Controlling access is
not verifying answers
Data-exchange platforms govern who may reach a document and log every access. That is a real and necessary layer — and it says nothing about whether the answer derived from that document is correct. Both questions get asked in the same audit.
"Your access log shows who opened the document. Now show me why the system concluded what it concluded."
Access governance answers the first half and stops there. The second half is a question about reasoning, and it needs a different kind of record.
Why ordinary search does not get there
Both layers use the same vocabulary.
Sovereignty, audit trail, compliance, zero trust. Identical words, different objects: one governs the channel, the other governs the conclusion.
Buying one and assuming the other is common.
An organisation with impeccable access governance can still deploy an assistant that produces unsupported answers about perfectly governed documents.
Only one of the two can abstain.
An access layer permits or denies. A reasoning layer must be able to say 'the documents do not support an answer' — and most do not.
A worked example
Where does the boundary actually run?
- 01Access layer
Identity, permission, encryption, transport, access log. Proves the document was not leaked.
- 02Retrieval layer
Which passages were consulted, and why those and not others.
- 03Reasoning layer
Which sub-question each source answered, and how they combine.
- 04Answer contract
Every claim cited, contradictions surfaced, abstention where evidence is absent.
The first step is somebody else's job and should stay that way. The last three are ours, and ARGUS integrates with the first rather than replacing it.
What ARGUS does here
Sits on top of your access layer
Where an access gateway or repository connector already governs retrieval, ARGUS consumes documents through it and inherits its permissions and logging.
Evidence ledger
Every claim carries its source, and the reasoning steps are recorded, so an answer can be re-examined months later.
Abstention as a feature
No source, no answer. A gap is reported as a gap rather than smoothed over with fluent text.
Model independence
Commercial API, EU-hosted endpoint or a model on your own hardware. The verification layer does not change when the model does.
What it does not do
Stated here rather than discovered in week three of a pilot.
- ARGUS is not a secure file transfer, email gateway or access governance product, and does not try to be.
- It does not replace DLP, encryption or identity management.
- Verifiability is about traceability to sources, not about truth in the world: a wrong statement in a correct source is still reported with its citation.
- Built and demonstrated scenarios; no production installations.
Questions we get asked
We already have a data governance platform. Does this compete with it?+
Can it integrate with an existing gateway?+
How do you prove abstention actually happens?+
Test it on a question you already lost time on
Bring one question your own documents should be able to answer, and the documents that ought to contain the answer. If the evidence is not there, that is the result — and it is worth knowing before an auditor finds it.