Portfolio, obligations, and control status as of batch 2026-07 — covering internal agents, vendor-platform agents, and every team in scope. Six items need attention before the 27 Jul cycle.
8 +4
Agents governed
8 internal · 4 vendor platforms
23/23
Use cases tiered & owned
100% coverage
6
Needs attention
1 sign-off · 5 client inputs
0
Open AI incidents
1 near-miss YTD · closed
43
Decisions on record
append-only · 0 edits
Dimension status
Weight = regulatory pressure + data exposure + gap · recalculated per batch
Dimension
Pillar
Weight
Maturity
Open items
Next review
D6 · Data Authorization
Foundations
9 · Critical
1.0 / 4
1 rule review due
27 Jul
D2 · Exposure Tiering
Outward-facing risk
9 · Critical
1.5 / 4
0
27 Jul
D10 · Audit & Assurance
Technical assurance
9 · Critical
1.0 / 4
2 evidence gaps · T4
27 Jul
D8 · Incidents
Outward-facing risk
8 · Critical
1.0 / 4
runbook in draft
Sep 26
D1 · Decision Rights & Portfolio
Strategy
7 · Elevated
2.0 / 4
1 sign-off · 2 assessments
27 Jul
D5 · Vendor Exposure
Economics
6 · Elevated
1.5 / 4
4 embedded-AI flags
Q3 scan
D7 · Cost & Value Activated
Economics
6 · Elevated
1.5 / 4
3 metered lines on watch
Monthly
D9 · Workforce Capability
Strategy
5 · Standard
3.0 / 4
leadership session Aug
Aug 26
D11 · Brand & Trust
Outward-facing risk
5 · Standard
1.0 / 4
profile in draft
Q4 26
D3 · Lifecycle Health
Foundations
4 · Standard
2.0 / 4
5 graduations blocked
27 Jul
D4 · Evaluation
Technical assurance
Deferred · DEC-0022
—
live-state preview ready
Q1 27
D12 · Agent Safety
Technical assurance
Deferred · DEC-0022
—
2 platform-agent flags live
Q1 27
Tasks due before next batch
27 Jul 2026
Payroll calendars — scope decision on Pay Period rulePilot-client audit finding · awaiting sponsor & COO-office sign-off
Inforce reconcile — tier/plan crosswalk + match keysPending from client
Client input
D3
Verify BAA eligible-services listMonthly re-verification · rule set v1.2
Scheduled
D6
Recent decisions
append-only ledger · newest first
DEC-0043
Agent composition standard adoptedUse cases cluster by workflow · skill · data affinity · 11 Jul
Approval
DEC-0042
Cost & Value activated ahead of scheduleToken economics adopted as programme module · 10 Jul
Activation
DEC-0041
Add-in surfaces set to Never for member dataPending BAA coverage change · 30 Jun
Rule
Workspace · Agent registry
Agent registry
Every agent in scope for the organisation — 8 internal agents composed from the 23 Phase 1 use cases, and the vendor-platform agents arriving inside existing contracts. Internal agents cluster on workflow affinity · skill affinity · data affinity. Open any agent to see its composition.
The most consequential table in the workspace: which AI surface may touch which data class. PHI rows are decided by verified BAA coverage — never by convenience. One near-miss YTD was caught by exactly this discipline.
Coverage is not uniform across the vendor's own products. Chat and Projects sit under the executed BAA; the Excel/PowerPoint add-ins and the desktop agent product do not (today). The matrix below is why that distinction is enforced as a rule, not a habit. Monthly verification due 27 Jul.
Authorization matrix · rule set v1.2
R-101 – R-120 · verified 13 Jul
Surface
PHI / member data
Client-confidential
Internal
Public
Rule
Claude chat BAA workspace
Min-necessary
Allowed
Allowed
Allowed
R-101
Claude Projects BAA workspace
Min-necessary
Allowed
Allowed
Allowed
R-102
Excel / PowerPoint add-ins not on eligible-services list today
Never
Never
Allowed
Allowed
R-104
Desktop agent (Cowork-class) not covered today · re-review on vendor change
Never
Never
Case-by-case
Allowed
R-105
Connectors (M365 · Monday · Zoom) Work Orchestration pilot scope
Append-only record of approvals, rules, corrections, activations and deferrals — grouped by what each decision governs. Entries cannot be edited after commit; supersessions link forward.
