AI controls and governance

Clear controls. Accountable implementation.

We work with your security and operations teams to define access, approvals and oversight. We write those controls, responsibilities and operating limits into the implementation before launch.

Three gates

Access, approval, review

Every automated action inherits your permission model, a person releases anything a customer sees, and every action is logged — with anything the system is unsure about routed to a person. The diagram is the whole policy; the sections below are the detail.

Data security and access control

Agents inherit your permission model. They read and write what their role allows, in an environment your compliance team already approved.

The first question every enterprise buyer asks about agents is what they can see. The answer should be boring: exactly what the role permits, and you can prove it afterwards.

An agent is not a special case with its own credentials and its own exceptions. It gets a role inside the permission model your administrators already maintain, and when that model changes the agent’s access changes with it. Anything else is a shadow permission system nobody audits.

On compliance we are precise about who holds what. Creatio and the underlying cloud platforms carry the infrastructure attestations — HIPAA-eligible hosting, regional data residency, the standard enterprise audit reports. We configure your deployment inside those controls and document how.

  • Role-based access control governs an agent exactly as it governs a user — an agent cannot read a record its role cannot read
  • HIPAA-eligible infrastructure where your sector needs it, on platforms and hosting that publish their own audit reports — we configure inside those controls and can point your risk team at the current report rather than a summary of it
  • Residency, retention and handling terms are written into the contract, not assumed from a defaults page
  • Healthcare engagements are scoped with your privacy officer before an agent touches a record

Model agnosticism

You are not locked into one AI vendor. The architecture supports frontier models from OpenAI, Anthropic and Google, or a model you bring yourself.

Model choice is the part of an AI deployment most likely to be wrong in eighteen months, so the architecture assumes it changes. The agent’s instructions, its grounding data, the approval gates and the audit trail all live in the platform. The model is the part you can replace.

That is commercial as much as technical. A firm that welds your system to one vendor’s model has handed you their negotiating position along with the invoice — and the right model for document extraction is rarely the right one for drafting a customer reply.

If procurement, data residency or your security posture requires a specific model, or one you host yourself, that is a supported configuration rather than an exception we will talk you out of.

Where an agent runs is a separate question from which model it calls. We name Creatio AI Studio for agents inside your CRM and Google Vertex AI for agents outside it: that is the orchestration layer we can support on day one. Only the model is deliberately replaceable. Orchestrating somewhere else changes the estimate, not the architecture.

  • Frontier models from OpenAI, Anthropic and Google are supported deployment targets
  • Bring your own model where procurement, residency or a fine-tune requires it
  • Workflow, grounding and approval logic sit outside the model, so a swap is configuration rather than a rebuild — though a material change still warrants revalidation on representative tasks before it carries live work
  • Where an agent runs and which model it calls are separate decisions — opinionated on the first, open on the second
  • Model choice is settled in Discovery, on your constraints, not on a default we inherited

Accuracy and auditability

Agents are grounded against your own records through RAG, and every action carries a log explaining what it did and on what basis.

Hallucination is the objection that stops enterprise AI projects, and it deserves an answer rather than a reassurance.

The answer has two halves. Agents retrieve from your knowledge base, your price book and your live CRM records, so the material they work from is yours and current. And when an agent is unsure it routes the record to a person instead of producing its best guess with full confidence. Where that threshold sits is decided with you, per workflow — it is different for a quote than for a support reply.

We will not tell you the error rate is zero; no honest implementer can.

We also will not tell you everything is reversible. A record update can be rolled back. An email that has gone to a customer, a payment instruction that has been accepted downstream, or a decision another system has already acted on cannot be — which is exactly why the approval gate sits before those steps rather than after them. Where an action is irreversible, that is a design decision made with you during Design, and it is written down.

What we do claim: every action is logged with the records that informed it, so when something is wrong you can find the cause, contain it, correct what is correctable, and show your auditor the trail.

  • Retrieval-Augmented Generation ties responses to your knowledge base and live CRM records
  • Below a confidence threshold the agent routes the record to a human approval queue instead of proceeding
  • Full audit logs record what an agent did, when and which records informed the decision
  • We do not claim a zero-error rate, and we do not claim every action can be undone — we claim you can see what happened, on what basis, and what it will take to put right
What we don’t claim

We are not a compliance authority

The infrastructure attestations — HIPAA-eligible hosting, data residency, the enterprise audit reports — belong to the platform and the cloud providers. We configure your deployment to sit inside them, and document how.

