Security & AI governance

Control should be visible before access is granted.

Questr’s control model is designed to make access, authority, evidence, and AI decision boundaries understandable to business, technology, risk, and audit teams.

ENTERPRISE CONTROL MODEL
IdentityAuthenticate the participant
AuthorityScope what they may do
EvidencePreserve the decision record
AI boundaryAdvise without assuming authority

The security story

Govern the participant, the action, and the evidence.

Know who has access, what each person can do, what is recorded, and where a person must make the decision.

01 · IDENTITY & ACCESS

Access follows role, relationship, and responsibility.

Questr is designed around least-privilege access, SSO and MFA, role-based permissions, separation of duties, sensitivity labels on confidential records, and keeping external users apart from internal data.

  • View, edit, and approve are distinct authorities
  • Access can be scoped by role and business relationship
  • Customer and external-user boundaries remain deliberate
IdentitySSO · MFA
AuthorizationRole · Relationship
Decision rightsView · Edit · Approve
02 · DATA & ACCOUNTABILITY

The evidence stays with the decision.

Encryption, audit history, retention, export, and monitoring support a control model in which material actions can be attributed and reviewed.

  • Encryption in transit and at rest
  • Tamper-evident audit history for governed actions
  • Configurable retention and export requirements
ProtectionEncrypted
EvidenceAttributable
LifecycleRetain · Export
03 · AI GOVERNANCE

AI can prepare the decision. People retain the authority.

Questr separates facts, calculations, predictions, and recommendations. AI-assisted work remains advisory, with authorized people accountable for consequential decisions.

  • AI may extract, compare, summarize, detect, and recommend
  • Recommendations remain distinguishable from system facts
  • Humans retain approval, risk acceptance, signature, payment, and material configuration authority
AIPrepare · Advise
SystemCalculate · Record
HumanApprove · Decide

Bring your security and AI review questions.

We’ll walk your team through access, audit history, data protection, and AI controls.

Request a working session