LLM CostControl-plane: $0 · Desk LLM: your provider (BYOK/on-box)
Compliance Evidence Report
Generate a branded PDF with live posture grade, policy inventory, audit summary, and compliance control matrix. Ready to forward to a CISO.
Platform Architecture
AI Operations
Core
Business Operator (8089)
Engine / Admin (8090)
Security Operator (8091)
Checker (internal)
Hindsight Memory (8765)
Identity & Access
Internal
Keycloak SSO (8180)
PostgreSQL (5432)
Workspace Services
Internal
Nextcloud (Files/Cal)
OnlyOffice (Docs)
Synapse (Chat)
Element Web (UI)
Communication
Internal
Stalwart (Email)
Jitsi (Video)
LLM Layer
Internal
Ollama (Host LLM)
NemoClaw (Sandbox)
Edge / Proxy
External
Caddy (reverse proxy)
Cloudflare Tunnel
Audit & Memory Architecture
Active — Zero LLM Cost
Audit Trail
✓
immutable JSONL logs
Conversations
✓
SQLite per-operator
Full-Text Search
✓
FTS5 indexed
Checker Findings
✓
local assessment logs
Policy Engine
✓
runtime enforcement
Control-Plane LLM
$0
Desk LLM: your provider (BYOK/on-box)
—
Services Running
—
Policies Loaded
—
Policy Self-Grade
—
Audit Events
—
Uptime
Enforcement: deny-by-default
Loading policies...
Live Audit Event Stream
Time
Type
Source
Message
Loading...
Environment
Loading environment...
Service Architecture
Loading services...
Deployment Commands
Stop All Services
View Logs
Rebuild Single Service
—
Policy Self-Assessment Grade
Self-assessment from policy configuration
Independent Checker: checking status…
Framework Compliance Scores
Loading compliance data...
Assessment Details
Grade is calculated in real-time from loaded policy YAML files mapped against
11 compliance frameworks: NIST AI RMF, ISO 42001, EU AI Act, SOC 2,
PCI DSS v4.0, HIPAA, FINRA, FedRAMP, PIPEDA, Privacy Act (Canada), and TBSDADM (Treasury Board Directive on Automated Decision-Making).
When the independent Checker is online, its grade is shown for cross-validation.
Enforcement mode: deny-by-default Grade formula: Average of per-framework control coverage → letter grade A: ≥93%B: ≥83%C: ≥73%D: ≥60%F: <60%
Framework Requirement Mapping
Framework
Control ID
Requirement
Test Coverage
Loading framework mappings...
10/10
OWASP Agentic Categories — Controls Mapped
OWASP Top 10 for Agentic Applications (2026) — control coverage self-assessed from the bundled test catalog. Design-time mapping, not an independent live validation.
Per-User Banks: Each operator gets isolated memory (user-{id}) Department Banks: Shared context within business units (dept-{name}) Org Decisions: Cross-team decisions, rulings, exceptions auto-captured Policy Knowledge: Governance policies indexed for LLM grounding Audit Banks: Searchable supplement to immutable JSONL audit trail Entity Extraction: Configurable (local LLM or cloud provider)
Platform Users
Create New User
Reset Password
User:
Change Role
User: · Current:
HR data (roster, headcount, leave, analytics) is limited to admins and users granted here. Regular staff keep self-service only.
CRM records are limited to admins and users granted here. Without this grant the CRM tools decline every request, whatever the phrasing.
The Bookkeeper role grants access to the Month-End Close dashboard + AI Bookkeeper. For SSO users this is written to the identity provider so it persists across logins.