AI builder

Describe the app. Review the change. Publish when you're ready.

The AI builder is not a code generator with a login bolted on. It works inside the platform, as the person using it, and it can only do what that person could do by hand: draft a change set. Every guarantee the platform makes about access, evidence and residency applies to what it drafts — because those were never the app's to decide.

How it works

From a sentence to a governed app

  1. You describe what you need

    "A register of vendor security assessments: one per supplier, with a risk rating, the reviewer, the evidence they looked at, and a review due every twelve months." Plain language, in the builder, from your own account.

  2. The builder drafts a change set

    It proposes the records, fields, relationships, lifecycle and rules as a change set — the same kind of draft a person would create in the builder by hand. It links to the people list and organisation tree that already exist rather than inventing new ones.

  3. The compiler checks it

    The draft is compiled by the same compiler that checks everything we ship: every identifier unique, every rule type-checked, every protected part of the core untouched. If it does not compile, the builder revises it before you see it.

  4. You review and publish

    You see the change as a reviewable document — what is added, what is changed, what it touches. Publishing is a human act, recorded like any other governed transition. The builder cannot publish, and nobody can skip the review.

  5. The platform runs it

    Screens, API, validation, reports and audit arrive with the app. Access is decided by the engine, scoped to the organisation, failing closed. The app you described an hour ago is governed exactly like the one we shipped last year.

What makes it safe

Four boundaries the builder cannot cross

It acts as you

The builder runs server-side as the invoking person, with that person's privileges and nothing more. There is no service account behind it with a wider view of your data.

It only writes drafts

Its tool surface is the draft API and nothing else. It cannot read your records, change access, touch another tenancy, or publish. What it produces is a proposal.

It cannot weaken the core

The people list, organisation tree, audit trail and access model are protected at compile time. A change set that tries to remove or restructure them fails to compile, whoever authored it.

Its output is a definition, not code

There is no generated code to review, patch or maintain. The result is a readable definition the platform understands, kept separate from ours and replayed on upgrade like any other change you make.

How we know it works

Measured, gated, and honest about the numbers

The builder does not read our documentation at run time. It works from a knowledge pack — a compact reference generated from the compiler's own source, so it cannot drift from what the platform actually accepts — plus worked patterns and examples.

We measured that pack against a full-documentation baseline on a fixed set of build briefs. The pack matched or beat the baseline on every brief and produced no violations of the platform's invariants across the set. We quote that as the claim it supports, not as a benchmark of the model.

The same briefs run in our build pipeline whenever the compiler, the reference or the builder changes, with floors on compile-cleanliness and revision loops — and a deliberate sabotage case that must fail, so a green run means the gate is actually looking.

What we do not claim: that the builder replaces an implementation partner for a complex rollout, or that every draft is right first time. It is a fast, safe first draft inside a system that makes the review cheap.

For whom

Who this is for

Administrators and analysts

The people who would otherwise open a spreadsheet. A register, a workflow, a field on an existing app — drafted in minutes, reviewed by the right person, published under the same rules as everything else.

Implementation partners

Domain knowledge becomes an app faster than a consulting engagement can scope one. Build a practice on what you know, and let the platform carry the security review. We are looking for partners →

The CIO who has said no

A place where generated applications are safe to run: one access model, one audit trail, one residency policy, one upgrade path — and an inventory of what exists, because every app is a published definition.

We're working with design partners now.

A small number of organisations shaping the first release, in exchange for early access, direct influence over what ships next, and pricing that reflects the risk of going first.