Assurance
Review the operating boundary before the system goes live.
This section explains how a DecarbDesk workflow is evaluated, controlled, recorded, and handed over. Each area names the operating evidence a client should expect.
Four assurance areas, each with an evidence path.
Assurance is part of delivery, not a separate certification claim. The exact controls and evidence depend on the workflow, environment, and client obligations.
Reliability & evaluation
DSPy-based evaluation, versioned reference sets, score tracking, regression review, and deployment gates.
Evidence: Evaluation definitions, score history, failed-case review, and release decisions.
A-02Security & controls
Role-based access, approval thresholds, audit records, exception handling, and stop controls.
Evidence: Role map, control configuration, approval records, exceptions, and administrative events.
A-03Responsible AI
Use-case boundaries, human oversight, impact readiness, documentation, and operator training.
Evidence: Purpose and boundary statement, oversight model, risk notes, and training records.
A-04Privacy & data handling
Data minimization, defined processing boundaries, scoped credentials, and client-controlled storage.
Evidence: Data-flow map, integration scope, credential ownership, and retention decisions.
Questions every deployment must answer.
- Purpose
- What decision or service task does the workflow support?
- Authority
- Which actions can the system take, and which require a person?
- Data
- What information enters the workflow, where is it processed, and where is it retained?
- Quality
- How are outputs evaluated, and what happens when a threshold is missed?
- Traceability
- Can an operator reconstruct the inputs, decisions, approvals, and outputs?
- Operations
- Who monitors the workflow, handles exceptions, and approves changes?