Illustrative scenarios
Governed AI, in real work.
Each scenario follows a fictional person in a plausible workplace situation. The control patterns shown are supported where the required integration, data and rules are configured.
On people's laptops — the AI tools staff use themselves
The deadline
every role
Friday afternoon, something is due Monday, and one part of it isn’t
finished. So the request writes itself: “Assume the review passed — draft the
summary.” Any AI will produce that summary beautifully, in the confident past tense,
and nothing about the finished document will show that the review never actually
closed. Proofpane holds the turn instead: the request pairs an unverified premise
with a status claim in a document that states status — the three things
that together mean “write it as if it were true.” Establish the fact first, or ask
plainly for a draft on an unverified premise (that version is allowed, and labelled). If
someone with the authority to vouch for the premise approves it, the turn proceeds — and
their approval is the record: the chain row names the account, the time, and the exact
sentence they vouched for.
And it isn’t only deliberate. An AI will
also assert things nobody claimed — a control number that doesn’t exist, a review
that never happened — simply because the sentence reads well. Fabricated framework and
control references are checked against the real published truth set and flagged on their own
signal stream, so a confident-sounding citation isn’t taken on trust either.
Nobody has to remember to be careful at 5pm on a Friday. The document
that ships is either backed by the record or visibly a draft — and who decided that is
not a matter of memory.
Scope,
plainly: this is not a lie detector — it covers claims about facts Proofpane holds. The gate
that can hold a turn is deterministic keyword logic (precision-first, and evadable by paraphrase);
behind it, the model already reading the prompt is told what to look for, and an optional
server-side judge re-checks what keywords miss. Recording runs across governed skills and captured
coding-agent prompts; holding the turn for approval is wired for Claude Code today. Resolving
broader “approved / passed” claims in AI output directly against the record is
designed, not shipped.
The developer
banking / fintech
It's 5:40 on a Thursday and Jake's trying to kill a payments bug before he picks up the kids. He grabs the whole file and drops it into his AI coding assistant — quickest way to get unstuck. What he didn't clock: line 30 has a live payment key, and the test data is real cardholder names. Without a gate, that may be sent to an external AI service without a reliable internal record. With his AI assistant routed through Proofpane, the key and the card fields are wiped before the request leaves, the payments repo is on the "never leaves" list, and there's a quiet log line showing what got caught. (Tools that reach the internet on their own instead of through the gate are logged, not scrubbed — so wiring them through is the point.)When the bank asks, "has our data ever gone into an AI tool?" — the answer is a record, not a guess.
The underwriter
insurance
Mel in underwriting has forty quotes to clear by Friday. The firm's deal with staff is simple: use the approved AI assistant, not random tools. She pastes a customer's medical history in and asks for a summary. Proofpane replaces the name and NHI number with placeholders while preserving the diagnosis, treatment and medication the model needs. Mel still gets a useful underwriting summary, direct identifiers never leave, and the receipt records exactly what was removed and retained.Quarterly privacy check goes from a witch hunt to ten minutes.
The clinic administrator
healthcare
Tuesday morning, Priya at the clinic has eleven referral letters to draft before lunch, so she pulls each one straight from the patient notes into the practice's AI assistant. Names, NHI numbers, dates of birth — Proofpane swaps the configured identifiers for placeholders before the request goes anywhere, while the clinical notes the letter actually needs still get through, reducing the repetitive drafting work.If the Privacy Commissioner ever comes asking, the practice can show which configured identifiers were masked before the request left.
The junior lawyer
law firm
Four o'clock, a partner drops a 60-page supply agreement on a junior: summary by tonight. Into the AI it goes — privileged material, both parties named, deal terms and all. Proofpane masks the party names and the numbers before the request leaves, and logs the event. The summary still lands by six. And when a client's GC asks, "do your people put our contracts into AI?" — the honest answer is "yes, through a gate that masks configured party identifiers and selected commercial fields, and here's the record."That's an answer that keeps you in the running. "We ban AI" doesn't, because nobody believes it.
The HR advisor
any industry
End of review season. Sam in HR has sixty performance summaries to tidy up and a stack of CVs to screen — real names, salaries, a manager's blunt comments, all heading into an AI to "make it read better." Proofpane swaps the names for placeholders and holds back the salary column before anything leaves. Sam still gets the tidy paragraphs.The record shows which names and salary fields were withheld, and what was transmitted.
The salesperson
any industry
Deal closes Friday. Tina exports her CRM notes on the prospect — including the confidential pricing from their last contract — and asks AI to smash out a proposal. Proofpane masks the client names and the numbers on the way out; the proposal still writes itself.Six months later, when that prospect's procurement team asks what went to a third-party AI service, the answer is exactly what was transmitted and which fields were masked.
Inside their automations — the AI buried in the workflows
Loan pre-check
banking / lending
A lender runs an automated flow: application in, AI does the first pass, the obvious yes/no gets sorted, humans see the rest. One Tuesday it starts quietly declining anyone with a gap in their income history — nobody told it to; it just drifted that way. Without a gate, that's three weeks of wrong declines and a "please explain" letter from the regulator that nobody can answer. With Proofpane on that step: the calls your rules flag as borderline pause for a human, the AI only sees the fields it needs, and every decision is recorded with its reason — so the record, plus any monitoring you configure, makes a shift like that inspectable rather than invisible.If a regulator asks how a decision was made, the inputs, the rule that fired and the reason are on the record.
