What Yohanun will not do.
Most AI products list what they can do. A governance platform is better described by what it refuses, because a refusal is a promise you can test. Every item below is enforced by the platform, not by a sentence in a prompt, and every one is visible when it happens: a status code, a row in a ledger, a receipt. Try to make it break one.
A system that governs by asking the model to be careful cannot print this list. Its list would be empty.
01
It will not let the model decide who sees what.
Access is compiled into the retrieval query before the model is involved. Material the asker is not cleared to see never reaches the model, so there is nothing for a clever question to extract.
How you see it: every read leaves a row naming what gate was applied and what was released.
02
It will not read without a record.
Each gated read writes an audit row before the answer returns, and the write is awaited, not fired and forgotten. A tenant can go further: with strict audit on, a read whose record cannot be written is refused.
How you see it: a 503 on the read, and nothing returned.
03
It will not serve from a ledger it cannot read.
If the clearance ledger is unreachable, the platform does not fall back to whatever the caller asserted. The asker is treated as cleared for public material only, until the ledger is back.
How you see it: an answer that suddenly holds nothing privileged, and a logged outage.
04
It will not store a memory without a wall, if you tell it not to.
A tenant can require that every memory and every upload names its compartment. A write that names none is refused, not filed as public by default.
How you see it: a 400 on the write, naming the missing field.
05
It will not let the person who asked approve their own request.
An action above someone's mandate waits for a second person, and the platform enforces that it is a second person: never the one who raised it, and only someone whose own mandate covers it.
How you see it: a 403 on the decision, and a decision_refused row in the audit.
06
It will not act beyond a mandate, and with no mandate it will not act at all.
An agent may act up to an explicit limit. Above it, or with none, the action escalates to a person. When the check itself fails, the commit fails closed: an action that cannot be authorised does not happen.
How you see it: escalated, with an id, in the human queue.
07
It will not accept an application's word for who is asking.
With verified identity on, the person asking is the subject of a token signed by your own sign-on and checked by the platform. A field naming someone else is ignored. No valid token, no read, and never a fallback.
How you see it: a 401, and an audit row marked verified when it passes.
08
It will not widen an answer's permissions.
A stored answer inherits the wall of everything it was given: the compartment of the most sensitive source, the highest classification, and the owners common to every owned source. Where no key covers them all, it belongs to the asker alone.
How you see it: the stored turn's labels, readable by id, and the consumer told when a turn spanned compartments.
09
It will not delete.
The store's delete is a no-op by design. A wrong memory is superseded, a finished one closed, and both stay readable by identifier with their history. Nothing is destroyed in ordinary operation.
How you see it: a lifecycle event on the memory, and a lineage you can walk both ways.
10
It will not erase without a plan, a permission and a receipt.
Destruction is one governed path. The target is resolved to a plan with counts and labels and no content; a mandate or a named second person authorises exactly that plan; every store is scrubbed; each erased memory leaves a tombstone.
How you see it: the receipt, and one purged row per memory in the ledger.
11
It will not pretend an erasure reached the backups.
Backups are not rewritten. The purge report, and every tombstone, says so and says how many days at most until they expire.
How you see it: the backups line in the receipt.
12
It will not rewrite history.
Ledgers are append-only: clearances, custody, mandates, escalations, refusals, lifecycle. A refused grant is a durable record, never a task. What the estate held on any past date can be read back, with what has happened to each item since.
How you see it: the as-of read, and the export of the whole estate under mandate.
Each of these is a test
Every refusal on this page has a live proof behind it, run against a throwaway tenant on the production platform before a change ships. We do not hold SOC 2 or ISO attestations yet, and we will not imply otherwise. What we offer is a list you can try to falsify, and an invitation to bring your security team and do so.
How the gate works