Eshalu
How it works

From “we use AI” to a reviewed record

Simple on the surface. Underneath: activation rules, versioned evidence, recorded reviewer decisions and disclosure-scoped outputs.

1

Profile

Register each AI system: purpose, owner, lifecycle, exposure, data and supplier position.

2

Activate

The relevant control set and questions switch on from the use case — not a fixed checklist.

3

Evidence

Upload or reference what proves each control. Version, hash and custody are recorded.

4

Review

An authorised reviewer challenges weak evidence and records a decision with a rationale.

5

Report

Governed outputs generate for each audience, bound to the version that was checked.

The strictness sits underneath

A human decides

Nothing becomes a finding without an authorised human decision. Every automated finding must be dispositioned as confirm, amend or hold — and a held finding blocks completion.

Versions are frozen

A submitted assessment is immutable. Changes create a new version with lineage back to the one it supersedes; the earlier version stays readable.

Results are computed server-side

The browser renders and refuses. It never evaluates a control, derives a band or reaches a conclusion.

Assessment is a team activity — and it is governed

Real assessments involve several people. The workspace splits the work by section without losing who did what, or who approved it.

Owner

Runs the workspace, manages participants, submits.

Contributor

Answers only the sections delegated to them.

Approver

Signs off that a section is ready — and never edits it.

Observer

Read-only visibility. No mutation rights.

No lost answers

Every write is version-guarded. Two people editing the same section cannot silently overwrite each other, and unsent work is never discarded without being shown to you.

Exact-position resume

A participant returns to the exact system, section and question they left — after a logout, on any device.

Server-assembled submission

The submission is built from governed workspace state, not from whatever the browser posts.

Frozen on submit

A submitted workspace and all its sections become immutable. Further work creates a new version.

Assurance that survives change

Systems change, suppliers change, rules change. The record is built to notice, and to require a human to approve what happens next.

1

Detected

A change to a registered source, system or supplier is recorded against its own register entry.

2

Classified

Content is separated from provenance, so a formatting change is not treated as a substantive one.

3

Proposed

A material change becomes a proposal with lineage back to the source that triggered it.

4

Approved

An authorised owner approves. Nothing activates automatically, ever.

5

Activated

The change takes effect once, with its lineage recorded and prior versions preserved.

Stale outputs are surfaced

When an upstream source moves, dependent reports and results are marked stale rather than left quietly wrong.