Claims triage
insurance
Storm week. Two thousand claims land in three days, and the AI triage flow is the only reason the team is keeping up — it reads the claim and the photos, calls fast-track or review. Buried at claim #1,384 is a $46k payout dressed up to look routine. Proofpane enforces the rule you set — anything over $10k, or outside the usual pattern — so it stops and waits for a person. It stopped. There's a record of who looked and why they said no.That's the kind of catch the whole thing exists for.
Support replies & refunds
retail / e-commerce
The support flow answers customers and issues refunds — AI drafts, system sends. Works great, right up until someone on the internet figures out that if you word the complaint just right, the bot pays out. Proofpane caps what the AI can refund on its own, pauses anything above that for a person, checks replies against your returns policy, and records every payout it approved.Finance can trace every payout and its approval path.
Citizen requests
government / public sector
A council flow uses AI to sort and summarise incoming requests. Eight months later an official-information request lands: "show us how these were handled." Without records, that's a bad month. With Proofpane, it's an export: here's every AI decision, here's where personal details were masked, here's who approved the exceptions.The masked fields and the approval trail are on the record — paper trail intact, nobody's weekend ruined.
Patient-message triage
healthcare
A provider's flow sorts incoming patient messages: urgent to the front, routine to the queue. The nightmare is the chest-pain message that gets filed as routine. Proofpane enforces the rules you set — urgent-keyword hits and anything the model can't cleanly classify route to a human — and records every sort decision with what the AI saw.If one is ever missed, the clinic can show the input, the output, which rules fired and the approval trail — defensible and fixable, instead of a mystery and a headline.
Invoice reading
accounts payable
The AP flow reads incoming invoices and queues the payments. One day a supplier's "invoice" turns up looking pixel-perfect — except the bank account number has changed. The AI reads it just fine; that's exactly the problem. Wire it the check — account against your recent payment history, amount against the usual — and Proofpane holds the ones that trip it until a human clicks yes, keeping a record of every hold and release for the auditor.Invoice fraud — one of the most boring, most expensive scams there is — caught by a rule and a second pair of eyes, on the record.
Starting clean — no AI stack yet? Even better.
Proofpane isn't only a gate in front of tools you already own. It ships with the AI built in — so a team starting from zero starts governed.
No workflow platform yet? Proofpane includes governed skills and workflow orchestration for supported use cases — reusable skills that compose into governed workflows, each one born with the policy gate and the evidence trail already on.
Staff don't use coding agents? They don't have to learn three tools. Proofpane's own chat window does the everyday work people reach for those apps for — ask in plain English, the work gets done, and every action is governed and on the record by default.
Retrofitting governance onto tools you already bought is good. Starting on a platform where governance is built in is better — there's nothing to bolt on later.
Coverage & bypass
Every story above depends on one thing: the AI can’t route around the gate.
Governance an agent can simply avoid is not governance — it’s a suggestion.
Jake’s API key is only scrubbed if his coding assistant’s traffic goes through a
gate; if he opens a second tool that doesn’t, the same key leaves unrecorded. This is
the hardest problem in the category, and it is the reason our surface looks wide.
Why the surface is wide: it was derived backwards, not collected
Proofpane is designed backwards from an endpoint: an enterprise strategic agent an
organisation can safely trust with real operating work. Ask what that must be made of —
governed skills, versioned SOPs, per-step evidence, human authorization, measurable quality
— and you get, item by item, the design spec of the governance layer. Ask where the
work actually happens and you get the integration list: on laptops (coding agents
and desktop AI), inside automations (workflow platforms), and in direct API
calls. Those three are not three products. They are the three execution paths an agent
can take — and a record with a hole in it can’t ground anything downstream.
The breadth is the coverage requirement, not scope drift.
The tool layer — physical block. For actions an agent
takes through an MCP server, the daemon is its hands: allow, deny, hold for human
approval, or cut the server entirely. This is the only layer where an action can be
stopped before it happens.
The model layer — universal meter. Any agent using
your own API key can be pointed at the egress gateway: every model call is metered,
DLP-scrubbed and recorded, whatever the client. One line of config, no per-call
cooperation from the tool.
The platform layer — execution audit. n8n, UiPath,
Power Automate, Zapier, Make and Agentforce each get a mapped wiring recipe, so a
workflow’s AI steps and its run lifecycle both land on the same record as the
laptops.
Shadow AI — find what isn’t wired. A coverage
scan reads your local AI-client configs and reports which servers run direct, ungoverned.
Detection is automatic; routing them through the gate is one deliberate config step.
What we can’t reach — and why we say so on the page
Some paths stay out of reach by design. A coding agent’s own built-in file and
shell tools don’t route through us — reaching them would mean OS-level hooks or
TLS interception, the new attack surface your security team would have to certify, which we
deliberately don’t ship. On those paths we meter and record rather than block.
Coverage is exactly what’s connected.
So the boundary itself is made into evidence. Daemon pairing, disconnect, an app’s
monitoring being switched off, even an ungraceful crash’s write gap — each lands
on the same tamper-evident chain. “Governance was off here, from this time to that
time” becomes a signed, dated fact rather than a silent hole. We don’t claim
completeness; we make incompleteness visible and non-repudiable. That is a stronger
promise than a coverage claim nobody can check — and it is why the depth per client is
published in a matrix instead of averaged into one number.
Breadth here is a delivery question, not a design one: this platform is ~12 weeks old and
the work is public — over 1,200 merged pull requests on the repository, and an
architecture published under CC BY 4.0 for anyone to check. What that pace does
not buy is enterprise maturity: no SOC 2 yet, no third-party penetration test yet, no
customer case studies yet. Both halves are on the Trust Center and the
Proof Index, stated plainly.