Governance
Studio:Blueprint is built to make the role of AI inside consulting work explicit and auditable. Every score, every finding, every roadmap action passes through human judgement. The system records who approved what, when, and on what evidence.
The seven governance principles
- AI proposes, the consultant approves. Agents may suggest scores, findings, mappings, and actions. None of them are committed to the record without explicit human approval.
- The methodology is the source of truth. Scores and gap rules come from the firm's own published methodology, not from generic model output. The methodology version used is recorded against every result.
- Evidence is reviewable, not asserted. Every finding is linked to its source. Confidence, contradictions, and the consultant's classification are visible alongside the claim.
- Every approval is attributed. The system records who approved each change, when, and against which version of the methodology and evidence base.
- Decisions remain auditable. Decisions are logged with reasoning. The ledger is append-only so prior judgement can be reviewed later without rewriting history.
- Client views are read-only and recorded. Share links produce a read-only client view. Generation, view, and revocation events are all written to the audit trail.
- Agents run within stated permission modes. Each agent declares whether it is read-only, propose-only, approved-write, or limited autopilot. The mode is visible in the product and enforced by the platform.
Where this shows up in the product
Forge. Scores carry a label that says they are proposed from your methodology and the supplied evidence, and a button to approve.
Evidence Canvas. AI-suggested findings are marked as suggestions until approved, and the approval is attributed.
Roadmap and Programme. Proposed actions arrive in a review queue. Nothing is added to the roadmap without approval.
Decision Ledger. Decisions are recorded with reasoning and remain auditable.
Client Progress Room. Snapshots are recorded against the audit trail. Share links are read-only and every event is logged.
Agents. Each agent's permission mode is shown on its detail page, with a one-line description of what that mode allows. See the four permission modes.