Supervisory Access
A scoped, revocable seat for a regulator or supervisor — with a hash-chained log of everything they read.
What it does
Supervisory Access is the only cross-tenant read in the platform, and it is built so that fact stays true. A regulator or supervisor is given an explicit grant — scoped to decisions, controls or proofs, bounded in time, and revocable — and every read resolves that grant back through the ordinary tenant-scoped queries rather than a second, privileged path. A refusal returns not-found rather than forbidden, so ids cannot be probed. Every access is written to a hash-chained log the supervised organisation can read and verify for itself: supervision that cannot itself be audited is surveillance.
Inside Supervisory Access
The core functions this engine provides across the Trust Fabric.
Supervisory Access composes with the Trust Fabric
Every engine is independently useful and interoperates through one API-first Trust Fabric — so identity, evidence, policy, risk and certification stay consistent across your AI estate.
Related engines
Trust Engine
Computes a signed, HCS-28 trust score per agent from its verified identity and governance track record.
- HCS-28 Trust Index
- Weighted adapters + coverage
- Drift monitoring
- Signed, publishable records
Risk Engine
Routes risk in proportion to impact — high-risk actions and low-trust counterparties escalate to a human, they don't fail silently.
- Risk-tiered escalation
- Policy thresholds (atoms)
- Trust-guidance routing
- Incident & near-miss reporting
- Proportional, not binary
Registry Services
Authoritative, federatable on-chain registries for agent identities and published trust records.
- HCS-2 identity registry
- Agent DID registry
- HCS-28 trust registry
- Federatable / discoverable
See Supervisory Access in action
Book a demo and see how the platform establishes trust across your AI systems.
