For federal agencies and programme offices
Start with the constraint: we hold neither a FedRAMP authorization nor a FedRAMP certification, and we claim no equivalency. The route that remains is deployment control — the capability runs inside a boundary your agency already authorized, under your continuous monitoring, doing only what a written grant permits.
The requirement is clear and has been clear for some time. Between it and anything operating there is an acquisition to structure, an authorization to obtain or inherit, a security assessment, a privacy analysis, an accessibility review, and a set of approvals held by people in different chains of command who are each individually reasonable.
By the time the path is walked, the requirement has often moved. The programme that needed the capability has a new priority, the staff who wrote the requirement have rotated, and the capability that arrives is the one that was specified two years ago.
Meanwhile the work itself is done by people carrying more than the process assumes. Case backlogs, correspondence, records requests, action items, deliverable reviews, data calls — necessary work that consumes the time of people hired for judgement, and that grows faster than the headcount authorised to absorb it.
And every proposal involving automation arrives into a legitimate question: what will it do on its own, who decided that, and how would anybody know afterwards. That question is asked because agencies have been sold capabilities whose actual behaviour was not enumerable, and the answer "it uses AI" is not an answer to it.
Then there is the evidence burden. An inspector general, an oversight committee, a GAO engagement or a records request all require reconstruction after the fact, performed by staff who were not doing anything wrong and now have to prove it.
Approval depends on knowing exactly what a system may do without asking, who granted that, and what record it leaves — and most capabilities cannot answer those three questions in a form an authorizing official can read.
This is why so many technically sound proposals stall. The stall is not resistance to the technology. It is that an authorizing official is being asked to accept a boundary they cannot see the edges of, and declining is the correct decision when the edges are not visible.
So the boundary is the product here rather than a feature of it. What may be done without asking is written down before anything runs, scoped narrowly enough to enumerate on a single page, granted by a named official, and revocable immediately without a contract action. Anything outside it does not happen — it becomes an escalation naming the decision required and who holds it.
The second half is the record. Every consequential action carries what was done, under which grant, by what actor, at what time, against which record, with what result. That record is produced during the work rather than assembled afterwards to describe it, and it belongs to the agency rather than to us. For an oversight response the difference between those two artefacts is substantial.
And the third is deployment control, which is what makes any of this available given our authorization position. The capability runs inside a boundary your agency has already authorized, under your monitoring, with your identity provider and your logging. The assurance question in play becomes yours rather than ours — which is not a way around the requirement, it is the arrangement the requirement contemplates.
Where mission work actually waits — measured by elapsed time per step decomposed into work, queue, approval and external-dependency time, against your own baseline.
What the capability may do without asking — measured by an enumerated authority grant an authorizing official can read in full, rather than a capability description.
Evidence available for an oversight question — measured by action-level records with actor, authority, time and result, produced during the work rather than reconstructed.
Correspondence, action items and data calls consuming judgement staff — measured by staff hours on routine administrative work before and after, sampled the same way.
Records and FOIA requests against their statutory clock — measured by elapsed time to fulfilment, and the count approaching or exceeding the deadline.
Time from a requirement being stated to anything operating against it — measured by days from scope agreement to a running observation phase inside an already-authorized boundary.
Whether an approval chain is the constraint — measured by approval wait time as a share of total elapsed time, which is frequently the largest single component and is rarely measured.
any authorization, any equivalency, any certification, and any determination that affects a member of the public. Nothing here adjudicates a benefit, decides a case, makes a determination about a person, or exercises discretion reserved to a federal official. Those are inherently governmental and a vendor offering them is offering a problem rather than a capability.
The capability runs inside a boundary your agency has already authorized. Your identity provider governs access, your monitoring receives the logs, your controls apply, and your continuous monitoring covers it as it covers everything else in that boundary. This is the arrangement that makes the offer real given our position, and it is described precisely rather than gestured at.
It is not a way around an authorization requirement. Where a requirement attaches to an external cloud service in the position being proposed, we are not a candidate for that position and we will say so rather than propose a structure around it.
