EngineeringGitLab Duo style30 days
AI code assistant remediates a failing compliance-bound pipeline.
A developer asks an AI coding assistant to fix CI on a repository with regulated change-control expectations. Summit wraps the action path with receipts so reviewers can inspect what changed, why, who approved it, and what evidence was relied on.
TriggerCI fails after dependency update
AI actionProposes patch and test run
GatePolicy and human approval
ReceiptEvidence, diff, tests, approver
ReviewChange-control packet
Acceptance tests
- Receipt exists for every material AI-assisted change.
- Reviewer can link diff, test result, and approval.
- Tampered receipt fails verification.
Artifacts
- Receipt chain excerpt.
- Change-control summary.
- 30-day expand/stop memo.
receipt fields: repo, issue, evidence refs, proposed diff, test status, approving actor, final outcome
Decision gate: engineering and compliance reviewers can reproduce why the change was allowed and decide whether to expand to more repos.
Knowledge OpsSharePoint style30 days
AI assistant answers from a controlled document library.
A team wants AI help navigating policies, customer records, or operational documents without losing the source trail. Summit records the evidence path behind each answer and the permission boundary used for retrieval.
TriggerUser asks operational question
RetrieveApproved library only
AnswerSource-grounded response
ReceiptSources and permission boundary
ReviewAnswer-quality sample
Acceptance tests
- Reviewer can see which documents supported the answer.
- Out-of-bound source access is blocked or marked.
- Sampling shows usable answers without unsupported authority claims.
Artifacts
- Question-to-source map.
- Permission-boundary report.
- Reviewer sample worksheet.
receipt fields: user role, query, approved source set, cited documents, answer state, review note
Decision gate: the buyer confirms whether source-grounded answers reduce review friction enough to continue.
GRCControl evidence30 days
AI prepares a control-evidence response without inventing authority.
A compliance or security team uses an AI assistant to assemble evidence for a questionnaire, vendor review, or internal control check. Summit records evidence provenance and separates supported statements from missing evidence.
TriggerControl question received
AssembleEvidence pack drafted
ClassifySupported vs. missing
ReceiptEvidence and reviewer state
SubmitOwner-approved answer
Acceptance tests
- Every material answer links to evidence or is marked missing.
- Reviewer can identify who approved final wording.
- No receipt implies a compliance certification.
Artifacts
- Evidence coverage matrix.
- Unsupported-claim register.
- Approval receipt packet.
receipt fields: question id, evidence refs, unsupported gaps, reviewer, approval state, submitted response
Decision gate: the buyer decides whether the pack improves evidence review enough to use on the next questionnaire cycle.
CyberSOC escalation30 days
AI triages a security alert and records the escalation path.
A security team wants AI triage to summarize alerts, correlate context, and recommend escalation without hiding the evidence. Summit receipts capture the signal path, decision criteria, and final disposition.
TriggerAlert cluster appears
CorrelateIdentity, asset, vuln, threat intel
RecommendEscalate, monitor, or close
ReceiptSignals and criteria
AuditFalse positive / true positive review
Acceptance tests
- Analyst can inspect the signals behind the recommendation.
- Disposition and reviewer are recorded.
- Historical review can reconstruct what was known at triage time.
Artifacts
- Alert-to-evidence graph.
- Disposition register.
- Post-incident receipt sample.
receipt fields: alert ids, asset context, evidence refs, recommendation, reviewer, disposition
Decision gate: the security owner decides whether reviewability improved enough to expand to another alert class.
Personal AgentsAudit trail30 days
Personal agent takes a delegated action with an inspectable record.
A user delegates scheduling, filing, or communication prep to a personal agent. Summit records the action boundary, user instruction, evidence used, and final outcome so the user can review or undo the result.
InstructionUser delegates bounded task
PlanAgent proposes action
ConsentUser approves or rejects
ReceiptInstruction, approval, result
UndoReview and correction path
Acceptance tests
- User can answer what the agent did and why.
- Approval state is visible before the action is final.
- Correction or undo path is captured where available.
Artifacts
- User-facing receipt summary.
- Boundary and consent log.
- Review/undo worksheet.
receipt fields: user instruction, allowed tools, evidence refs, consent state, action result, undo path
Decision gate: users and product owner decide whether receipts make delegated actions trustworthy enough for broader beta use.