assisted answers in approved pricing, product, contract, and policy sources; later reconstruct which source and version governed a challenged answer.
Reduce five informal versions of the same answer circulating across the field.
Try Sales Governance →Data + Analytics
Stop the same metric meaning five different things
Govern metric definitions and reporting rules, answer questions from the authoritative definition, and audit dashboards/models for definition drift.
Useful when a wrong definition can become a wrong business decision.
Try Data Governance →Quality + Operations
Audit work against the standard before a customer finds the gap
Use governed quality standards, inspection criteria, procedures, and operating rules to evaluate processes or outputs and produce a traceable violations report.
Try Quality Governance →Customer Success
Make every support answer follow the current policy
Ground responses in playbooks, refund policy, escalation rules, and approved templates so customers receive consistent policy-based answers.
Try Customer Success →Executive + Policy
Know who decides, who approves, and what happens next
Resolve decision rights, approval processes, escalation paths, and operating policy without relying on tribal knowledge or stale copies.
Try Policy Answers →Don't see yours?
Bring the use case where a wrong rule creates risk or rework.
We'll start with the work you want AI to do and the rules that should govern it.
Case Study · Career Highways runs on Charter
We rebuilt the process from idea to production. The results followed.
We did not layer AI onto the old software-delivery process. We moved product standards, design standards, business rules, application context, accessibility requirements, engineering standards, and QA criteria upstream into Canon—then automated the lifecycle around that governed foundation.
The results
This is what changed.
The result is an order-of-magnitude change in how work moves—not a collection of isolated AI productivity wins.
The mechanism is not “AI codes faster.” The mechanism is Canon + Shift Left: put the standards and rules into what plans, creates, checks, and governs the work.
20–25×
engineering throughput: one engineer moved from ~12–15 points per two-week sprint to 150+ points per week
~6×
faster major releases: ~6 months to ~1 month, idea through production
~4×
faster minor releases: ~2 months to roughly two weeks
~10×
faster design cycle, while eliminating the conventional Figma handoff
~61%
fewer tokens in a demonstrated prose-to-SIGN compilation: ~980 tokens to ~380
~15 min
demonstrated automated design/QA review against governed standards
Why we built it
Our own product operates in a domain where policy and law cannot be an afterthought.
Career Highways builds Skills Intelligence software used for workforce decisions—hiring, internal mobility, promotion, development, role requirements, and related talent processes. Those decisions sit inside enterprise policy and legal/regulatory requirements. As we put more AI into our own product and operating model, we needed a way to ensure AI was not simply finding relevant information; it was working from the approved standards, policies, business rules, and decision criteria that actually governed the work.
Example: when AI supports an internal-mobility or promotion workflow, the relevant role and skills definitions are not enough. The workflow may also need current eligibility rules, promotion/mobility policy, decision rights, and other applicable workforce requirements. Charter lets those governing sources be resolved together and preserves the evidence of what exact policy, rule, source, and version was in force when the human or agent executed the work. Charter preserves the governance evidence; it does not itself make a legal-compliance determination.
What we rebuilt
From idea to production, the process now runs on governed rules and automation.
This is the operating-model change behind the results. Product does not hand an idea to design to reinterpret. Design does not hand pictures to development to rediscover. Front-end and back-end development do not independently reconstruct requirements. QA/UAT does not wait until the end to discover the standards. We moved standards, policy, accessibility, architecture, business rules, and acceptance criteria upstream into Canon so every stage can create and check its work against the same governed source—with human review at the decision points that matter.
Ideate
Start with the business problem, desired outcome, and constraints.
Product brief
Automation builds the brief to our governed product standard—including required sections, experience expectations, acceptance approach, business rules, and implementation-specific context.
Design brief
The approved product brief becomes governed design input. Automation adds the design-specific standards and constraints instead of asking design to reinterpret the requirement from scratch.
Design + prototype
AI builds against governed components, tokens, patterns, usability, brand, and accessibility requirements. The output includes a working front-end foundation that development can use—not just pictures to recreate.
Implementation plan
Development receives the approved brief, design, and front-end foundation. AI resolves SIGN-enabled repositories plus architecture, interfaces, dependencies, engineering standards, and business rules to generate the implementation plan.