Integration is through documented interfaces into the systems already holding the work. Nothing migrates, no second record of a case or a person is created, and where an interface does not exist, the limitation is reported as a limitation rather than worked around by automating a screen.
Accessibility is a property from the beginning rather than a review at the end. A surface that a federal employee or a member of the public cannot use is not a delivered surface.
We hold neither a FedRAMP authorization nor a FedRAMP certification, at any impact level, and we make no equivalency claim. A vendor who answers that question with anything other than a plain no or a specific package identifier is not giving you information you can use.
Bounded authority is the mechanism that makes the rest governable. A grant names what may be done, by which actor, within which scope, and it is short enough for an authorizing official to read completely rather than to accept in summary. It is revocable immediately, by the official who granted it, without a contract action.
The evidence belongs to the agency. Every consequential action carries actor, authority, timestamp, target and result, and the record is exportable by you without asking us to produce it — which is the whole point, since an audit trail you have to request from a vendor is one you do not really control.
Operational access is not permission to train. Mission and programme data does not become material improving anything serving another organisation, and that boundary is architectural rather than a sentence in a document.
The authorizing official’s question is about the boundary, and the answer is that the boundary is yours: the capability operates inside an environment you already authorized, under your controls and your monitoring. What it may do inside that boundary is the written grant, and it is a document rather than a description.
The privacy analysis needs to know what data is reached and for what purpose, and the answer should be narrow enough to state in a paragraph. If a proposed scope cannot be described that narrowly, it is too broad and should be reduced before it is analysed.
Accessibility is documented for any surface a federal employee or a member of the public would use, and it is treated as a delivery requirement rather than a review gate at the end.
And the contracting officer needs to know the constraint plainly. We hold no authorization, that closes certain positions completely, and we would rather that shape a requirement early than be discovered during evaluation.
One programme workflow — correspondence, action items, records requests, or a case backlog — observed read-only inside an environment your agency has already authorized, with no authority to act on anything.
The observation phase grants nothing and decides nothing. It produces the decomposition of elapsed time for that workflow: work, queue, approval wait, and external dependency. In most programme offices the approval component turns out to be the largest and has never been measured, which is a finding an agency can act on without any vendor at all.
That is a legitimate stopping point and some programmes should stop there. A measured approval wait is an internal fact that belongs to the agency, and it is frequently more actionable than any capability that could be procured.
If it continues, the first grant is one narrow, enumerated, revocable delegation, written by a named official, with escalation defined before anything runs — and nothing inherently governmental inside it.
No, at any impact level, and we claim no equivalency. That closes any position requiring an authorized external cloud service, and we will not propose a structure around it. The route that remains is deployment inside a boundary your agency has already authorized, where the assurance question in play is yours. If your requirement cannot be met that way, we are not a candidate and you should have that answer before an acquisition is shaped.
By reading the grant, which is a document rather than a description and is deliberately short enough to read completely. It names what may be done, by which actor, within which scope, and it is signed by an official who can withdraw it immediately without a contract action. Anything outside it does not happen — it escalates, naming the decision and the person who holds it. If a capability cannot produce that document, an authorizing official is right to decline it.
Correct, and nothing here should be. No determination about a person, no adjudication, no exercise of reserved discretion. What can be bounded and delegated is the administrative flow around those decisions — where work sits, what it waits for, what is aging, what evidence exists. The boundary between the two is written into scope before anything runs, and if a step cannot be cleanly separated, it stays with your officials.
A fair concern and it should be weighed. Two things reduce the exposure: the observation phase is small enough to fit inside existing authority in many programme offices, and the evidence and flow data produced belong to the agency in an exportable form, so what you learn survives the vendor relationship whatever happens to it. Exit terms are part of the initial scoping documents rather than a negotiation later.
Then the useful test is not an explanation of how a model reasons — it is whether the system can produce, for any given action, what was done, under which written grant, by which actor, at what time, and with what result. That is a smaller claim than most vendors make and it is the one that answers an inspector general. Where judgement was required rather than rule, it should have escalated to a person, and the record should show that it did.