Walkthrough: regulated and enterprise
A larger or regulated organisation adopting what its AI-native people already use bottom-up, now with compliance and IT at the table. The requirement: keep the individuals' velocity, but add the governance a regulated environment needs - audit, approval gates, provenance, SSO and data control.
Kythene is built so this layers on without remodelling: the provenance and scoping spine is there from day one, and the governance surfaces sit on top.
Provenance and lineage as a compliance artefact
Every artifact and memory records who and which instance produced it, and from what. That lineage is not just a UX nicety here - it lets you answer "which shared knowledge did this output rely on?" as an audit trail, not a guess. Activity is recorded as events across the workspace: who shared what, and which instance read what.
Approval gates with recorded approvers
Where work must be signed off before it counts, require review on the collection. Approvals record the approver and the revision, and promotion of a finding into team memory can require the same gate - so "who approved this becoming team truth" has a recorded answer.
Access, permissioned by tag
Projects are delineated and access-controlled by tag: internal-only, password-protected, or opened to a named guest by share code. The compliance boundary is expressed in the same model your people already use, not bolted on.
SSO and roles
Sign-in is via your identity provider (GitHub today; enterprise SSO / OIDC directories on the Enterprise tier), and members carry roles. You can restrict sign-in to your own domain so only your people get in.
Self-host for data sovereignty
Run Kythene entirely on your own infrastructure under a signed, offline licence - no phone-home, no dependency on our servers. Suitable for data-sovereign, regulated and air-gapped deployments. The individuals' workflow - publish, recall, review, memory - is identical to the hosted product; only the deployment changes. See self-hosting.
What is available now vs. on the roadmap
The model spine - provenance, lineage, approvals, tag-level access, self-host - is in place today. Some governance surfaces (a compliance-grade audit/export UI, retention and legal-hold controls, enterprise SSO and fine-grained RBAC) are on the Enterprise track and rolling out - talk to us about what your environment needs and the timeline.
Tips
- Regulated firms usually want self-host; the hosted Enterprise tier offers the same governance (SSO, audit, support) if you would rather we run it.
- Because provenance is designed in, adopting Kythene later does not mean losing the audit trail of what came before - it starts recording from the first publish.