Front-end + back-end build
Development completes the production front end, back-end services, data, APIs, integrations, and application logic against the approved plan and governed rules.
Code review + integration
Automated and human review checks implementation against engineering standards, architecture, business rules, design requirements, and integration expectations before it moves to QA/UAT.
QA / UAT
Automation checks the integrated product against acceptance criteria, design standards, business rules, accessibility requirements, and QA/UAT standards.
Release
Release proceeds after governed checks and required human approvals are complete, with the governing evidence preserved.
What changed:
The important change is continuity. Product and design briefs are automated against standards in Canon. Design produces a governed prototype and front-end foundation. Development generates a precise, human-audited implementation plan against the real application estate, then completes front-end and back-end implementation to that plan. Code review, integration, QA, and UAT use the same governed standards and rules. Automation carries the governing context forward; people review the decisions and outputs instead of manually rebuilding context at every handoff.
Design
We didn't just make design 10× faster. We removed the handoffs that made it slow.
Our components, tokens, design patterns, brand standards, usability requirements, and accessibility requirements live in Canon. The AI can build from the same governed component system developers use, producing a working prototype/frontend package that goes to development for the implementation plan and full build.
Accessibility shifts left too. Governed WCAG/accessibility requirements are part of the design/component standards before the screen is created. We can then run an automated review against those standards in minutes rather than relying only on a manual page-by-page audit and remediation cycle. Human review still determines final conformance and design quality.
“Design, compliance, and policy today live in separate systems, checked at separate stages, by separate people — and that sequence is exactly what slows a regulated redesign down. Collapsing it into one governed source is the kind of change that doesn't just speed up design; it removes the handoffs that make regulated design slow in the first place.”Design executive · regulated enterprise
Engineering
Precision before execution.
We put standards and business rules in Canon and SIGN-enable the repositories themselves. Before AI writes implementation code, it can resolve the actual application context—architecture, interfaces, dependencies, constraints, and governed rules—and generate an implementation plan specific to that codebase.
01
Generate the plan
Requirement + approved design/frontend + SIGN-enabled application context + engineering standards + business rules.
02
Engineer audits it
A human verifies what will change, where, why, dependencies, tests, and business-rule implications before execution.
03
Execute to plan
AI implements the approved plan; code review and QA/UAT check the work against the governed foundation.
Throughput result: one engineer who historically delivered ~12–15 points per two-week sprint is now delivering 150+ points per week.
One rule, many automations
The business rule doesn't belong inside the skill.
Skills, agents, and automations are consumers of governed standards—not the permanent home of them. Our product, planning, design, development, QA, document, and other AI capabilities call Canon for the rules they need. When a rule changes, we change the governed source; the capability does not have to be rewritten just because the business rule changed.
“This runs the company. Every process, every standard, every policy goes into Canon... the capability looks at that and generates the work in the standard we want.”
Liz Eversoll, CEO · Career HighwaysWe audited ourselves
Then we checked where code had silently become the source of business truth.
We scanned approximately 30 repositories and extracted 412 application business rules and constraints for reconciliation against Canon. This was a targeted audit of rules embodied in our application estate—not the total number of business rules governed in Canon.
31%
Fully governed
The application rule was already represented in Canon.
24%
Partially governed
Canon defined the concept, but implementation contained additional unstated constraints.
45%
Code-only at audit time
The application contained a rule or constraint without a corresponding governed source.
Why this mattered: it showed exactly where implementation had accumulated enterprise knowledge that was not yet governed—and surfaced two probable software defects during reconciliation.
The case study
We didn't automate the old operating model. We changed it.
The speed is the compounding result of governed standards and rules upstream, automation across the lifecycle, precise plans before execution, and human review where judgment matters.
Why Charter
AI doesn't need more content. It needs authority and guardrails.
Most enterprise AI stacks can find information, add instructions, call tools, inspect outputs, and record traces. Charter solves the upstream governance problem: which enterprise knowledge and rules have authority over this work—and how do those rules govern the AI action?
