Cognatum

Governed Solutions / System of record

Where the approved answer lives.

Cognatum is a system of record. It stores the approved answer itself. Traditional search & AI only points to an answer and cannot vouch for it.

Who asks

AI assistants & agentsProposal toolsInternal search & chatCustomer portalsCompliance & auditEmployeesBusiness applicationsWorkflowsSupport teamsAuditors

Cognatum, the governed layer

approved · versioned · permissioned

Where the work already happens

SharePointSlackCRMTicketingWikisEmailDocumentsShared drivesBusiness systemsCollaboration toolsStorage

Without Cognatum

Nobody approved that answer.

An AI system does not go live until a review board signs off on it.

Regulated enterprises are deploying AI assistants and agents they cannot prove are answering correctly, and their AI initiatives are stalling at governance review because of it.

Ask who approved the answer an AI assistant just gave, and the honest reply is that nobody did.

A system of record for knowledge stores the canonical, approved, versioned entry. Index-in-place tools point at content wherever it happens to live, which means they cannot version it, approve it, or attest to it.

The word for that record is provenance: who approved an entry, when, from what source, and at which version.

app.example-cognatum.internal
Knowledge Approver D. Whitfield
Draft 26 In Review 41 Approved 318 Stale 27 Archived 9
Search knowledge... All types Reach: high to low Taxonomy
Select all Showing 1-50 of 412 items Export CSVExcelPDF
Select TitleTypeTaxonomyStatusExpiresReach
Which retention period applies to client trade communications? Q&A Records Approved in 214 days 38
Standardize retention schedules on the records policy Decision Compliance Approved in 149 days 31
Applying a legal hold to a retention schedule Procedure Legal Approved in 24 days 27
How long are supervisory review records kept? Q&A Supervision In review in 96 days 18
Which regions are approved for data residency? Q&A Security Stale Expired 6 days ago 12
Retention questions raised in the Q3 examination Note Compliance Draft No expiry 4

The choice

Three ways to feed AI.

Three architectures now compete to feed enterprise AI. They differ in the one dimension that decides governance review: whether anyone can attest to what gets generated.

Architecture 01

Index in place

Leave content where it lives, crawl it, and rank it. Nothing to author, and nothing to approve.

Architecture 02

Verification workflow

Add a person who confirms on a cadence that a card is still accurate. A real improvement, and still not a record.

Architecture 03

A governed record

Store the approved entry itself and govern it, so the approval, the date, and the version belong to the answer.

The first one

What an index cannot know.

An index does not know which of the six copies of a policy is current, whether the page it just retrieved was superseded last quarter, or whether anyone with authority ever reviewed the words it hands to a model. It can point to content. It cannot vouch for it. The limit is structural, not a roadmap gap: you cannot version, approve, or attest to content you merely point at.

For disclosure language at a broker-dealer or a medical information response at a pharmaceutical company, it is the point where the AI initiative stalls: an index cannot say who approved what the AI assistant said. The trail ends at a URL, and a URL is not an approval.

Source A · Retention policy v7

Supervisory records are kept for six years.

APPROVED

Source B · Supervisory procedures v3

Supervisory records are kept for five years.

APPROVED

Neither is served as approved

The record settles it

Resolution queued for approval

Entry B supersedes A · Effective 2026-05-01 · queued

A real disagreement

Flag open

Routed to a named person · Records management

The second one

A check is not a record.

The second architecture adds a human check. This is the ground verification-workflow tools such as Guru occupy: a designated verifier confirms on a review cadence that a card of content is still accurate, and unverified cards get flagged. It is a real improvement over pointing. Someone is at least looking.

It still stops short of a governed system of record, in three specific ways.

  • No answer-level provenance chain. A verified card says the card was reviewed. It does not say who stands behind the specific answer an AI assembled from it, at which version, from which source.
  • No sovereign deployment. The knowledge and its history run where the vendor runs, not necessarily where a regulated customer needs them to.
  • No AI running the maintenance loop. Deduplication, reconciliation, and archiving still depend on the sustained human diligence whose lapse left the knowledge ungoverned in the first place.
app.example-cognatum.internal
Find SMEs Approver D. Whitfield
SMEDepartmentPrimary ExpertiseAvailabilityIn queueAuthority
D. Whitfield Head of Records Management Records Management Records retention and legal hold Same Business Day 6h / wk 3 Can review Can approve
M. Alvarez Compliance Director Compliance Supervisory procedures and examinations Within 2 Days 4h / wk 0 Can review Can approve
J. Park Senior Counsel Legal Data residency and cross-border transfer Same Week 3h / wk 1 Can review
R. Okonjo Quality Systems Lead Quality Change control and deviation handling Within 2 Days 5h / wk 0 Can review
T. Lindqvist Platform Operations Engineer Operations Connector configuration and access roles Same Week 2h / wk 0 No review authority

With Cognatum

Four facts on every answer.

