How Complyee works

Complyee turns the policy documents a company already has into a searchable, governed library — and answers questions with grounded responses that can be checked against the source. This page walks through the chain, from upload to answer, and explains where the independent policy engine draws the line.

What Complyee is

Complyee is a policy information and interpretation service. It takes the documents a company already has — policies, guidelines, instructions — and turns them into a searchable, structured library that can answer questions with grounded, cited responses.

Complyee describes what the documents say. It does not decide who may act on an answer. That judgement is left to a separate, deterministic policy engine — Agent Control Room — which evaluates permissions, applies precedence, collects human approvals and issues the final permission for any governed step. Keeping the interpreter and the authority apart is a deliberate design choice: the thing being governed is not the thing granting permission.

From upload to a searchable library

An administrator uploads documents into their workspace. Every document is stored in storage dedicated to that workspace alone, never pooled with another customer's material, and is recorded with its file details and a fingerprint of its exact content.

Each document is placed in one or more business areas — such as HR, information security, finance or legal — so retrieval can be scoped to the part of the organisation the question concerns.

Administrators can also state whether a document is a binding policy, an exception, guidance or a procedure, and when it takes effect or expires. Those distinctions let an assessment consider only material currently in force and prevent guidance alone from being treated as permission or prohibition.

The document is then indexed by an enterprise search service. From upload to answerable, a document moves through explicit states: uploaded, indexing, indexed — or failed, with the reason shown to administrators rather than hidden.

Every document gets an abstract

Once a document is indexed, a background curator writes a structured abstract for it: a dense summary of what the policy covers, the rules and exceptions it states, who is responsible for what, and a set of keywords that describe its subject.

The abstract is what makes coverage questions fast and reliable — it is also how Complyee knows what a workspace has and has not got, without searching every document every time.

Abstracts are built deterministically. The work is bound to a fingerprint of the exact document it describes: if a document has not changed, no work is repeated; if it has, the old abstract is replaced. Each document is worked on by one curator at a time, so parallel jobs can never duplicate effort or race on the same document.

Agent work is governed, not assumed

The curator is an agent: software acting on its own rather than a person pressing a button. No agent in Complyee decides for itself what it is allowed to do. Before every single step — reading a document, submitting content to the language model, writing the result back — it asks the independent policy engine for a decision.

The engine answers in one of three ways. A permit lets the step proceed. A refusal stops it, and the reason is recorded. An approval requirement pauses the work for a person: the exact work is frozen, nothing is sent to the model, and the step only resumes if a workspace administrator grants it — and then only for that exact, unchanged piece of work, within a short window.

Every governed step and every decision appears in the workspace audit trail, whether the run was started by an administrator, by an integration, or automatically when a document finished indexing.

How a question is answered

When someone asks a question — an employee in the app, or a system through the API — Complyee first works out what kind of question it is.

  • Coverage questions, answered deterministically

    "Do we have a travel expense policy?" or "What guidelines exist for data retention?" are answered from the library's abstract and keyword index — a direct lookup, not a generation step. The answer lists the policies that exist, their scope and their summaries. Because nothing is generated, this path cannot invent a policy that is not there.

  • Interpretation questions, answered from evidence

    "Can I expense a train ticket for a client dinner in London?" needs the actual text. Complyee retrieves candidate passages from the workspace's own search index — scoped to the business areas in use — and ranks them by how much they actually bear on the question. A bounded set of the most relevant passages from several documents, never just one, is assembled as the evidence.

Grounded answers, or an honest no

The answer is generated by an AI model configured per workspace — including which region it runs in. Its instructions are strict: answer only from the evidence in front of it, and never extrapolate.

Every claim carries a reference marker that maps back to the document and passage it came from, so any statement in an answer can be checked against the source in one click. If the evidence does not contain the answer, Complyee says so rather than filling the gap — being told "your documents do not cover this" is a feature, not a failure.

Follow-up questions are supported: recent conversation is summarised so the assistant understands context, without carrying every earlier word forward.

Evaluating proposed actions

An agent or decision system can ask a different kind of question: whether a proposed action is supported by the workspace's policies under a set of facts that the caller identifies as trusted. Complyee handles that as a staged assessment rather than as an ordinary chat answer.

  • 1. Find the relevant policies

    The document abstracts are consulted first to identify which policies cover the action. If no abstract covers the subject, the result is insufficient rather than a guess.

  • 2. Read what is in force

    Complyee retrieves relevant passages from those documents, respecting business areas, effective dates and each document's role as policy, exception, guidance or procedure.

  • 3. Return a structured outcome

    The model evaluates the passages and returns one of five outcomes: supports, prohibits, requires approval, insufficient or conflict, together with its reason, conditions, assumptions and citations.

  • 4. Check the evidence and exceptions

    Every quoted excerpt must be found in the retrieved source wording or it is removed. A supporting result triggers a second search for exceptions, exclusions, prohibitions and approval requirements; this check can lower the result but never raise it.

  • 5. Apply strict mode when needed

    In strict mode, a supporting result cannot stand if it depends on an assumption or a condition not verified by the trusted facts. It becomes requires approval instead.

A frozen record of the evidence

Before an assessment is returned, Complyee stores an immutable record of the proposed action, trusted facts, structured outcome and cited evidence. The record also carries a fingerprint of the exact in-force policy library used, so a later review can tell whether that library has changed.

The record is evidence for the customer's decision process, not a grant. An external authority or human reviewer decides what happens next.

Answers in your language

Questions can be asked in any of the languages Complyee supports, and documents can be in any language. A question in Swedish against English policies — or against policies written in German — is understood and answered in the language of the question.

The multilingual index also powers coverage questions: the abstract keywords are matched across languages, so "resepolitik", "Reiserichtlinie" and "travel policy" lead to the same document.

Programmatic access

Everything the app can do with the library is also available through a single API gateway: asking questions, assessing proposed actions, retrieving frozen assessment records, checking a workspace pairing, listing documents and abstracts, and uploading or removing documents. Access uses per-workspace keys with fine-grained scopes — a key that may only ask questions cannot delete documents — and keys are stored only as hashes.

The API page documents every operation, the Agent Control Room pairing pattern, and the machine-readable description of Complyee as an AI system that an inventory or governance tool can pull.

The division of responsibility

Together with Agent Control Room, the two services form one governed chain:

  • Complyee — heuristic interpretation and evidence

    Holds the documents, builds the index and abstracts, interprets questions and proposed actions against the evidence, and returns grounded answers or advisory assessments with verified citations.

  • Agent Control Room — governance and authority

    Holds the deterministic rules. Evaluates whether an agent may perform a step, enforces precedence and constraints, routes high-risk steps to a human approver, and issues the final, bound permission that any governed step needs before it happens.

The flow at a glance

document upload
      │
      ▼
workspace storage ──▶ search index
      │
      ▼
curator agent ──▶ policy engine (permit / refuse / approval)
      │                    │
      │        approval granted ◀── workspace administrator
      ▼
document abstract + keywords + dates and role
      │
      ├─▶ user question
      │      ├─▶ coverage ──▶ deterministic answer from abstract index
      │      └─▶ interpretation ──▶ passage retrieval ──▶ grounded answer
      │
      └─▶ proposed agent action
             └─▶ abstract routing ──▶ in-force passage retrieval
                    ──▶ model outcome ──▶ evidence and exception checks
                           ──▶ frozen advisory assessment ──▶ ACR decision

This page describes the pipeline as it behaves for every workspace. The controls that keep one customer's material separate from every other customer's — and from attackers — are covered separately on the security page.