Loading
Loading
Every decision Bob makes is logged with reason codes and the sources it cited, gated as advice or information by rules your firm authors, and held for a licensed adviser when it counts. Built around the FMA’s advice rules and the Privacy Act, not bolted on afterwards.
Indicative health cover, Ava Chen
AGE_BANDProposed health loading, Ava Chen
DISCLOSED_CONDITIONCompliance is not a peer agent a router can choose to call. It is an always-on wrapper every hand-off passes through, so logging, the advice gate, and disclosure are non-optional on every path.
Compliance is not a step Bob can skip. Every agent hand-off passes through one wrapper, so logging, disclosure, and the advice gate apply on every path, by construction rather than by good intentions.
No path around it
Each decision is written to an append-only record with structured reason codes and the exact sources it cited. Edits and deletes are revoked, so the log is the system of record, designed to be exported for a regulator.
Reason codes + cited sources
Deterministic, FAP-authored rules decide whether an output is regulated advice or plain information. Information can be answered; advice is held for a licensed adviser. It is a licensing rule, not a model's guess.
Deterministic, not a prompt
An adverse decision (a decline, loading, exclusion, or cancellation) is never auto-actioned. It waits for sign-off from an adviser whose FAP scope covers the line, and the whole thing sits on the record.
Never auto-actioned
An example of the decision log for one household. Each entry carries the reason codes, the sources it cited, the model that handled it, and whether a licensed adviser has signed it off. The adverse decision is held, not actioned.
A quote for Ava’s cover is logged and clearly indicative. A proposed health loading is an adverse decision, so it never goes effective on its own: it waits for a licensed adviser whose FAP scope covers health, with the whole reasoning attached.
The log is append-only. Advice-producing records are written through a single wrapper, and the right to edit or delete them is revoked, so the trail is the system of record and is designed to be exported for a regulator.
Indicative health cover for Ava Chen (child), $28/mo.
Proposed health loading on Ava Chen's cover.
FSLAA makes almost anything tied to a client's circumstances regulated advice, and only a licensed person can give it. Bob runs a deterministic, FAP-authored gate on every output: information is answered and logged; advice is held for your adviser. The rule is code your firm can read and test, not a model deciding on the fly.
“What does my health cover include?”
Answered by Bob, disclosed as AI, logged.
“Should I increase my life cover?”
Regulated advice waits for a licensed adviser under your FAP.
Health and other sensitive data is routed by class before any model sees it. Anything sensitive goes to an in-region, DPA-backed model and never offshore. If that in-region host is unavailable, Bob fails closed rather than quietly routing somewhere it should not go.
A general chatbot answers with no record and no accountability. A shared inbox is a record only if someone keeps it. Bob makes the trail, the gate, and the sign-off part of how it works.
| A general chatbot | Bob | A shared inbox | |
|---|---|---|---|
| Every decision logged with reason codes | No | Yes | Manual notes |
| Cited sources on every answer | No | Yes | No |
| Advice held for a licensed adviser | No | Yes | If someone remembers |
| Adverse decisions never auto-actioned | No | Yes | By habit, not design |
| Sensitive data kept in region | Unclear | Yes | Depends on the tool |
| Append-only trail, regulator-exportable | No | Yes | No |
| Tenant data isolated by firm | No | Yes | Shared-mailbox risk |
Bob logs, gates, routes, and flags. A licensed adviser reviews, signs off adverse decisions, and binds. The accountability sits with a named person, always.
Bob is built so that being auditable is the default: the decision log, the advice gate, in-region routing, and tenant isolation are part of the architecture, framed around FSLAA and the FMA's advice rules and around the Privacy Act and its Health Information Privacy Code. We are early, and we will not claim a formal security certification we do not have. What we do claim is simple and checkable: every decision is logged with its reasons and sources, adverse outcomes wait for a licensed human, and sensitive data stays in region.
Every decision Bob makes is written to an append-only log: a structured set of reason codes, the exact sources it cited, which model handled it, the data class, and whether a licensed adviser signed it off. It is designed to be exported for a regulator, and it cannot be quietly edited or deleted after the fact.