System-by-system governance
Each AI capability has a versioned intended purpose, owner, provider/deployer role assessment, risk classification and review date.
This page describes how Collty governs AI-assisted team assembly, project planning, collaboration intelligence and agents across their lifecycle, including classification, data governance, human control, transparency, evaluation and monitoring.
Each AI capability has a versioned intended purpose, owner, provider/deployer role assessment, risk classification and review date.
Private evals, domain graders, provenance, holdout testing, canary controls and human approval gate changes to ranking behavior.
Collty recommends project-team options and explains supporting professional evidence. Users review profiles and make the final team and project decisions.
Alignment describes Collty's engineering and operating controls. It is not an official conformity assessment, CE marking, regulator approval or legal classification. Final obligations depend on each system's intended purpose, deployment and applicable dates.
Collty treats itself as the provider of its proprietary AI-assisted product systems and evaluates customer roles as deployer roles where applicable. External foundation-model and embedding providers are replaceable processing components; Collty retains product purpose, evidence selection, permissions, domain logic, evaluation, provenance and action controls.
Team recommendations are intended to help users assemble project teams from professional evidence, not to make employment, dismissal, worker-management, credit, insurance, education, law-enforcement or public-benefit decisions. Intended-use restrictions do not eliminate the need to assess actual use and foreseeable misuse.
Collty is not designed, offered or permitted for AI practices prohibited by the EU AI Act. Collty does not provide biometric identification or categorisation, facial-image scraping, emotion recognition, social scoring or criminal-risk prediction capabilities.
Actual use and reasonably foreseeable misuse remain part of each system's documented risk review. Collty may restrict, suspend or investigate use outside these product boundaries.
Collty tracks the application dates published by the European Commission and records the applicable date in each system assessment. The current timeline reflects the AI Omnibus that entered into force in July 2026 and may be updated if the legal framework changes.
| Application date | Relevant rules |
|---|---|
| 2 February 2025 | Prohibited AI practices and the applicable definitions entered into application. |
| 2 August 2025 | Governance rules and obligations for providers of general-purpose AI models entered into application; Collty separately assesses its role and the role of external model providers. |
| 2 August 2026 | The AI Act becomes generally applicable and Article 50 transparency obligations apply to covered AI interactions and generated or manipulated content. |
| 2 December 2027 | High-risk requirements apply to systems in the sensitive areas covered by Annex III under the current AI Omnibus timeline. |
| 2 August 2028 | High-risk requirements apply to AI systems embedded in regulated products covered by Annex I. |
A date in this table does not classify every Collty feature into that category. Classification and resulting obligations are assessed per system, intended purpose, deployment context and foreseeable use.
The protected versioned inventory records the intended purpose, owner, provider and deployer role assessment, model categories, input and output categories, people affected, human-oversight requirement, Article 50 transparency requirement, risk class, assessment state and review date for each system.
| System area | Governance focus |
|---|---|
| Team Assembly | Capability relevance, verified evidence, team composition, ranking bias, exclusions and final human selection. |
| Signals | Applicant evidence, project fit, client approval and safe use of general-database candidates when response coverage is insufficient. |
| Team Intelligence | Competence, role balance, availability, collaboration evidence, confidence and non-public data boundaries. |
| Project Architect | Grounded phases, tasks, roles, dependencies, duration, commercial consistency and absence of invented specialists. |
| Project Advisor and agents | Project evidence, permitted actions, approval gates, mutation provenance, rollback and monitoring. |
| Smart Console and generative interfaces | Clear AI interaction notice, source grounding, permissions and user review. |
Features that may affect access to professional opportunities remain in conservative assessment scope. The recorded classification can be changed only through a new version with documented rationale.
Collty uses versioned private evaluation datasets and task-specific graders. Team Assembly evaluation measures request relevance, mandatory capability coverage, unsupported or unsuitable specialists, invented roles or evidence, role allocation, availability, capacity, collaboration compatibility, stability, human rating and project outcomes.
Project Architect evaluation measures phase and task completeness, dependency validity, realistic duration, sprint consistency, role and assignee correctness, absence of invented professionals and commercial consistency.
A professional can update or delete their profile, change visibility and report inaccurate or unsupported evidence associated with their own account. This correction mechanism addresses data and system error; it does not make Collty the adjudicator of an independent customer's final team choice.
The versioned risk register covers discrimination, ranking and selection bias, erroneous exclusion, hallucinated evidence, private-data leakage, prompt injection, model or provider failure, over-reliance, drift, unauthorized actions, weak evidence and misuse outside intended scope.
Production monitoring records quality, pass rate, latency, provider errors, timeouts, token cost, drift, duplicate calls, eval coverage, calibration exposure and observed outcomes. Reports of incorrect evidence, unexpected exclusion, unsafe recommendations or unauthorized action can be recorded against the applicable AI-system version.
Collty's technical file is assembled from versioned system inventory, intended-purpose records, data-flow and privacy controls, risk assessments, DPIAs, evaluation datasets and graders, model/provider configuration, provenance, monitoring, incidents, literacy records, release evidence and change history.
The operating quality system separates build, validation, shadow evaluation, human approval, canary activation, monitoring and rollback. A code deployment alone does not silently promote new ranking weights.
Collty maintains a role-specific AI literacy register for administrators, product owners, engineers, support staff and deployer-facing roles. Records include programme version, module, role scope, assignment, completion, expiry and protected evidence.
Collty has implemented the technical foundations described above and continues to validate legal classification, documentation completeness, supplier evidence, deployment contexts and applicable transition dates. High-risk classification, conformity assessment, registration or notification obligations are determined per system and use case.