Every AI surface in OllieSafe runs behind the same governance frame — jurisdiction resolution, verified citations, confidence tiers, and human control. Chat, photo analysis, voice capture, and drafting all answer to the same rules.
Chat, photo analysis, voice capture, and drafting all run behind the same four layers. None of them are optional, and none of them are policy PDFs — they are how the product works.
01
Jurisdiction resolution
Before the AI answers, it resolves the jurisdiction of the physical work — the incident case first, then the establishment, then tenant headquarters, then the federal fallback. Where a jurisdiction has no authored vocabulary yet, the AI answers from the federal floor and discloses the fallback.
Proposed regulatory citations are checked against retrieved regulatory text before they persist. A citation that cannot be verified is flagged in the artifact, and ungrounded identifiers are structurally blocked from becoming part of your record.
Ask OllieJurisdiction-resolved
What does a silica exposure control plan need to cover for this site's scheduled concrete cutting?
A written exposure control plan must identify the tasks involving silica exposure and the engineering controls, work practices, and respiratory protection for each task — designate a competent person, and restrict access where required.
29 CFR 1926.1153 · VerifiedGrounded in retrieved text
Suggestions become records only after a person reviews and accepts them.
03
Confidence tiers & human control
Every AI feature class carries one of three confidence tiers — INFORMATIONAL, ADVISORY, or DETERMINATIVE. Determinative outputs route to a human review queue before anything acts on them, and every reviewer decision is audit-logged.
Human review queue3 awaiting
ADVISORYDraft JHA from scan finding
DETERMINATIVERecordability determination
ADVISORYCitation for heat program gap
Reviewer decisions are audit-logged on a tamper-evident chain.
04
Tamper-evident record & eval-gated change
Advisory and determinative outputs land in a hash-chained AI decision log — append-only and tamper-evident. Model changes ship through a 1,435-case governance evaluation across 37 AI feature classes.
Evidence chain · append-only
Incident finalized9f2c…a1d4
AI decision logged5b7e…03f9
Evidence attachedc48a…77b2
Inspection bundle exports with a signed manifest — every file hash-verifiable.
The boundary
What the AI will never do.
Guardrails only count when they are structural. These are enforced in the product, not promised in a policy.
Never files a report or closes a record on its own
The AI prepares drafts and determinations. Acting on them — including any transmission — remains your explicit act.
Never persists an unverifiable citation without flagging it
A citation that cannot be verified against retrieved regulatory text is flagged in the artifact — visibly, not in a footnote.
Never acts on a determinative output without a human decision
Determinative outputs wait in the review queue until a person approves or rejects them — and that decision is audit-logged.
Never silently answers for the wrong jurisdiction
When authored jurisdiction content is not available, the AI answers from the federal floor and discloses the fallback.