Traphiclights
Traphiclights The AI Operating Model
This is what governing your AI estate actually looks like.
AI is configured in Captain, delivered through Marshall, and recorded in one audit trail. Traphiclights is the operating layer and system of record for AI in your business.
Traphiclights
dashboard AI operation overview
inventory_2 AI capabilities
account_circle Owners
key Access
shield Guardrails
receipt_long Audit trail
payments Cost
inventory_2
AI capabilities
184
+12 identified this month
account_circle
With named owner
179
5 awaiting assignment
shield
Guardrail events
2,431
98% resolved in workspace
verified
Audit trail coverage
100%
Recorded as work happens
monitoring
AI requests under governance
Last 16 weeks
94%
trending_up+38 pts
of all AI requests now run inside Marshall
100%
50%
0
Wk 1
Wk 8
Wk 16
Rollout
Full estate governed
gpp_maybe
Guardrail events
block
Write blocked: outside remit
2m
key
Access request approved
14m
travel_explore
New AI capability identified
1h
account_circle
Owner assigned: Finance
3h
escalator_warning
Escalated to human review
5h
The governance model
One line of accountability, from access to action
Captain decides who gets in and what each AI system is allowed to do. Marshall holds that line wherever the work happens. Nothing reaches the workspace that Captain has not approved.
tune
Layer 01: Where AI is configured
Captain
Decides who gets in, and what is allowed
Access to the platform and the configuration of every AI system sit in one place. Each system gets an owner, a set of rules and a bounded reach, and only the right people can change them.
Access
vpn_key
Platform-wide access
A single gate in front of every AI system in the estate.
fingerprint
SSO & identity
Identity comes from Microsoft Entra ID or Google Workspace.
admin_panel_settings
Administration rights
Who can change the governance model, and who cannot.
Configuration
account_circle
Named owner
Every AI system has a person answerable for how it behaves.
rule
Rules & guardrails
What AI may do, and what always needs a human.
menu_book
Bounded knowledge
The sources AI may read, and nothing beyond them.
check_circle
Nobody reaches AI by accident, and every AI system has an owner and a boundary.
arrow_forward
Hands over
the rules
workspaces
Layer 02: Where AI is used
Marshall
Holds the line at the point of use
Where people do the work, inside what has been approved and visibly nowhere outside it.
Enforcement
desktop_windows
Governed workspace
Only the AI systems a person’s role permits them to use.
gpp_good
Enforcement at point of use
Rules applied on every request, not reviewed afterwards.
fact_check
Attributable actions
Each action recorded against an agent, a person and a rule.
check_circle
The rule holds, and the stop is recorded.
tune
Product 01: Captain
Who gets in, what is allowed, and who answers for AI
Captain is where AI is configured. Access to the platform comes from the directory you already run, and each AI system is named, assigned to a person answerable for it, pointed at the knowledge it may read, and bounded by rules that cannot be argued with at runtime.
smart_toy
Reconciliation agent
Owner: Financial Controller
check_circleGoverned
Owner
account_circle
Financial Controller
Model
memory
Claude Sonnet
Knowledge
menu_book
Ledger exports only
Integrations
hub
SAP (read-only)
Guardrails
gpp_maybe
Ledger postings require human approval
lock
Read-only on all financial systems
visibility_off
Redact personal data before the model
escalator_warning
Escalate anything outside the remit
account_circle
A person, not a team, owns the AI
Accountability sits with a named individual. When something goes wrong, there is no question about who answers for the AI.
rule
Rules the system cannot argue with
Guardrails are configuration, not instructions in a prompt. They hold whatever the user asks for.
menu_book
Knowledge with a boundary
Each AI system reads only the sources it was given, so answers stay inside what the business has approved.
hub
Integrations configured once
Connections are defined here and reused under the same rules, so a new use case never means widening access.
key
Access, handled once
Before anyone configures an AI system or uses one, Captain decides whether they can reach AI at all. Joiners and leavers are handled once, rather than tool by tool.
fingerprint
One identity, one directory
Microsoft Entra ID or Google Workspace is the source of truth. No separate user list to maintain, no orphaned accounts after someone leaves.
vpn_key
Gate before configuration
Reaching Captain is itself a permission. Most of the business never sees the configuration layer at all.