We do not describe Kewl as certified against a standard we do not hold, and we do not claim a zero-error rate for any agent we deploy. Both would be easier to write and worth less to you.

Where personal information is in scope, Canada’s PIPEDA — and provincial law such as Québec’s Law 25 where it applies — sets the terms a deployment has to meet. We design access, retention and residency to them with your privacy officer, and the terms go into the contract rather than onto this page.

Where your data is processed

Stored is one question, processed is another

Where records and AI processing happen, by component
ComponentWhereWhose statement
Your CRM recordsThe Creatio Cloud region you choose — Ontario, Canada is one of nine — or your own Azure or Google Cloud region, or on-site. Written into the contract.Creatio’s data-centre list; Kewl’s contract term
Creatio.ai and Creatio AI StudioCreatio states that its language-model features run on Microsoft Azure services in the same region as your Creatio site.Creatio (Creatio Academy, “Data privacy in Creatio.ai”)
Agents Kewl builds outside the CRMCanadian regional endpoints only where residency is in the contract — never a provider’s “global” endpoint, which does not guarantee a processing location. A model not offered in Canada is named as such in the proposal.Kewl’s design rule; the provider’s own endpoint documentation

What this website itself collects is a separate and much shorter question — one contact form, no cookies, and no analytics that identify you. It is written out in full on the privacy page.

Common questions

Security and governance

Yes. The attestations belong to the platform and hosting providers, and we do not claim them as ours; what matters in practice is how a regulated engagement is sequenced.

Your privacy officer is in it before an agent touches a record. Where the sector requires a Business Associate Agreement or an equivalent instrument, that is agreed on first — not after go-live, and not as a document produced to close a procurement question. Agent access is then restricted through the role-based permission model your administrators already maintain, and we document both.

Wherever you decide, and the decision is made per workflow rather than once for the whole deployment.

Three gates are common. An approval step, where the agent prepares the work and a person releases it — standard for anything a customer sees or anything with money attached. A confidence threshold, where an unsure agent routes the record to a queue instead of proceeding. And an exception path for the cases nobody anticipated, which is the one most implementations forget to design and then discover at the worst moment.

Too tight and the agent is pointless; too loose and the system is unreviewable. Getting the placement right is most of the design work, and it changes as you build confidence — which is fine, because moving a gate is a configuration change.

Yes. Integrations, automation services and middleware are deployed directly into your own Google Cloud project or Microsoft Azure tenant, so data stays inside your security boundary. Canadian data residency is available — Creatio Cloud’s Ontario region, or your own Azure or Google Cloud Canadian region — and is written into the contract, along with the specific handling and retention terms, per engagement.

We constrain what the agent can use rather than hoping it behaves. Answers are retrieval-grounded against verified CRM records and price books, and actions run through structured tool calls with defined schemas — designed so an agent can only write values that exist in your data, and a person approves anything customer-facing. Where a workflow needs a decision rather than a lookup, a confidence threshold decides whether it proceeds; below it, the record goes to a human approval queue instead of guessing. In Creatio AI Studio that approval step, the execution log and the audit trail are enforced by the platform itself.

We do not claim a zero-error rate — no honest AI deployment does. We claim that every action is bounded to data you can check, logged where you can see it, and stoppable by a person before it reaches a customer. The AI Trust Framework sets out how.

A CRM where people and AI agents do the work together, rather than one where people record what already happened. Purpose-built agents sit inside the workflows — ticket triage, quote generation, sales intelligence — each scoped to one task and grounded in verified CRM records, so its output stays tied to data you can inspect. This is now how Creatio itself describes the platform, and since the 10x release in July 2026 the agent lifecycle, approvals and audit trail are managed natively in Creatio AI Studio.

Not answered here? Ask us directly — we reply by the end of the next business day.

Updated : the three-gates diagram now reads from the bottom up: a record enters at the foot and rises through access, approval and review to its outcome at the top. Written against Creatio 10x — if a release since then has moved something on this page, tell us and we will fix it.

Bring your risk team to the first call

Constraints are easier to design around than to retrofit.