SECURITY & GOVERNANCE

Built for the 7% who see impact: agents that survive the audit.

CFOs don't buy autonomy; they buy traceability. Every Corin decision is reconstructible — model version, inputs, reasoning, approval, posting — in a ledger designed around how audits actually work.

ACCESS CONTROL

Who can approve what.

Role-based access down to the decision type and entity. The same matrix governs the app, the API, and the MCP tools.

Sales rep

Simulate quotes and read decision cardsown accounts
Approve quotes up to $25kledger entry written
Approve quotes above $25kroutes to manager
Change autonomy levelsadmin only

Sales manager

Approve quotes up to $100kledger entry written
Override the margin floordual control
Edit team policy boundsversioned
Post payments or move moneynever an app action

Finance controller

Approve credit memosledger entry written
Release a credit holddual control
Set entity-level autonomywith admin
Export the audit ledgerread-only

Matrix shown is the design baseline; your tenant configures its own.

THE AUDIT LEDGER

Complete traceability, COSO-friendly.

Model and version, prompts and inputs, reasoning, the human who confirmed, and the postings that resulted — retained and queryable. When the auditor asks 'why did this happen', the answer is a lookup, not an interview.

timeactoractiongatestatus
11:41:07m.chenQuote Q-2291 approved and releasedmodel v2026.08.3humanapproved
11:38:52policy:credit-holdOrder held — account on credit holdrouted to controllerpolicypending
11:20:14j.okaforCredit memo CM-1180 approveddual control satisfiedhumanapproved
THE GUARANTEE

Corin never moves money, signs, or sends without your confirmation — until you tell it to.

Autonomy levels are explicit, per decision type, and changeable at any time. Auto mode is bounded by policy you write — value limits, counterparties, terms ranges — and still logs everything.

EU AI ACT

Scoped, not hand-waved.

Corin supports human decisions in sales and finance operations; it is not credit scoring, biometric, or critical-infrastructure AI under the Act's high-risk annexes. Human-in-the-loop gating, logging, and versioning are built to make your conformity assessments straightforward. We track the Act's timeline and will update this page as guidance lands — this is a scoping statement, not legal advice.

COMPLIANCE ROADMAP

Named milestones, honestly labeled.

None of these are current today. They are commitments with a sequence:

ROADMAP

SOC 2 Type II

Audit engagement is the first compliance milestone after general availability.

ROADMAP

Microsoft 365 Certification

Targeted with the Teams approval surface.

ROADMAP

Marketplace listings

SAP Store and Infor Marketplace listings follow their respective certification processes.

DECISIONS, WITH RECEIPTS

See a decision simulated before it's made.