⌂ Atlas
govrn · internal · integration roadmap

The engine & the standard.

Aperture — the govrn.ai engine. The official integration roadmap, for Richard & Joe. Enter the access key.

Invalid key
govrn / internal · ↖ walkthrough · merge map ↗ Official roadmap · for Richard & Joe · June 2026
One company · one platform · the engine and the standard

Aperture.

The govrn.ai engine.

Aperture is govrn.ai's engine — the deterministic system of record the standard reads to see, prove, and certify. This is the roadmap for how we officially integrate the two into one platform, with the engine brand intact, from what's built today to the merged product taken to market. Two builds, one conviction — an AI estate you can't see, you can't govern — converging by design.

The standard sees it and proves it. The Aperture engine runs it.
01 · The foundation

The engine is built. The standard is proven.

This isn't a concept — both halves exist today, and the seam between them is already designed. That's why the integration is a build plan, not a research project.

govrn — the standardsee · prove

The judgment layer — what an auditor, board, or regulator will accept.

Three-lens assessmenttechnology · security · AI — a productized, repeatable baseline
Standards crosswalksNIST AI RMF · CSF 2.0 · ISO/IEC 42001 · EU AI Act · OWASP · ATLAS
Independent attestationaudit-ready evidence, certified via accredited third parties — never self-certified
Product-AI reviewthe AI a company ships — the part a regulator and a PE owner care about most
Aperture — the enginerun

The deterministic system of record the standard reads from.

Deterministic measurementno model in the measurement path — every number reproducible and audit-defensible
Pointers, not payloadsmetadata only, enforced in the architecture — survives a security review
The shadow-AI bucketthe AI spend no one owns, surfaced with a dollar figure — the wedge
Attributed cost & usageevery dollar resolved to a team through inspectable rules; 15 tests green

Real today: the deterministic engine + the designed evidence interface (govrn-interface). Staged honestly: connectors are built and ready for first live integration; the readout runs today on a representative org and goes to measured the moment it connects. We say modeled until then.

02 · How they are one platform

One record. Two lenses. The engine runs it; the standard proves it.

The integration is clean because the two halves were built for it: the engine produces a single attributed record of fact; the standard reads a typed, read-only view of that record to render posture and attest. The standard calls the engine — never the reverse.

Aperture — the engine

Computes the truth: the attributed event record, the rollups, the shadow bucket, freshness signals. Metadata only.

evidence interface engine ── evidence ──▶ standard read-only · typed · no payload
govrn — the standard

Renders the posture and the verdict: conformance, the crosswalks, the attestation. The judgment the board accepts.

The credibility feature — independence by design. Even as one platform, the arm that attests stays structurally independent of the arm that builds and runs — the same separation that lets an auditor sign books they didn't keep. The engine emits evidence; the standard judges it. That's not a constraint on the merge — it's the exact property that makes the combined verdict worth something to a board, an auditor, or a regulator. We keep it on purpose, and it raises what the engine is worth.

The annuity — why this is a relationship, not a sale. Operate → emits evidence → re-assess → re-baseline, and the loop closes. The longer the engine runs an estate, the deeper the proven relationship: an attestation is only valid against a fresh record, so continuous measurement isn't an upsell — it's what keeps the proof true. The engine running is the ongoing relationship, and the accumulated record is the thing a competitor can't replicate overnight.

03 · The team & the entity

Who backs this — and why the structure comes first.

Before the Kelly partnership, we stand up the entity: the team, the brand, the company. When this is vetted — by an investor, an enterprise buyer, or Microsoft — the answer to "who's behind it?" is a bench of AI-first, enterprise-grade operators, and a structure built so the only rational move is to license it.

The thesis — entity first, then leverage. This weekend we build the team, the brand, and the company. The goal is a structure where there is no other choice than to partner with us — a licensing play for the process, the product, and the rights to the brand at enterprise scale. Kelly / MCG Kelly Services is the first channel, not the destination. The destination is enterprise licensing — and the horizon is Microsoft.
04 · The integration roadmap

From today to the merged platform.

Seven moves, each shipping real value, each reading from the same record. Owners are marked — govrn leads judgment, engine is Aperture, co-build is together.

Phase0

This weekend — stand up the entity

Form the company: the team, the brand, the structure. The engine is built, the standard is proven, the seam is designed — now lock the brand (Aperture is the govrn.ai engine, green is its color) and align the language across the brief and docs (modeled until connected; "synthetic reference," never "live demo"). One entity, one honest story, before any partner conversation.

the teamprinciple · entity first
Phase1

The seam + first live connection

Spec the evidence interface as a typed, versioned, content-incapable contract — the load-bearing joint, with a named owner who keeps the two halves in sync as they evolve. Run the first connector against a real API. The meter goes from modeled to measured.

co-buildprinciple · the contract is the keystone
Phase2

Grace Hill — the proof gate

One regulated account, end to end: assess → design → the engine stands up → operate → re-baseline. Proves the arc, proves the interface is real on live data, and covers both risk surfaces — the AI Grace Hill uses (the engine's home turf) and the AI it ships (the standard's). Nothing public unfreezes until this proves the engine runs live.

govrn leadsengine runsgate · proof before market
Phase3

Engine hardening — enterprise-ready

Multi-tenant isolation, SSO/RBAC, the immutable audit log, a secrets vault, per-tenant pricing. The engine clears the exact bar the standard certifies against — so the platform that proves governance is itself a model of it. Account two can be onboarded safely.

engineprinciple · meet the standard we sell
Phase4

The governance lens on the engine

Conformance scoring, the AI-BOM, policy-as-code shipped observe-first, the crosswalks — the standard reading the live record to render posture continuously. The dashboard's honest "not connected" becomes real-time truth.

co-buildprinciple · one record, two lenses
Phase5

Attestation + the annuity

Independent attestation on the fresh record, signed evidence packs, the regulatory crosswalks. Freshness keeps the proof valid; portability keeps it the customer's. The recurring proven relationship — services in the front, the engine underneath.

govrn · independentprinciple · fresh record, portable evidence
Phase6

License it — enterprise & Microsoft

With the proof in hand, the platform becomes the licensable asset: the process, the product, and the brand rights. Kelly / MCG is the first channel; the horizon is enterprise licensing and a Microsoft play. See it, prove it, run it — no competitor covers all three on one record, which is exactly what makes the license worth paying for.

togetherprinciple · build the only choice
05 · Next steps

What we do next — the first ninety days.

Concrete moves, with a first owner each. None of these wait on the others; the first three start now.

Formalize the entity, roles + contribution in writing — early and clean. One company, one platform, one team — so the paperwork is light, not adversarial. Writing down contribution, ownership, and the engine/standard/SME roles while everything is early is the cheapest insurance we'll ever buy, and it protects the work everyone is putting in.
06 · The opportunity

The largest opportunity is to build this now — together.

See it. Prove it. Run it.

No single player covers assessment, attestation, and a live deterministic engine on one record. The standard makes the engine's numbers provable; the engine makes the standard's verdict continuous. Neither half is the whole — together they're a category no incumbent can match. The window is open now, both halves exist, and we hold both. This is the moment to build it.

The shape of the play: stand up the entity, assemble the bench, prove it on one account — then license the process, the product, and the brand at enterprise scale. govrn.ai is the platform and the standard; Aperture is the engine, brand intact. Kelly / MCG is the first channel; enterprise licensing is the model; Microsoft is the horizon. Two doors into every account, one source of truth, an annuity that compounds — and a structure where partnering with us is the only rational move.