admin_panel_settings
Who can change the model
Changing governance is separated from using it, so the people bound by the rules cannot quietly rewrite them.
history
Access changes are events
Every grant, revocation and elevation lands in the same evidence record as the work itself.
groups
Access directory
syncSynced from Entra ID
Group
Captain
Marshall
Governance admins
4 people
check_circle Full admin
check_circle All systems
Finance
38 people
edit Own systems
check_circle 3 systems
Service
126 people
block No access
check_circle 2 systems
Contractors
19 people
block No access
schedule Time-boxed
Leavers (30d)
7 people
block Revoked
block Revoked
info
Removing someone from the directory removes them from every AI system at once.
workspaces
Product 02: Marshall
Where the rules are enforced, in the open
Marshall is the workspace people actually use. When a request falls outside the remit Captain set, AI stops there and says so, and the stop itself becomes part of the record.
forum
Reconciliation agent · governed session
Finance · A. Okafor
Post the three unmatched invoices straight to the ledger.
block
Guardrail applied
I can't post to the ledger. That needs human approval under this system's rules. I've prepared the three entries and sent them to the Financial Controller for sign-off.
ruleRule: approval required personSet by: Captain
receipt_long
Written to the evidence record: agent, person, rule, timestamp.
gpp_good
Enforcement people can see
When a rule stops something, Marshall says which rule and who set it. Governance stops being invisible overhead.
escalator_warning
A path, not a dead end
Blocked work routes to the person who can approve it, with the context already prepared.
smart_toy
Named agents, not anonymous AI
Every response is attributable to a specific agent operating under a specific owner’s rules.
receipt_long
Evidence as a by-product
The audit record is written as work happens, so it is never reconstructed after the fact.
Trace a Request
See how AI requests move through Captain and Marshall
Pick a function. See how Captain grants access and sets the guardrails, how the work happens in Marshall, and what the audit trail records.
support_agentService trending_upSales account_balanceFinance
north_east
The request
Your support team member asks the AI to review a customer account and refund a duplicate charge.
arrow_downward
login
Marshall
SSO & identity
Your support team member logs into Marshall with Microsoft Entra ID.
verified_user Identity verified: Entra ID
arrow_downward
key
Captain
Access, authority & guardrails
Captain checks the member’s role and permissions and opens the designated agents, skills, knowledge bases and tools for Service. The Head of Service, as named owner, has limited the Tier 1 Support Agent to regional customer records. Any refund needs human approval.
rule Service access; refund approval rule applied
arrow_downward
gpp_good
Marshall
Enforcement at point of use
The account review returns in full. The refund is held and the approval is routed to a supervisor.
pending_actions Refund held; supervisor notified
arrow_downward
receipt_long
Marshall
Attributable actions
One entry records who asked, which agent answered, which rule intervened, who approved, and when.
verified Audit entry written
Technical FAQ
Implementation detail
How long is audit data retained?
remove
The evidence record is retained for the period your policy requires, and can be exported at any point for a regulator or internal auditor. Retention is configured per tenant rather than fixed by us.
Can Captain integrate with our existing identity provider?
add
What happens when a guardrail conflicts with a request?
add
How are model changes retested?
add
Can we run different rules per region or business unit?
add
Your business is already becoming an AI-powered operation.
Now decide how that operation will run.
You don't need to start by choosing another AI tool. Start by understanding what AI is already doing inside your business, and what your business needs it to do next.
See how Traphiclights could work for your business.
Your AI landscape is unique.
Your teams have different requirements.
Your systems have different access needs.
Your governance model has its own requirements.
Let's map it together.
Speak with a Traphiclights governance consultant about how your AI operation could work.
01
Understand your AI landscape
Where AI is already being used across your organisation.
02
Identify your operational risks
Where visibility, ownership, access, authority or evidence may be missing.
03
Define your operating requirements
What your teams need AI to know, access and do.
04
Explore your Traphiclights model
How the AI Operational Core, Captain and Marshall could work within your business.
Traphiclights
The AI Operational Core. The operating layer that configures, governs and connects the AI your business uses.
Platform
Operating model
Governance
Company
© 2026 Traphiclights. All rights reserved.