Skip to main content
Back to Documentation

Getting Started with HAIEC

Evidence-bound assurance for consequential AI systems

The HAIEC Workflow

Define, connect, collect evidence, map actions, evaluate, assure, and verify.

1

Define

5 min

Create or select an AI System in HAIEC. HAIEC organizes evidence and assurance around a bounded AI System, so every evaluation, action, and receipt is scoped to a specific system.

Go to AI Systems
2

Connect

10 min

Register and connect the supported evidence sources relevant to that system. Examples include source repositories, application access, provider/IAM evidence, and runtime evidence where connected. Registered does not mean connected. Connected does not mean evaluated.

View Evidence Sources
3

Collect Evidence

Varies

Run or attach supported evidence producers: static analysis, runtime evidence where connected, policy, provider/IAM evidence, or self-reported/uploaded evidence where supported. Missing evidence remains missing — it does not silently become PASS.

View Evidence
4

See the System Constellation

10 min

Review what the AI system can reach: identities, application access, credential evidence, actions, APIs/tools, potential consequences, policy context, and unknown relationships. HAIEC does not promise universal discovery — the map shows what available evidence establishes.

Open System Constellation
5

Run Evaluation

Varies

Use Evaluation Runs to coordinate evidence collection and evaluation across supported producers. An evaluation run produces operational evidence and scores. An evaluation run is not an Assurance decision.

Go to Evaluation Runs
6

Assure

5 min

Review the canonical Assurance outcome: ALLOW, REVIEW, or BLOCK. ALLOW means the system is permitted within the evaluated scope and available evidence — it is not a universal safety or compliance claim. UNKNOWN, NOT_ASSESSED, PARTIAL, FAILED, TIMEOUT, UNSUPPORTED, and NOT_RUN never silently become PASS.

Go to Assurance
7

Verify

5 min

Review the Decision Receipt and public verification where supported. Verification confirms bounded record integrity and the recorded decision. It does not certify compliance, regulatory approval, or universal safety.

Go to Verify

Key Concepts

Evidence-Bound Assurance

HAIEC connects source, identity, access, policy, permissions, evidence, and observed behavior to show what AI systems and agents can reach, change, and trigger, and what the evidence actually establishes.

Evaluated Scope

ALLOW means within evaluated scope and available evidence. It is not a universal safety or compliance claim. The evaluated scope is captured with each Assurance decision.

Missing Evidence Stays Missing

UNKNOWN, NOT_ASSESSED, PARTIAL, FAILED, TIMEOUT, UNSUPPORTED, and NOT_RUN never silently become PASS. If evidence is not collected, the gap is visible.

Evaluation Run ≠ Assurance

Evaluation Runs coordinate evidence collection and produce operational evidence. The canonical Assurance Decision Engine independently produces ALLOW / REVIEW / BLOCK. They are distinct.

Decision Receipt ≠ Certification

A Decision Receipt is a tamper-evident record of a bounded Assurance decision. Public verification confirms record integrity and the recorded decision. It is not compliance certification, regulatory approval, or a legal opinion.

Framework Mapping ≠ Assurance

Framework and regulation guides (GDPR, HIPAA, NYC LL144, SOC 2) help you understand requirements. Mapping controls to a framework is not an Assurance decision and not a certification.

Ready to Get Started?

Create your free account and define your first AI system to start collecting evidence.

Related Documentation