Five tiers, adopted as v1.0 (DEC-0035), assigned by a scored five-question protocol — deterministic by design: same inputs, same tier, every time. The empty T5 row is the point: nothing here warrants prohibition-level exposure, and the model proves that rather than asserting it.
23 +8
Classified
use cases + composed agents
4
T4 use cases
quarterly re-tier · full packs
0
T5
prohibition list empty
Tier definitions · v1.0
Tier
Meaning
Count
Controls
T1
Internal · no client or member data
0
AUP only
T2
Internal work product · anonymised or internal data
6
Tower-owner approval
T3
Client-facing output · human reviews before send
13
Named reviewer · SC approval
T4
Regulated-adjacent or connector-scope work
4
Joint approval · full evidence pack · quarterly re-tier
T5
Prohibited — autonomous regulated decisions, PHI on uncovered surfaces
0
No path — bright line
Scored protocol · 5 questions
0–14 → tier
Question
Scores
Q1 · Highest data class touched
0–3
Q2 · Audience of the output
0–3
Q3 · Regulatory adjacency
0–3
Q4 · Error blast radius
0–3
Q5 · Autonomy of action
0–2
0–2 → T1 · 3–5 → T2 · 6–8 → T3 · 9–11 → T4 · 12–14 or any bright-line hit → T5 · two assessors, independent scores
"A human reviewed it" must be provable. Every T3+/T4 workflow carries a four-part evidence pack — configuration, boundary rules, review record, outcome sample — assembled on demand for a client audit, a DOL inquiry, or an OCR question.
2/4
T4 packs complete
2 gaps in flight
2
Audit packs delivered YTD
sponsor questionnaire · broker RFP
< 1 day
Pack assembly time
target for any examiner ask
Evidence completeness — T4 and highest-volume T3
4 components per pack
Workflow · agent
Config
Boundary rules
Review record
Outcome sample
Pack
File triage & fix-it note Filing Data Agent · T4
Held
Held
Held
Held
4/4
Intake snapshot Filing Data Agent · T4
Held
Held
Held
Held
4/4
Inforce reconcile Data Integrity Agent · T4
Held
Held
Held
Gap
3/4
FLOW orchestration Work Orchestration Agent · T4 pilot
Held
Held
Gap
Held
3/4
Gaps assigned with owners · close-by 27 Jul · OCR dry-run pack in draft as the Q3 exercise
No internal agent has write scope today — so full agent-safety controls are deferred honestly rather than performed. What is not deferred: the watchlist. Vendor platforms are shipping agents into the tenant right now, and named internal triggers would activate this dimension the day autonomy arrives.
Watchlist — live flags
reviewed each batch
Flag
What's happening
Why it matters here
Status
monday.com native agents
Platform shipped agents to all customers, no setup required · Agent Accounts let external agents authenticate into tenants
Boards hold live client casework — an agent acting on them would be an ungoverned write actor
Live in tenant
HubSpot Breeze agent lineup
Customer, Prospecting and Data agents GA · Assistant on every seat · outcome-based pricing
Autonomous client-facing replies drafted from CRM data — brand and advice-bounds exposure
Intake pending
Recap & board write connector
Caseload Agent's natural next step is writing recaps onto boards directly
First internal write scope — crosses the autonomy line
Trigger armed
FLOW write-back
Work Orchestration pilot could graduate from read + draft to task write-back
Same line, wider surface (M365 · Monday · Zoom)
Trigger armed
Activation switches on: autonomy fields in the registry · action logging · kill-switch standard · autonomy budget per agent
Workspace · Obligations
Obligations register
The regulatory surface Selerix's AI programme answers to — federal frameworks in force, state AI statutes, and what is on watch. Each obligation maps to the controls that satisfy it. Prepared with programme counsel input; not legal advice.
All · 10Federal · 6State · 4In force · 7On watch · 3
Obligation
Status
What it demands of AI use
Mapped controls
Review
Federal
HIPAA Privacy & Security Rules45 CFR 160/164 · PHI at the core of the platform
In force
Minimum-necessary PHI on covered surfaces only · BAA before any disclosure to an AI vendor
Who approves what, and the org-wide AI portfolio those decisions govern. Every use case has a named approver and a tier-driven approval path — the ERISA "prudent process" answer.