Nothing goes live until a named person signs off, and the sign-off is recorded, so every live entry carries four facts an AI assistant inherits every time it answers from the record.

  • A named approver: a person with authority put their name on this entry.
  • A timestamp: when the approval happened, not when someone last happened to look.
  • A source: the document or system the entry derives from.
  • A version: which iteration the approval attaches to, with the history retained.
Which risk disclosure is approved for the retail fact sheet? Ask
Approved answer APPROVED

Use disclosure D-214 rev 6. It supersedes rev 5 for all retail communications and carries the current market-risk language. SOP-4471 v3

Approved by J. Mercer, Regulatory affairs 2026-07-14

The chain

What an auditor wants.

The chip is a summary. Behind it is a chain, and the chain is what an auditor actually wants. Each link names the one below it, so a generated answer leads back to a dated decision a person made, rather than to a URL.

Superseded versions are retained rather than overwritten. That is the part that matters after the fact: the question is rarely what the entry says today, it is what it said on the day the answer went out, and who had signed off on that.

The answer, as served

Use disclosure D-214 rev 6. It supersedes rev 5 for all retail communications and carries the current market-risk language.

Asked: Which risk disclosure is approved for the retail fact sheet?

names

The entry and version it came from

Version v3, in force

v2 and v1 superseded and retained

names

The source that version derives from

SOP-4471

What version v3 was drafted from

names

The decision that put it in force

Approved by J. Mercer, Regulatory affairs

2026-07-14 · version v3, against SOP-4471

APPROVED

What the chip represents is evidence supplied toward the customer's own obligations: who approved this answer, when, and from what source.

Connected

Four flows, both directions.

  • Ingest, from source systems into Cognatum over a plain API and over MCP, the open standard AI assistants use to reach outside data: raw knowledge enters from wherever work happens.
  • Provide, from Cognatum to consumers over MCP and API: governed, approved entries reach people and AI.
  • Write-back, from Cognatum to the source systems: corrections propagate to the place the error came from, so people stop finding the stale version.
  • Usage signals, from consumers back into Cognatum: what gets used, questioned, and contradicted feeds the next cycle of the loop.

What never moves is where the truth lives. The canonical, approved, versioned entry lives in Cognatum. Other systems can reference it, cache it, or sync from it, but exactly one entry carries the approval, and every consumer, human or machine, answers from it.

Served to one approved entry
AI assistants & agents
Proposal tools
Internal search & chat
Customer portals
Compliance & audit

Cognatum governs the entry

source · version · approver · permissions

Where it lives

And you decide where.

A governed home raises one more question: where does that home live, and who gets to connect to it? That is what Sovrinty is for. Sovrinty is the control layer on top of Cognatum, and it becomes available once your knowledge lives in Cognatum, because control needs something real to hold.

It is a separate product and this page does not sell it. What is worth knowing here is the shape of the choice it gives you, because it is the question a security review reaches within about ten minutes.

  • Your hardware. The knowledge base runs in your own environment rather than ours.
  • Another country. The same knowledge base, in a jurisdiction you choose.
  • Another vendor. Which systems and which model providers connect to it stays your decision.

Common questions

What people ask here.

What is a knowledge management system of record?

It is the store that holds the approved answer itself, versioned, with a record of who approved it and when. A search index points at content wherever it happens to sit, which is why it cannot version that content, approve it, or say who stood behind it.

We already have enterprise search. Why is this different?

Search solves finding. This solves defending. A search box that returns the right document is a good search box, and it was never asked to vouch for what it returns.

What does an answer carry?

Four facts: the person who approved the entry, the date they approved it, the document it came from, and which version the approval attaches to. Superseded versions are maintained, so what an answer said on a date in March is a lookup.

Do we have to move our content?

No. Source systems keep their content and feed in. What moves is where the approved version lives: exactly one entry carries the approval, and every reader, human or machine, answers from that one.

Does this make us compliant with anything?

No. Standards and regulations assess organizations, not software. What you get is evidence toward duties you already carry: an approver, a date, a source, and a version on every answer provided.

Knowledge governed. Intelligence everywhere.

See it on your own content, in your own environment.