The distinction
Existing tools solve real problems. They don't answer the same question.
Retrieval finds. Identity grants access. Prompts instruct. Orchestrators coordinate. Guardrails inspect. Observability records. GRC documents. Policy engines decide. Charter establishes what governs.
RAG finds what's relevant.
Charter establishes what's authoritative and applicable.
Retrieval is useful discovery, but semantic ranking does not establish which source or version governs.
Enterprise search grants discovery.
Access is not authority.
Permission to see a document does not mean that document governs a particular decision or action.
Prompts can carry business logic. Charter governs it.
Business rules should not be buried in prompts.
Charter moves that logic into a governed enterprise source with ownership, approval, applicability, precedence, and versioning—then AI uses the current rule when it works.
Guardrails inspect or block.
Charter supplies the governing context and policy behind the control.
Trellis can apply registered policy before governed actions proceed.
Observability records what happened.
Occurrence is not authority.
Charter preserves the governed resolution behind the trace: source, version, entitlement, corpus state, and decision context.
GRC documents policy and compliance work.
Charter connects approved policy to execution.
A policy registry can show a policy existed; Charter is designed to show which governed source was used in the AI work.
Policy engines make precise decisions.
Charter governs the broader knowledge around them.
Policy-as-code is excellent for structured authorization; Charter also governs the human-authored standards, requirements, decisions, and operating knowledge agents need.
Agent frameworks orchestrate work.
Orchestration answers what happens next.
Charter establishes what has authority to govern the AI-bearing step underneath the workflow.
Open + portable by design
Your enterprise knowledge should not be locked inside one AI ecosystem.
SIGN is the open specification Charter uses to represent facts, relationships, standards, business rules, constraints, dependencies, and provenance in a form agents can interpret consistently.
SIGN
Open, agent-readable knowledge.
- Tool-independent:
- serve governed knowledge to Claude, ChatGPT, Copilot, coding agents, enterprise agents, and custom applications.
- Model-independent:
- the authoritative knowledge does not have to move when the preferred model changes.
- Platform-independent:
- enterprise rules do not have to become proprietary configuration trapped in one vendor's knowledge/governance stack.
- Human source remains readable:
- people author and approve the source; Charter compiles the governed representation.
- Portable enterprise asset:
- open representation plus export/interoperable delivery are the mechanism for keeping governed knowledge under enterprise control.
Why this becomes more valuable with scale
One markdown file can work for one team. Enterprises have many teams, tools, agents, repositories, and accountabilities.
The governance problem appears when instructions fork across repositories, models, vendors, business units, and environments—and somebody later has to reconstruct which copy applied. Charter keeps the governing source explicit and reusable across those environments.
Change once
Update the authoritative governed source instead of chasing copies across AI instructions and workflows.
Apply consistently
Resolve the applicable rule by context, identity, purpose, and version wherever Charter governs the work.
Reconstruct later
Preserve what governed the work rather than relying only on a trace of what happened.
See the difference on one real use case.
Pick the AI work where a wrong version, wrong rule, or ungoverned action would matter.
Talk to us
Have an AI use case where the rules matter?
Bring the use case. We'll talk through what needs to govern it and whether Charter is a fit.
Good starting point
One decision
An AI-assisted decision where policy, standards, approvals, or business rules determine what is acceptable.
Good starting point
One process
A workflow with repeated manual checking, handoffs, or different teams interpreting the same standards.
Good starting point
One agent
An agent that needs authoritative enterprise knowledge plus clear boundaries around access, tools, approvals, or actions.
Test drive Charter
Start with one use case. See what governs it.
Choose the work you want AI to do, connect an AI tool, and experience how Charter resolves authoritative knowledge and rules and preserves the governance record.
Test drive free. No card required.
A simple first test
Use something your team already has to get right.
1. Pick the use case
Choose an AI answer, workflow, design, decision, audit, or governed action where standards and rules matter.
2. Connect the governing sources
Add the relevant policy, standards, business rules, frameworks, or enterprise knowledge and connect the AI tool you already use.
3. See Charter resolve it
Ask the question or run the use case and see the authoritative source, applicable rules, and governance evidence behind the work.