Oversight & compliance

Oversight isn't a setting. It's the architecture.

A system that observes how people work is high-risk under the EU AI Act. Most vendors answer that with a policy document. Nebbos answers with how it's built — and you can read the guarantees below.

EU AI Act · high-risk readyGDPRSOC 2ISO 27001

Certification status to be confirmed before publishing.

The guarantees

Four things that are true by construction.

A human on every consequential move. Changes to how work runs route through an approval gate — there is no path that lets the system act on the consequential things without sign-off.
Every decision is sourced. What was decided, by whom, on what evidence, and why — all recorded and queryable, all the time.
Bounded, reversible autonomy. Pearl only acts within limits it has demonstrably earned, and any action it takes can be undone.
Your data, your tenant. Isolation is enforced at the database for every row — not promised in a clause.

Defence in depth

The approval gate is enforced in five places.

Oversight that lives in one layer can be bypassed in another. Nebbos enforces the human checkpoint at every level of the stack, so a change to how work runs can't slip through.

Layer 1

Interface

Changes are submitted to an approval flow, not pushed straight through.

Layer 2

API

Workflow changes require a valid approval token, or they're refused.

Layer 3

Agent policy

The agent pauses on consequential tools and cannot proceed without a human resume.

Layer 4

Tool permissions

Tools check the approval context before any logic runs.

Layer 5

Database

Unauthorised writes to workflow tables are caught — with alert and rollback.

Break-glass

Emergency override

Requires two senior approvers, a priority alert, and an automatic post-incident review.

Layers of governance

Not everything earns the same scrutiny. Nothing skips it.

Governance that treats every action the same is either too slow to live with or too loose to trust. Nebbos runs four tiers: routine, reversible work moves on a light lane; anything that can change how the organisation runs takes the heavy one. The red lines — approval gates, prohibited actions, isolation — bind every tier without exception.

G0

Constitutional

The only tier that can change the system of record. Full review, full audit.

G1

Canon-constrained

Reasoning and drafting against approved context. Binding only once promoted through a G0 gate.

G2

Convention

Routine production work under standing rules. Human sign-off, light weight.

G3

Ephemeral

Read-only and exploratory. Produces findings, never changes anything on its own.

And before any consequential action runs, the Simulation Gate rehearses it against a private copy of your operation, checks the outcome, and throws the copy away — so the real thing only ever sees a move that's already been tested.

Data handling

It reads the shape of work — not the contents.

Nebbos stores structured signal — patterns, thresholds, relationships, timing — rather than the raw text of your messages and documents. The Operational Graph is a map of how work moves, not an archive of what everyone said.

What's stored vs. what isn't
KEEPSevents, patterns, thresholds, relationships, outcomes
SKIPSraw message bodies and document contents
SCOPESaccess by role; surfaces sensitive gaps to leads, not peers

Bring the security questionnaire. We built for it.