Decision automation for regulated operations

Automate the decision. Keep the proof.

AI Rule Engine runs the judgment calls your team makes by hand - claims triage, eligibility, prior authorization, underwriting referral - and records exactly why each one went the way it did. Deterministic rules decide. AI reads the parts only a human could read before. A person handles the exceptions. Every run leaves a trace an auditor can follow.

Runs in your own Azure tenant · Every decision traced, versioned, and replayable · Human approval built in

The proof is the product

Plenty of tools will run your workflow. The question that decides whether you can put one in front of a regulated process is what it can tell you six months later.

Every decision shows its work

A run records which rules fired, in what order, and the actual values each condition matched on, along with every change made along the way. Not a log line saying it happened. The reasoning that got there.

Ask why the answer is missing

Name the answer you need and the engine works backwards to establish it. When it cannot, you get a proof tree naming the fact that was absent, instead of a confident wrong answer.

Conclusions that withdraw themselves

When a fact behind a conclusion changes, the conclusion retracts rather than going quietly stale. Stale derived facts are how automated decisions get indefensible.

Caught before it runs

Static verification flags rules that can never fire, duplicates, conflicting writes, and input combinations no rule covers. Saved test cases run on every change, and a release can be blocked until they pass.

Where AI fits, and where it does not

The reason a general workflow tool is a bad home for a regulated decision is that it has no opinion about this. Ours does. AI turns unstructured input into facts: it classifies a loss description, extracts a value from a document, summarizes a long clinical history. Those become facts on the run.

Rules you wrote and approved decide what the facts mean. No model applies a threshold, interprets a policy, or picks the outcome. The boundary is enforced by how the workflow is built, so you can point at the rule behind any decision rather than at a paragraph in a governance policy.

You choose the model per step across Anthropic, OpenAI, Azure OpenAI, Google Gemini, and xAI, using your own provider keys.

Built for the security review

The controls a mid-market regulated buyer filters on, and a straight answer on the ones we do not have yet.

Identity and access

SSO over OIDC and SAML 2.0, DNS-verified domain capture, enforced SSO, SCIM provisioning from Entra or Okta, custom roles, periodic access review, and IP allowlisting.

An audit trail that holds up

Append-only audit events capturing the actor and address, exportable as CSV or JSON and streamable to your SIEM off the request path.

Evidence you can verify yourself

Every publish produces an RSA-SHA256 signed record, verifiable against a public key, proving the logic in force on a given date has not been altered since.

What we do not have

No SOC 2 attestation, no DPA or BAA yet, no third-party penetration test. We say so on the security page rather than leaving you to find it in the questionnaire.

Detailed Feature Overview

Runs in your cloud, not ours

On a dedicated deployment, AI Rule Engine installs into your own Azure subscription through an Azure Marketplace managed application. Rule data, execution history, uploaded files, and AI prompts never leave your tenant, and pairing it with Azure OpenAI keeps the model calls inside your boundary too.

For most security reviews that is the whole conversation, because the compliance boundary is one you already own and already assess.

Detailed view of scalability and security features on Azure

Rules your policy owner can read

Build decisions as decision tables and nested conditions, not code. The people who understand the policy can maintain the logic that implements it, and publishing is gated behind approval so authoring access is not production access.

Rules re-fire as their own results change the facts other rules read, so a chain of small decisions cascades to a final one without anyone scripting the order.

Detailed view of flexible rules engine interface

An answer inside your own request

Post the decision inputs to a single endpoint and get the outcome back in the same call, with the run recorded and traceable. Actions that would park a run for later are refused on this path rather than silently changing the contract.

When a decision genuinely needs to wait, on a slow integration or a human approval, the asynchronous path handles it without holding up anything else.

Detailed view of API access interface

Test it before anyone relies on it

Save test cases against a ruleset and run them on every change. Replay historical cases in a sandbox that produces no side effects, compare a proposed change against the current logic, and gate a release on the whole suite passing.

Promote the tested release between environments through a deployment pipeline instead of editing production directly.

Detailed view of asynchronous workflow tasks interface

Extend it to fit your stack

Wrap your own logic in custom extensions and call them straight from your rules. Add new actions, conditions, and data sources so the engine matches how your business actually works instead of forcing your process to match the tool.

Detailed view of customizable extensions interface

When an AI agent acts, it acts through a rule

Your organization is being asked to let Claude, Copilot, and ChatGPT touch internal processes. The usual options are to say no, or to hand an agent broad credentials and hope.

AI Rule Engine gives each agent its own token over the Model Context Protocol, scoped to the exact rulesets, files, and log entries you allow and nothing else. Whatever the agent triggers runs through the same rules, the same approval steps, and the same audit trail as everything else, so an agent cannot reach a decision path a person could not.

Frequently asked questions

What is AI Rule Engine?

AI Rule Engine automates operational decisions that are governed by written policy - claims triage, eligibility determination, prior authorization, underwriting referral - and records why each decision went the way it did. Deterministic rules make the call, AI reads unstructured input into facts, and a person handles the exceptions.

What does an auditor actually see?

The inference trace for the run, showing which rules fired, in what order, and the values each condition matched on. Alongside it: the exact published ruleset version that produced the decision, the person who approved that version, and an RSA-SHA256 signed release record that proves the logic in force on that date has not been altered since.

Does AI make the decision?

No. AI classifies, extracts, and summarizes unstructured input such as documents, notes, and free-text descriptions, and its output becomes a fact on the run. Rules you wrote and approved decide what those facts mean. No model applies a threshold, interprets policy, or picks an outcome.

Can this run inside our own cloud?

Yes. Enterprise includes up to three dedicated hosts deployed into your own Azure subscription through an Azure Marketplace managed application. Rule data, execution history, uploaded files, and prompts never leave your tenant, and paired with Azure OpenAI the model calls stay inside your boundary as well.

What happens when the rules change?

A change is authored as a draft, checked by static verification for rules that can never fire, conflicting writes, and uncovered input combinations, run against your saved test cases, and published behind an approval. Prior versions stay intact, and every past decision remains explained by the version that produced it.

How fast is a decision?

The synchronous endpoint returns the decision inside your own request, with a default 30 second budget you can lower per call. It is a real run, so it still produces a run record and a full trace rather than a bare answer.

What compliance certifications do you hold?

None yet. There is no SOC 2 attestation, no DPA or BAA on offer, and no third-party penetration test. The security page states this plainly and lists the controls that do exist, including SSO over OIDC and SAML, SCIM provisioning, IP allowlisting, custom roles, and an append-only audit trail with SIEM streaming.

How much does it cost?

Free is $0, Pro is $49 a month, Team is $199 a month, and Enterprise is a flat $999 a month for 50 environments, 500,000 runs, 25 author seats, and up to 3 dedicated hosts. Larger or non-standard requirements are handled on a Custom plan.

Bring us one decision you make by hand

Pick the decision that costs your team the most time and the most argument. In one working session we will model it, run it against your own examples, and show you the trace it produces. If it is not a fit, we will tell you.