Industries
Authority at the point of change.
A payment to a supplier, a regulatory filing or a change to a patient record can be technically possible and still lack authority. Inktomi makes the conditions for that change explicit and checks them before it executes.
- Before executionBind the approval
Inktomi checks your policy and the required evidence for the specific action and its details.
- At your systemVerify the permit
A connected payment, record or filing system checks the signed permit before it acts, and refuses a call that has none.
- AfterwardsExamine the evidence
Replay any decision and compare what your systems did with the permits that were issued.
These are the markets we address. Each sector integration carries its own engineering, testing and acceptance, and no customer deployment is claimed here.
Patient records
Healthcare
- The proposed action
- A clinical workflow proposes a change to a controlled patient record under delegated authority.
- Who must authorise it
- The authorised role for that record, and any approval that must be current at the time of the change.
- What Inktomi checks
- The specific record change against the authority in force at that moment, before the change is committed. Clinical judgement and the institution's approval responsibilities stay with the responsible professionals.
- What you get
- A defined boundary for testing record changes, and a record of the authority and evidence behind each one.
Matters and privileged documents
Legal
- The proposed action
- An agent working on a matter proposes to send a document outside the firm or file it with a court.
- Who must authorise it
- The responsible attorney, for that exact document, within the matter and the client engagement.
- What Inktomi checks
- The proposed release against the matter's policy and the approval tied to that document. The connected filing or document tool checks the permit before it sends. Professional judgement and supervisory duties stay with the responsible attorneys.
- What you get
- A record of who authorised each release, re-checkable at audit or in a dispute.
Payments and transfers
Financial services
- The proposed action
- A system proposes a funds transfer under a delegated spending authority.
- Who must authorise it
- Whoever holds authority for that amount and destination at that moment, revocations included.
- What Inktomi checks
- The exact transaction against the limits and the authority current when it executes. The connected payment system checks the permit before it commits.
- What you get
- A control point for testing whether a transaction is still authorised when it is executed. The same check applies to insurance claim payments and policy records.
Claims and delegated authority
Insurance
The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (December 2023), adopted in 25 US jurisdictions as of April 2026, expects insurers to maintain a written AI program with controls and testing. In the EU, AI used for risk assessment and pricing in life and health insurance is classed as high-risk under the AI Act.
- The proposed action
- An agent proposes a claim payment or a change to a policy record.
- Who must authorise it
- The adjuster's delegated authority for that line of business and amount, and any required second approval.
- What Inktomi checks
- The exact payment against the authority in force at that moment. A required approval is tied to that payment only, and the connected payment system checks the permit before it commits.
- What you get
- A decision record for each automated action that an examiner can re-check: evidence for the written AI program insurance regulators increasingly expect.
Deployments and privileged commands
Production operations
- The proposed action
- A deployment agent proposes promoting a specific release to production, or an enterprise agent proposes a change to an operational record.
- Who must authorise it
- The release, the target environment and the approval required for that exact deployment request.
- What Inktomi checks
- Your policy and evidence for that release. The connected deployment tool checks the permit before promoting it, and refuses a direct call that carries none.
- What you get
- A defined control over what the agent may change, with recorded decisions and observed effects available for review, and a way to measure integration effort, review burden and evidence preparation time on one defined workflow.
Controlled records
Government
- The proposed action
- An automated workflow proposes a change to a controlled government record, under a delegation with a principal, a scope and an expiry.
- Who must authorise it
- The responsible principal, the scope of the delegation and any approvals required for that change.
- What Inktomi checks
- The proposed change against the authority still in force and the evidence the policy requires. The connected record system checks the permit before the record changes.
- What you get
- A practical way to examine whether automated actions remain within delegated authority, and a record an inspector can re-check.
Deployment
Every component runs on your hosts or at your network edge. Where each piece runs
Assurance
The decision to grant effect is specified mathematically and made deterministically; the AI model stays probabilistic. Each decision is written to a tamper-evident record, and replay derives it again from what was recorded. Inktomi's architecture binds reviewed source to released artifacts.
Integrity
Inktomi is moving its signatures and encryption to quantum-resistant algorithms, to protect the integrity of operational data over the long term.
Evidence obligations have dates.
Governing an automated action is becoming a record-keeping duty, not only a design duty. These dates are enacted, not proposed, and they apply to systems already running.
Regulation (EU) 2026/1744 deferred the AI Act's high-risk obligations, which include automatic logging and record-keeping, to 2 December 2027 for stand-alone systems and 2 August 2028 for AI embedded in regulated products. The Article 50 transparency duties applied from 2 August 2026.
The AI Framework Act is already in force, requiring impact assessments, risk management, human oversight and documentation for high-impact systems.
California's ADMT requirements for significant decisions and Colorado's SB 26-189 both take effect. Colorado requires developers and deployers to retain the records needed to demonstrate compliance for at least three years.
Dates as enacted at 19 September 2026 and subject to change. Applicability depends on the system and its use. Kihan does not guarantee compliance with any instrument named here.
Request a demo.
Request a 30-minute live demonstration with Kihan, with time for your questions.