A technically correct system can still create unsafe, unlawful or distrusted work. These are the controls we build in, the failure modes we design against, and the decisions we refuse to automate.
Two of three factors on every account, phishing-resistant preferred: FIDO2 security keys and device biometrics via WebAuthn, authenticator TOTP, or push approval. CJIS-style controls per the SRS non-functional requirements.
88 role templates scoped by tenant, department, team and assignment. Access decisions evaluate purpose, not just identity — API-IAM-003 returns a policy result on every request.
Nobody holds permanent keys to protected zones. Elevated access is requested with a purpose, granted time-boxed, fully logged, and expires automatically. Weekly grant sampling.
Clinical, occupational-health, forensic-psychology, privileged-legal and audit stores each carry independent policies. Cross-zone reads are denied and the denial is itself audited.
An inheritance model, not a folder tree: global policy flows downward; lawful local variations are explicit, versioned and reversible. Feature plans, role templates, rule packs, language and retention all inherit.
No one raises, approves and receives the same purchase; no one certifies their own sentence calculation. Attempts are hard-blocked at source and logged as precedent.
Every screen in XReform carries an audit register. Every audit entry records who, role, device, time, reason and policy result. Corrections preserve the original — nothing is silently rewritten.
Every registered AI use has an owner, a legal basis, an evaluation, an explanation, an override path, an appeal route, monitoring and a kill switch. Green is not "no risk"; amber may be prohibited by local law or policy; red decisions stay human and contestable.
| Registry ID | Use | Lane | Governance |
|---|---|---|---|
| AI-004 | Spend anomaly ranking Cohort baselines rank ledger anomalies for accounts review | GREEN | Precision audited quarterly (71%) · human decides every action |
| AI-007 | Housing placement ranking Soft-constraint scorer over lawful candidates only | AMBER | Hard constraints block separately · overrides 11%, all reasoned |
| AI-011 | Recidivism cohort analytics Population outcome model for programme evaluation | AMBER | Policy gate blocks any individual adverse decision |
| AI-REQ-31 | Automated segregation triage Vendor proposal to auto-rank segregation candidates | RED | DENIED · disciplinary decisions stay human and contestable |
Staff defer to a score or an alert.
Purpose expands because the data exists.
Missing context becomes false certainty.
Every ranked output shows why, can be overridden with reasons, and staff are trained that the score is a navigation aid.
New purposes require a new lawful basis and a redress route — not just a new dashboard.
Figures ship with lineage and confidence; quarterly fairness review by language, gender and age.
Count, medicines and release cannot wait for the cloud. Critical work continues locally on the facility edge node with signed evidence, then reconciles conflict-aware when service returns.
Audit events immutable for 25 years; CCTV 90 days (evidence until case closes); IoT telemetry 400 days rolling; staff screening 24 months then aggregate only. Deletions are provable events, not silences.
Legal calls, messages and mail are excluded from recording, monitoring and analytics at the infrastructure level. Interview rooms have no recording capability at all.
Aggregates render only above thresholds (n ≥ 8 for staff wellbeing, n ≥ 30 for outcome subgroups). Below that, data rolls up or is discarded unread.
Deployable in-country on sovereign cloud or on-premise with facility edge nodes. Tenant data never crosses a jurisdiction boundary without an explicit, versioned configuration decision.
TLS 1.3 in transit, AES-256 at rest, MQTT-TLS for device telemetry, per-tenant key separation, and hash-chained event stores for tamper evidence.
Ombudsperson read-only access to grievance samples, internal audit sampling on observation proof and access logs, and external notification thresholds for serious incidents.
See also: Privacy policy · Terms & conditions · Service status & SLA
Architecture diagrams, data-flow maps, zone models, retention schedules, AI registry extracts and drill reports — for your security review, not for a brochure.
Request the pack