Governance
Governance used to stop you finding out. Now it finds out.
Governance answers three questions: who may know what, who decided, and can you prove it afterwards. For its entire history it's been enforced the same way — by controlling who gets into the container. Here's what changes when a memory sits between your people, your AI, and your files.
The old flaw
The container is coarser than the question.
Almost every governance failure is the same mismatch. Someone needs one figure, so you admit them to the whole drive — over-permission. Most of the drive is sensitive, so you admit no one — and the work doesn't happen, or happens in shadow. Same root cause both times: you were forced to make a decision about a folder when the real need was a sentence.
Find and Seek separates two things that have been the same operation since paper: reading and asking. To ask a question of a record, you used to have to be let into the record. Put a memory in between and they come apart — "may ask questions of Finance" and "may read Finance" become two different permissions. The unit of governance stops being the container and becomes the answer.
Proof, not policy
A six-department audit that never crossed a wall.
We ran a spend-and-risk audit across six departments' files. The agent worked one wall at a time — 28 retrievals, every single one scoped to one team, each call authorised independently. No session ever held all six departments' records. And it still caught the thing no single department could see:
3/3
runs the walled agent caught the company invoicing itself across two departments' books
0/3
runs the agent with unrestricted access to everything caught it
28/28
retrievals scoped to a single team — walls never crossed
The class of risk that matters most is the class that's only visible across departmental walls — which is precisely what departmental walls make invisible. The segregation that protects an organisation also blinds it. That's not a flaw in segregation; it's its price. Until now, you simply paid it.
And to be clear about what's being claimed: the unrestricted agent completed the audit too. The claim is sharper than "we can and they can't" — the audit runs without the access grant that makes it unacceptable, and it ran cheaper doing it.
The clock
From 10 December 2026, your AI becomes disclosable.
Australia's Privacy Act reforms are tightening around AI: penalties for serious breaches now reach $50 million or 30% of turnover, individuals can sue directly for serious invasions of privacy, and from 10 December 2026, organisations must disclose in their privacy policies where automated systems substantially assist decisions affecting people. Every AI deployment will have to answer for where data goes and what the system does with it. That answer is structurally simpler when the data, the index, and the answers never left your hardware — and every retrieval left a record.