No shadow AI, no black box. Each system below is one guarded path: it reads only your own data, removes personal details before any model sees it, lands on a record you can check, and — where it can change anything — waits for a person.
11
AI systems
every one
Personal details removed first
every call
On a record you can check
5 of 11
Can't act without a human
The four RMF functions — Govern, Map, Measure, Manage — backed by controls already enforced in the platform, not aspirations.
One card per AI system. Every one removes personal details before the model and lands on a record you can check — the badge shows the human approval it can't act without.
Scouts funding opportunities and proposes new prospects for the pipeline.
Rates a prospect 0–100 against the tenant profile, with a written rationale.
Drafts a grant application from the prospect and the org's own record.
Drafts a post-award funder report under the same proposed→final discipline as drafts.
Conversational help over the grant pipeline; can propose pipeline changes.
Grounded assistant across every app; can propose the same whitelisted writes as the co-pilot.
Sharpens a civic resource’s summary in plain language for the tenant.
Translates and culturally localizes a civic resource’s summary into a resident’s language.
Answers a question about civic resources, grounded in and cited to the matched hub rows.
Turns a builder’s plain-English idea into a safe, governance-valid app listing (copy only).
Narrates "what changed this week" from the confirmed harm/resilience indices in plain language.
The model provider is disclosed on our sub-processor list. More on how it’s built: Security & Trust.