For Compliance Leads

Server-enforced segregation of duties
for AI agents that act on systems of record.

If you are the person who attests to the control objectives, this page is the technical evidence base. Syntheka does not certify compliance. Syntheka is the technical foundation that makes AI agent actions defensible to the internal auditor, the external auditor, and the notified body.

Syntheka is built for that question. This page is the evaluation checklist we use with compliance leadership. Honest on what we do, what we don't do, and where we are not yet ready for your environment.

Why this matters to compliance

The question is not “is it logged” but “is it defensible to the auditor who walks in tomorrow.”

A Compliance Lead evaluating AI agent platforms is not asking about prompt quality or model size. The question is whether the platform can produce the technical evidence — within 60 minutes — that proves the control objectives your framework already names (SOX 404 for public; the equivalent for private; statutory audits for regulated industries; EU AI Act Article 9 risk management).

How the approval DAG works

Six states, seven transitions, one rule.

Syntheka's approval DAG has six states (Draft, Staged, Approved, Rejected, Executed, Reversed) and seven possible transitions. One rule runs through all of them: any single actor cannot occupy both the initiator and approver roles for the same action.

01 · Draft

Action being assembled

The agent or a human is composing a typed action on a typed business object.

Action has not yet entered the approval queue. Initiator identity is captured at composition. The state machine is the contract.

02 · Staged

Action in approval queue

Action is recorded with its rule set, target object, expected system-of-record state, and proposed approver chain.

Initiator identity is sealed. The system-of-record expected-state is captured so that three-way reconciliation has a reference to compare against.

03 · Approved

Qualified approver signed

An approver distinct from the initiator has approved. The system has verified: no role assignment, no token, no override can collapse those two identities.

Approval is recorded with identity, timestamp, evidence reference, and the configured rule set that authorized this approval.

04 · Rejected

Or approver rejected

Rejection is recorded with reason, rejecting identity, and the decision chain that surfaced the issue.

Action is closed in the audit log, not in the system of record. The state never advances to Executed. The original action is preserved with full evidence.

05 · Executed

System of record confirms

Action has been written to the system of record and three-way reconciliation has passed.

Platform intent, system-of-record state, and field evidence all agree. The state change is in the audit log. The action is complete.

06 · Reversed

When reversal is needed

Reversal is a compensating entry, not a delete. The reversal re-enters the approval DAG with its own chain.

Original action state changes; original audit record stays intact. The compensating entry has its own initiator, approver, hash chain, and three-way reconciliation.

What Syntheka does NOT do

Honest boundaries for the compliance conversation.

If any of these are required for your evaluation, Syntheka is not the right vendor today. We will tell you, and refer you elsewhere if we can.

The Compliance Lead evaluation checklist

Twelve questions to ask of any AI agent vendor.

Use these against any vendor, including us. If a vendor cannot answer them clearly, treat that as the answer.

  1. Is segregation of duties enforced in code, or is it a recommendation in documentation?
  2. Can the initiator of an action also approve it through any sequence of role changes, token rotations, or override paths?
  3. Is the audit log append-only and hash-chained? Can you verify on demand that the hash chain has not been broken?
  4. Do you record bi-temporal timestamps (transaction time + valid time), or only one of them?
  5. How do you reconcile platform intent against system-of-record state after the write — and are discrepancies surfaced as tracked exceptions?
  6. For reversals, is the reversal a deletion or a compensating entry — and is the reversal itself auditable through the same chain?
  7. What is the multi-entity / multi-ledger behavior — can one action accidentally touch two entities without an explicit override?
  8. Are audit records exportable as structured JSON for our audit analytics tooling (SIEM, GRC, internal audit dashboards)?
  9. Can you demonstrate a single concrete action end-to-end, with technical evidence, on a real system of record, in 60 minutes?
  10. What is your upgrade cadence, and do security patches enter via the same chain that agent actions do — so the upgrade itself is auditable?
  11. For our retention period (typically 7 years for SOX, longer for regulated industries), can the audit trail be replayed end-to-end?
  12. If we end the engagement, what is the exit path — full audit trail export, hash chain continuation or verifiable bridge, credential revocation?
Pricing for compliance

Three numbers that matter.

Syntheka's pricing is published, not quoted. There are no per-action variable surprises because there are no per-action variables in the price.

TierPriceFits
Starter$500 / monthOne team, one workflow, one site
Professional$2,000 / monthMulti-workflow, multi-site, multi-approver
EnterpriseQuote (custom)Self-hosted, air-gapped, regulated environment

A fixed-fee pilot is $1,500 for one site, 60 days, up to two workflows. The pilot pricing is honored for the first three customers.

The pilot ends with a measured evidence pack: hash chain validation report, SoD verification record, three-way reconciliation pass rate, bi-temporal export — the artifacts you can take to internal audit or to the notified body.

How to start

The Compliance Lead path through the pilot.

Most Compliance Leads we work with run a 60-day pilot in parallel with their existing process — not a replacement. The pilot ends with a measurable evidence pack, not a swap.

  1. Week 1: Define the action in scope (a payment run, a vendor master change, a refund queue). Identify the internal audit sponsor and the control objectives the pilot must evidence.
  2. Weeks 2-3: Syntheka composes the agent from the industry template plus your artifacts. No data leaves your environment. The approval DAG is configured with the rule set your control objectives require.
  3. Weeks 4-6: Run the pilot in shadow mode with the internal audit observer present. Every Syntheka-proposed action is compared against the existing process, side by side. Exceptions are tracked.
  4. Weeks 7-8: Report. The pilot produces the evidence pack: hash chain validation, SoD verification, three-way reconciliation pass rate, bi-temporal export. The decision to adopt, extend, or end is yours, with the technical evidence.