Appearance
Human in the Loop
Modulos is designed so that AI accelerates governance work without undermining accountability. Humans remain responsible for decisions, approvals, and attestations.
Mental model
AI informs. Humans decide. No agent output changes a compliance status on its own: Controls, Requirements, and Assets move only through the human status and review workflows. Some agent outputs, such as assessments and quantifications, are stored when the run completes, but they inform decisions rather than make them: every run is attributed and traceable, and a re-run replaces the result.
Principles
Modulos implements human oversight through a few consistent patterns:
- Statuses stay human: no agent changes an execution, fulfillment, or approval status; status changes go through the human workflows with their logs and reviews.
- Stored output is replaceable, not final: assessments and quantifications are re-runnable; the stored result is the latest run, not a locked verdict.
- Auditable runs: agent runs are attributed, logged, and traceable back to their inputs.
- Stable artifacts: locking rules protect Evidence and completed work from post-hoc edits.
- Clear data boundaries: Sources are project service accounts, and Connectors are user accounts.
Where humans close the loop
Agent output and where review happens
Each agent has a defined handoff point where human judgment takes over:
- Evidence Agent: proposes Evidence titles, summaries, and candidate Control mappings. You review and save before anything is created.
- Control Assessment Agent: running it stores the readiness assessment directly; each run replaces the last. Your review happens on the result: validate gaps and recommendations against the Evidence, fix what it found, and re-run. The assessment never changes a Control's status.
Learn more:
Reviews and accountability
Accountability is built into how statuses change: Controls change status directly with a logged comment, Requirements are reviewed and fulfilled by their owners, and Assets use a formal review request with an approve-or-reject decision. This keeps status changes auditable without slowing down day-to-day work.
Learn more:
Stable artifacts and audit readiness
As work progresses, Modulos protects audit-relevant artifacts:
- Evidence becomes harder to change once it supports executed Controls.
- Stored assessments and status change decisions remain visible in logs for traceability.
Sources and Connectors
Agents can be grounded in two kinds of access:
- Sources are project-level service accounts attached to a project.
- Connectors are user-level accounts attached to the current user.
This separation makes it possible to combine a shared operational view with user-scoped access to external systems.
Learn more:
Responsible AI
- Modulos is a signatory of the European Commission’s AI Pact.
- Read our Code of Responsible AI.
Important considerations
- AI can make mistakes. Treat outputs as drafts and verify against your underlying Evidence and system reality.
- Scores are not certifications. Use them to focus review effort, not as a substitute for approvals.
- Use the audit trail. When decisions matter, capture rationale in comments and reviews so auditors can follow the reasoning later.