Industries / Other regulated enterprises
One knowledge layer every team uses.
Your business units keep buying their own AI tools. This gives them one approved place to read from making them more effective and more compliant.
Without Cognatum
A third team bought one.
“I need an AI architecture I can defend to security, compliance, and the CIO.”
Every business unit is solving the same problem separately, and security is reviewing each answer after it has already been given.
One business unit buys an AI tool. Then a second. Then a third, and each points at a different pile of files.
Permissions are set differently in every repository. None of them is the authoritative one, so the same question has three answers and nobody signed any of them.
Then one of the source documents changes, and none of the three tools knows which of their answers depended on it. Then a security review blocks an integration you own, and you are asked to defend an architecture that nobody designed.
The document store. The wiki mirrors it and the procedure repository is a subset.
No source · no approver · no date
Where did this come from? Nothing on this answer can say.
Why this industry
We have run knowledge bases.
The people behind Cognatum have run knowledge bases as a business for years, not as a side effect of building something else.
RocketDocs has served regulated response teams from a knowledge base since long before generative AI made this question urgent.
That history is why the product starts from the record rather than from retrieval.
These are the failure modes we watched happen, over and over:
- The answer existed and nobody could find it.
- Three versions existed and nobody knew which one was current.
- The person who knew left, and the knowledge left with them.
- Someone answered from memory and was confidently wrong.
What we will not claim
Cognatum does not make you compliant with anything. No software does.
What it produces is evidence you can put in front of a reviewer: which entry answered, who approved it, when, and from what source. Your obligations stay yours, and your auditors still audit you.
Which retention period applies to client trade communications?
Entry SOP-4471
- v4 In force
Retention extended to seven years for client trade communications.
D. Whitfield, Records management · 2026-07-02
- v3 Superseded · retained
Chat channels brought into scope.
D. Whitfield, Records management · 2025-11-14
- v2 Superseded · retained
Exception process added for legal hold.
M. Alvarez, Compliance · 2025-03-09
- v1 Superseded · retained
First approved version.
M. Alvarez, Compliance · 2024-06-18
→ what the entry said on a date is a lookup
With Cognatum
What it does in your company.
Work already produces knowledge. It lands in documents, threads, tickets, and records, spread across whichever systems each team happens to use.
Capture
Work becomes entries
Each document, thread, or ticket becomes an entry with a title, a body, a link to where it came from, and an owner.
Approve
One gate, one name
A named person approves the entry. Nothing is served until somebody does. That gate is what separates a knowledge base from a folder.
Clearance
Answers stop at the boundary
What comes back is decided by the asker, at the point the answer is made. An agent answers within the clearance of the person it acts for.
Gaps
Unanswered becomes a work list
A question with no approved answer is recorded as a gap with an owner, instead of being absorbed and forgotten.
Why not search
You cannot approve a pointer.
Search tools index what you already have and point at it. That is genuinely useful, and it is a different job.
You cannot version a file you only point at. You cannot approve it either, because the file changes underneath the index and the index follows.
And you cannot say afterwards that anybody stood behind it, because no record was made at the moment somebody decided.
Where the work already happens
Cognatum, the governed layer
approved · versioned · permissioned
Who asks
Who asks
Cognatum, the governed layer
approved · versioned · permissioned
Where the work already happens
Frameworks
What each framework asks.
| Instrument | What it asks of you | What we supply toward it |
|---|---|---|
| ISO 27001 | That information security is managed by a system with defined controls, documented ownership, and evidence that the controls operate. | Every entry has a named owner and an approval record. Access to an entry is decided by clearance rather than by who found the file. |
| SOC 2 | That you can show an auditor how a control worked over a period, not only that it exists today. | The approval trail is kept per entry and per version, so a period can be evidenced from the record rather than reconstructed from memory. |
| GDPR | That personal data has a lawful basis, a defined retention period, and a record of processing. | Entries carry their source, so where an answer came from is a matter of record. Retention and lawful basis remain yours to set. |
This table describes obligations that fall on your organization, and the evidence Cognatum produces toward them. It is not a claim of certification or conformity, ours or yours.
In practice
Three repositories, one assistant.
A team asks to point an AI assistant at a document store, a wiki, and a validated procedure repository, each with its own permissions.
You map the repositories, the identities, and the sensitivity labels once. Nothing is served until a named person has approved it.
Clearance is decided when the answer is made, so nobody gets an answer they could not have opened themselves. Denials are recorded.
Change a source and every entry built on it is flagged for re-check. The record shows the source, the approver, and the version behind each answer.
Requests in
One assistant, one asker
- Approved disclosure language
- Current supervisory procedure
- A draft nobody has signed
- An entry retired last quarter
Served
With approver, date, version
-
Disclosure D-214 rev 6
J. Mercer · approved 2026-07-14
-
Procedure WSP-11 v4
Supervision · approved 2026-06-30
Not served
Not fetchable at all
-
Draft entry
No approval on record
-
Retired entry
Archived 2026-04-11
Common questions
What architects ask first.
Do we have to move our content into this?
No. Entries are drawn from the systems where work already happens, and each entry links back to the file it came from. Your repositories stay where they are.
How do permissions work across systems that disagree?
Clearance is decided at the point the answer is made, not only at the document store. Two people can ask the same question and get different answers, or none. Denials are recorded.
What connects to it?
Assistants and agents connect over MCP, the open standard AI assistants use to reach outside data. Applications and workflows connect over a plain API. Both directions are supported.
What happens when two approved sources disagree?
They are held apart and routed to a person to settle. They are never averaged into one confident answer. A conflict is a decision, so a person makes it.
Is this a migration project?
No. The loop drafts entries from work your teams are already doing, and your people approve a few at a time. There is no six-month cleanup before anything is usable.
Knowledge governed. Intelligence everywhere.
See it on your own content, in your own environment.