Platform Features
This section documents the individual capabilities of the Asenion platform. Features are grouped by the area they support.
AI System Inventory
Use Case (AI System)
The top-level record for an AI system: description, lifecycle stage, risk status, stakeholders, assessments, evidence, and reports. Supports predictive, generative, and agentic systems — built internally or sourced from a third party.
Governance Policies
Policy
A framework, standard, regulation, or testing criteria assigned to an AI system. Made up of control bundles and controls. An Operational Risk Assessment is auto-assigned at creation.
Policy Library
The organization’s central collection of policies, browseable and searchable by sector, jurisdiction, use case, methodology, and lifecycle stage. Includes out-of-the-box regulatory frameworks and organization-specific policies.
Control Bundle
A named category of controls within a policy (e.g. “Data Governance,” “Transparency”). Carries a weight that contributes to the overall policy score.
Control
A single requirement or test criterion within a control bundle. Supports multiple choice, checkbox, text entry, test score, document upload, and card answer types.
Assessment & Workflow
Workflow
Structured review and approval process for assessments: Not Started → In Progress → In Validation → In Review → Waiting for Approval → Approved / Rejected. Includes independent audit status separate from the approval chain.
Conditional Form Logic
Role-based conditional display of controls: controls can be shown or hidden based on earlier answers in the same control bundle.
Lifecycle Management
Configurable AI system lifecycle stages (e.g. Development, Pre-Production, Production) with assessment completion and risk score thresholds that gate progression.
Risk & Governance Evidence
Risk Status Tracking
Continuous, historized tracking of each AI system’s governance posture across residual risk, technology risk, and alignment risk dimensions. Supports data pipeline integration (Python library, REST API, microservices, Web UI).
Reports
Template-based report generation per AI system. Built-in types: Risk Assessment, Action Report, EU AI Act Deep Dive, Risk Reduction. Custom org-level report templates supported. Background generation with PDF download.
Document Hub
Per-AI-system file manager for governance evidence. Upload with Private or Public visibility, import pages and attachments directly from Confluence, download via secure time-limited URLs, search, and attach files directly to assessment controls.
Corrective Actions
Automatic Nonconformity and Corrective Action (NCCA) records opened by risk alerts, with a pre-filled register entry, a Review assignment for follow-up, and an optional linked Jira ticket.
Activity Log
Tamper-evident audit trail of all platform actions, categorized by Access, People, Integration, Configuration, Projects, and Policies. Available at org level and project level with filtering by user, category, and date range.
Access & Security
User Roles
Two-layer permission model: platform roles (Member, Compliance Manager, Governance Manager, Assurance Manager, Audit Manager, Org Admin, System Admin) and project roles (Owner, Contributor, Reviewer, Approver, Viewer, Auditor).
Admin
Organization Admin and System Admin capabilities, including member management, policy import, lifecycle configuration, and role-capability matrix management.
Security
Two-factor authentication (TOTP) with optional org-wide enforcement, Single Sign-On with Okta and Microsoft Entra ID (self-service, discovered by email domain), and role-based access control.
Permissions
Role-based access control with fine-grained capability overrides. 27 named capabilities across platform, org, project, assessment, report, and test scopes. Org Admins can grant or revoke individual capabilities per user without changing their role. System Admins can edit the role-capability matrix.
Multiple Organizations
A single user account can belong to multiple organizations. Each organization is an isolated workspace. Users select their active organization at login and can switch at any time from the left nav. Includes organization unit hierarchy (Department, Division, Team, Project Group).
Global Project Roles
Org-level pre-assignment of review and approval slots (Compliance, Governance, Assurance, Audit) for automatic routing when new AI systems are created.
Alerts & Notifications
In-app notification center for risk status changes, workflow events (submission, approval, rejection), control assignments, and audit updates. Configurable per AI system with email, Slack, Microsoft Teams, and Jira ticket delivery.
Integrations
Integrations
Named connections to external systems: cloud platforms (Azure, AWS, GCP) for model discovery, MLflow for test evidence linking, Jira for corrective action and assignment tickets, Confluence for importing documentation, Slack and Microsoft Teams for notifications, ServiceNow for ITSM, and Okta / Microsoft Entra ID for SSO. Managed from Settings → Connections.
Model Discovery
Scan connected cloud platforms to auto-discover deployed AI models and import them into the Asenion inventory with pre-populated metadata. Supports Azure, AWS, and GCP.
Usability
Light mode / dark mode display (follows OS setting). Enterprise localization: currency, timezone, and language.
Table of contents
- Activity Log
- Admin
- Alerts & Notifications
- Conditional Form
- Control
- Control Bundle
- Corrective Actions
- Document Hub
- Global Project Roles
- Integrations
- Lifecycle Management
- Model Discovery
- Multiple Organizations
- Permissions
- Policy
- Policy Library
- Reports
- Risk Status Tracking
- Security
- Usability
- Use Case
- User Roles
- Workflow