Industries / Enterprise
One knowledge layer every team uses.
Your business units keep buying their own AI tools. This gives them one approved place to read from, with a name on every entry.
The problem
A third team bought one.
“I need an AI architecture I can defend to security, compliance, and the CIO.”
Every business unit is solving the same problem separately, and security is reviewing each answer after it has already been given.
One business unit buys an AI tool. Then a second. Then a third, and each points at a different pile of files.
Permissions are set differently in every repository. None of them is the authoritative one, so the same question has three answers and nobody signed any of them.
Then a security review blocks an integration you own, and you are asked to defend an architecture that nobody designed.
Why this industry
We have run knowledge bases.
The people behind Cognatum have run knowledge bases as a business for years, not as a side effect of building something else.
RocketDocs has served regulated response teams from a knowledge base since long before generative AI made this question urgent.
That history is why the product starts from the record rather than from retrieval. A system that finds a document quickly is a different kind of thing from one that can say who approved the sentence it just returned.
These are the failure modes we watched happen, over and over:
- The answer existed and nobody could find it.
- Three versions existed and nobody knew which one was current.
- The person who knew left, and the knowledge left with them.
- Someone answered from memory and was confidently wrong.
What we will not claim
Cognatum does not make you compliant with anything. No software does.
What it produces is evidence you can put in front of a reviewer: which entry answered, who approved it, when, and from what source. Your obligations stay yours, and your auditors still audit you.
What it does here
What it does in your company.
Work already produces knowledge. It lands in documents, threads, tickets, and records, spread across whichever systems each team happens to use.
Capture
Work becomes entries
Each document, thread, or ticket becomes an entry with a title, a body, a link to where it came from, and an owner.
Approve
One gate, one name
A named person approves the entry. Nothing is served until somebody does. That gate is what separates a knowledge base from a folder.
Clearance
Answers stop at the boundary
What comes back is decided by the asker, at the point the answer is made. An agent answers within the clearance of the person it acts for.
Gaps
Unanswered becomes a work list
A question with no approved answer is recorded as a gap with an owner, instead of being absorbed and forgotten.
Frameworks
What each framework asks.
Written as pairs, because a list of framework names is one screenshot away from reading as a claim to hold them.
| Instrument | What it asks of you | What we supply toward it |
|---|---|---|
| ISO 27001 | That information security is managed by a system with defined controls, documented ownership, and evidence that the controls operate. | Every entry has a named owner and an approval record. Access to an entry is decided by clearance rather than by who found the file. |
| SOC 2 | That you can show an auditor how a control worked over a period, not only that it exists today. | The approval trail is kept per entry and per version, so a period can be evidenced from the record rather than reconstructed from memory. |
| GDPR | That personal data has a lawful basis, a defined retention period, and a record of processing. | Entries carry their source, so where an answer came from is a matter of record. Retention and lawful basis remain yours to set. |
This table describes obligations that fall on your organization, and the evidence Cognatum produces toward them. It is not a claim of certification or conformity, ours or yours.
Why not search
You cannot approve a pointer.
Search tools index what you already have and point at it. That is genuinely useful, and it is a different job.
The difference is not ranking quality, and it is not how many connectors either side ships. It is structural.
You cannot version a file you only point at. You cannot approve it either, because the file changes underneath the index and the index follows.
And you cannot say afterwards that anybody stood behind it, because no record was made at the moment somebody decided.
Who asks
Cognatum, the governed layer
approved · versioned · permissioned
Where the work already happens
In practice
Three repositories, one assistant.
One business unit wants to connect an assistant to the places its work already lives.
A team asks to point an AI assistant at a document store, a wiki, and a validated procedure repository, each with its own permissions.
You map the repositories, the identities, and the sensitivity labels once. Nothing is served until a named person has approved it.
Clearance is decided when the answer is made, so nobody gets an answer they could not have opened themselves. Denials are recorded.
Change a source and every entry built on it is flagged for re-check. The record shows the source, the approver, and the version behind each answer.
Common questions
What architects ask first.
Do we have to move our content into this?
No. Entries are drawn from the systems where work already happens, and each entry links back to the file it came from. Your repositories stay where they are.
How do permissions work across systems that disagree?
Clearance is decided at the point the answer is made, not only at the document store. Two people can ask the same question and get different answers, or none. Denials are recorded.
What connects to it?
Assistants and agents connect over MCP, the open standard AI assistants use to reach outside data. Applications and workflows connect over a plain API. Both directions are supported.
What happens when two approved sources disagree?
They are held apart and routed to a person to settle. They are never averaged into one confident answer. A conflict is a decision, so a person makes it.
Is this a migration project?
No. The loop drafts entries from work your teams are already doing, and your people approve a few at a time. There is no six-month cleanup before anything is usable.
Knowledge governed. Intelligence everywhere.
See it on your own content, in your own environment.