100%
Portfolio with named approver
no orphaned use cases
3
Pending decisions
oldest 9 days
4.2 days
Median time-to-decision
target ≤ 7
5
Functions in portfolio
Eng & Product intake Q3
Approval queue · 3
the assessment sits behind each pending decision
Decision
Waiting on
Holder
Age
Payroll calendars — Pay Period scope ruleCase Setup Agent · pilot-client audit finding · option (b) recommended with named-reviewer check on every derived row
Sign-off
Sponsor & COO office
9 days
New use case — Broker RFP supportScored 6 → Tier 3 proposed · conditions drafted: named reviewer, house voice pack, no commercial commitments from a draft
Compliance endorse
Compliance lead
5 days
Engineering & Product AI intakeCode assistants + in-product AI · same intake door, same protocol · nothing scored until intake
Zero open incidents — and a discipline built so the first real one is handled inside HIPAA's 60-day clock, not discovered against it. Near-misses are captured deliberately: the programme's one save so far produced a permanent gate.
0
Open incidents
YTD
1
Near-miss captured
caught pre-delivery → DEC-0038
3
Tabletops scheduled
W3 safety practices
Severity matrix
runbook v0.4
Sev
Definition
Clock
S1
Confirmed PHI on an uncovered surface / disclosure
Activated ahead of the original deferral — because AI cost stopped being one licence line. The operating principle: cost follows autonomy. Humans-in-chat cost a flat seat; the moment work graduates to skills, agents and platform toggles, cost becomes metered.
Illustrative figures. Dollar amounts on this page are programme estimates at list pricing for teaching and planning — not invoices. Token economics is now a taught module in the AI Gym.
~$2.1K/mo
Estimated AI spend today
seats ≈ 90% of it
73%
Seat utilisation · 30 seats
9 daily · 13 weekly · 8 light
3
Metered lines on watch
tokens · credits · per-seat creep
Aug
Value evidence lands
blind-eval + time-capture readout
Cost lines — every source, one table
reviewed monthly
Line
Model
Today · est.
What moves it
Watch
Claude seats · 30
Fixed per-seat
~$1.9K/mo
Headcount only — usage inside a seat is free at the margin
Stable
API tokens at skill graduation
Metered per run
~$120/mo
Each prompt → skill graduation moves runs from seat to meter
Watch
M365 Copilot
$30/user/mo if licensed
$0 today
30 seats would add ~$900/mo — governance position before licensing, not after
Creep risk
HubSpot Breeze credits
Credit-metered · outcome-priced
$0 today
Customer Agent bills per resolution once enabled — cost scales with autonomy
Watch
monday.com agents
Included today · pricing evolving
$0 today
Vendor pricing for agent actions under review industry-wide
Monitor
Zoom AI Companion
Bundled with paid seats
$0 marginal
No direct line — exposure is data, not dollars
Stable
Unit economics — the teaching card
AI Gym token module
Inforce reconcile, one run: ~90K input tokens + ~8K output ≈ $0.31/run at API list. At 150 reconciles a month ≈ $47/mo — replacing hours of side-by-side comparison per run. Fix-it note, one run: ~25K in + ~3K out ≈ $0.10/run.
The lesson the cohorts learn: token cost is almost never the constraint — review capacity is. The economics justify far more automation than the named-reviewer gates currently allow, which is exactly why the gates, not the budget, are the control.
Usage distribution — 30 seats
Jul batch
Band
Seats
Profile
Daily
9
ACA analysts + EDI — Gym habits carried into live work
Weekly
13
CSM + Shared Services — workflow-triggered use
Light
8
Adjacent roles — coaching targets for the W6 champion push
Utilisation is the leading value indicator this early — the Aug readout pairs it with blind-eval quality scores and time capture
Every AI use case in scope carries a named owner, an exposure tier and a recorded decision. Two dimensions remain deferred on the record (DEC-0022) with live watch flags; one scope decision is waiting on the sponsor and COO office before the 27 Jul cycle.
Exposure position
Four use cases sit at T4 with full evidence packs required; the prohibition tier is empty. Data authorisation is enforced per surface — PHI is permitted only where BAA coverage is verified monthly, and the one near-miss this year was caught by that check before any exposure.
What changes next cycle
Two audit-evidence gaps close by 27 Jul. Vendor-platform agents already live in the tenant enter the registry before any enablement. Cost and value reporting is now active, ahead of the original deferral.