Skip to main content
Evidence-Bound AI Assurance

Know what your AI can do
before it acts.

HAIEC connects source, identity, access, policy, permissions, evidence, and observed behavior to show what AI systems and agents can reach, change, and trigger. See what the evidence actually establishes.

Applicable to AI applications, AI systems, AI agents, model/API integrations, automated AI workflows, and consequential agentic systems.

Loading sample map…
The Blind Side

Permission is not delegation.

Security controls answer whether an identity is permitted to do something. They do not necessarily establish whether the AI was delegated the consequential choice it made. A valid permission and a valid delegation are not the same evidence.

Permission

An identity policy that allows an action. Establishes what is permitted, not what was authorized by a human decision.

Delegation

Whether a human or process with authority actually delegated the consequential choice to the AI. Distinct from permission. Not always established by available evidence.

HAIEC does not claim delegation violations are currently proven unless evidence establishes them. The distinction between permission and delegation is a structural insight, not an automatic finding.

See the System

The AI Action & Access Map.

See how identities, permissions, AI actions, APIs, infrastructure, data, and consequences connect. The Map shows what an AI agent can reach, what credentials it uses, what controls apply, and what the evidence actually establishes.

Reach

What the AI agent can access

Credentials

What permissions are in play

Actions

What the AI can technically do

Consequences

What could happen if it acts

Five Evidence Questions

What the evidence establishes.

HAIEC evaluates across five evidence questions. Not all five are always available. Missing evidence remains UNKNOWN. It never silently becomes a pass.

1. Intention

What you intend the AI to do

2. Policy

What your policy allows

3. Credentials

What credential evidence establishes

4. Capability

What the application can technically do

5. Observed

What HAIEC observed where supported runtime sources are connected

These are evidence questions, not a causal proof chain. A gap between any two is a finding, not a safe state. Not every question currently has a native evidence producer.

How HAIEC Works

Define → Connect → Collect → Assure → Verify → Monitor

A bounded lifecycle for evidence-bound assurance of consequential AI systems.

Define

Select the AI system and assurance question

Connect

Connect evidence sources: repo, APIs, and infrastructure

Collect Evidence

Source, identity, access, policy, capability

Assure

Deterministic evaluation within explicit scope

Verify

Decision Receipt with SHA-256 integrity

Monitor

Ongoing evidence from supported runtime sources

Monitor is bounded to supported evidence and runtime sources. Not every connected asset has a native evidence producer. Evaluated Scope is currently structured at the contract level; structured scope binding is under development.

Evidence & Framework Support

Mapped to standards. Not defined by them.

HAIEC maps evidence to recognized frameworks and regulations. This is evidence mapping, technical evaluation, readiness, and assurance support. Framework mapping is not the same as assurance. A green or source-established fact is not the same as safe.

NIST AI RMF
OWASP LLM
ISO 42001

HAIEC supplies evidence and analysis. The qualified firm, CPA, certification body, or assessor retains professional judgment and issues the applicable attestation, certification, or assessment outcome. Framework mapping does not equal assurance.

Evidence-Bound Assurance for Consequential AI

Know what your AI can do
before it acts.

See what AI systems and agents can reach, what controls apply, and what the evidence actually establishes.