Feature · My work

AI agents draft, map, and test. A human makes every decision.

Specialized agents watch regulators and do the first pass. Nothing counts until a person confirms it.

SectionMy work
UpdatedSeptember 2026
Agent runs · 15 task types · human on every decision
  • 14:02:19Mapping FFIEC-2026-17 against Authentication Policy v4.2Policy mappingRunning
  • 14:01:54Indexed 17 citations in §3.2.1: §5.1, §5.4, §11.2Citation indexerLogged
  • 13:58:03Gap detected: §11.2 references retired access vendorGap analysisProposal
  • 13:54:11New publication: BSA-1042-A revision (effective Jul 1)Regulatory monitorLogged
  • 13:50:42Drafted exam-ready response for CRA-2025-09 · 8 citationsDrafterLogged
Bedrock / Anthropic defaultZero data retention
Illustrative product preview. It does not show tenant data.
01 · AI agents

The agent catalogue

Every agent run is one of a closed, named set of task types (agents/tasks/). Each agent does one job and stays in its lane.

  • 01The catalogue starts with Regulatory Monitor, Gap Analysis, Policy Mapping, Drafter, and Citation Indexer.
  • 02Exam Prep, Mock Examiner, FDL Classifier (fair lending), and Ad Screener are part of it too.
  • 03So are SOC Reviewer, Contract Reviewer, and Horizon Scanner (emerging risk).
  • 04Internal audit has IA RCM Drafter, IA Workpaper Drafter, and IA Finding Drafter, and all three are draft-only.
02 · AI agents

A human on every decision

Agents propose and a person accepts. Draft output stays a proposal on an immutable run until a human confirms it through the app.

  • 01The pipeline records each run and its proposal (agent_pipeline, AgentRuns).
  • 02Nothing an agent produces mutates your library until a person accepts it.
03 · AI agents

Every action cited and logged

Agent output is grounded in your corpus and traceable. Ungrounded output is rejected rather than shown.

  • 01Extractions must be found verbatim in the source or they fail grounding.
  • 02Each run is retained with its inputs, proposal, and outcome.
04 · AI agents

Inference transparency

You always know which model ran, and your data is never used to train one.

  • 01Inference runs on bank-grade AI services via AWS Bedrock (Anthropic Claude), with zero data retention.
  • 02Zovos never trains on customer data.
  • 03The provider used is recorded per run (agent_runs.ai_provider).
Proof points

Grounded in shipped behaviour.

  • A closed set of specialized agent task types ships (agents/tasks/): Regulatory Monitor, Gap Analysis, Policy Mapping, Drafter, Citation Indexer, Exam Prep, Mock Examiner, FDL Classifier, Ad Screener, SOC Reviewer, Contract Reviewer, Horizon Scanner, and three internal-audit drafters (RCM, workpaper, finding).
  • Agents propose, and a person accepts. Draft output stays a proposal on an immutable run until confirmed.
  • Bank-grade AI services via AWS Bedrock · zero data retention. Zovos never trains on customer data.
  • The provider used is recorded per run (agent_runs.ai_provider).

Counts come from the platform's regulatory corpus, connector registry, and seed template library at release. See the documentation for the current values.

FAQ

Questions, answered first.

Do agents change anything on their own?
No. Every output is a proposal on an immutable run. A person accepts it through the app before it affects your library.
Which model runs the agents?
The agents run on Anthropic Claude models via AWS Bedrock. Amazon Bedrock does not store prompts or completions or use them to train models.
Does Zovos train on our data?
No. Your data is never used to train a model.
How do I know an agent did not make something up?
Extractions must be found verbatim in the source or they fail grounding and are not shown, and every run is logged with its inputs and proposal.

See ai agents on your library.

Bring your controls, a policy, and one regulator paragraph that gives you trouble. We target two-week onboarding.