Skip to main content
Greyquill
Back
Product · Govern tier

GQ Govern.
Controls that have
to prove themselves.

Regulated enterprises rarely fail audits for lack of dashboards. They fail because the rule lived in a wiki, the exception got granted over email with no record, and nobody could produce the evidence when someone finally asked for it. GQ Govern stores the rule, records the exception, and keeps the evidence somewhere it can actually be produced on request.

workflow · promote-to-production · step 4
Data classification gatePassed
Model risk sign-off gatePassed
Disparate-impact thresholdHold for approval
Routed to Model Risk · 2 approvals required · evidence pack drafting
The dilemma it solves

A rule nobody can produce is not a rule.

Policy scattered across wikis. Exceptions granted over email with no record anywhere. Evidence assembled by hand the week before an audit, if it gets assembled at all. GQ Govern stores each one and can produce it on its own when asked.

What GQ Govern offers

Five modules and a library that grows with you.

The two below have a visual, because a passing control and a documented exception are easier to see than to read about.

01

Policy registry

A policy is authored, versioned, and approved like a record. A new save is a new version; anything that ran under version 3 stays explainable under version 3.

02

Workflow gates

A workflow names its policy gates. GQ Govern evaluates them: pass, hold for approval, or refuse, with the policy named.

03

Evidence

A pass names the policy actually enforcing it, in the words the person who set it up would use, not just a green checkmark.

04

Exceptions

A miss gets a reason, a compensating action, a target date, and a name tied to a role, CFO or DPO, not just whoever was logged in.

05

Diagnose

AI-maturity assessment, model inventory, and document intelligence over the policies a customer already has.

06

Standards library

Five standards checkable today. Dozens more mapped by domain and region, so a workspace can find the one it actually needs.

How it works

Two controls, the same catalogue, two different outcomes.

Control · GDPR · Art. 5
PII is classified and masked before usePassing
checkedno PolicyHolder record carries an unmasked national_id or email
enforced byMask PII · EU strict, applied on every intake workflow
The first line is a fact the verifier found. The second is why it's true, named once by the person who set it up.
Control · disparate-impact threshold
Documented exception
Reason
Bias audit for the underwriting model is still in progress.
Compensating action
Manual review on every declined application above ₹2L.
Target date
2026-09-30
Approved by
Chief Risk Officer
Past the target date, this stops reading as an exception and starts reading as overdue.
How an engagement starts

Diagnose is the front door. Govern is what it becomes.

Before an enterprise has a policy registry, it usually just has a question: how mature is our AI use, really. GQ Govern's Diagnose role answers that first, with an AI-maturity assessment and score, a model inventory of what exists and who owns it, and document intelligence that reads a customer's existing policies and drafts registry entries for a person to confirm. What Diagnose produces becomes the first version in the registry. It doesn't get filed away as a report nobody opens again.

Where it fits

The govern tier, between the data and the action.

GQData makes the data underneath trustworthy. GQ Govern turns that trust into an enforceable, evidenced rule. GQ Agents asks GQ Govern's gates before every governed step, and GST Co-Pilot is what that looks like running in production.

Make the rule something the system can produce.

Thirty minutes. Bring your hardest policy or audit question. We'll tell you, honestly, whether GQ Govern solves it and what the path to production looks like.