Governed
by execution.
Most AI governance is documentation — binders, sign-offs, evidence assembled by hand. R1's governance executes: every AI request checked in-path, every refusal recorded, every dollar accounted. Live, in public.
Two kinds of AI governance exist. Only one is running here.
- Policy binders and sign-off workflows
- Evidence assembled by hand, after the fact
- Deployment checked once, at release
- Answers live in a private dashboard
- Every request checked at execution, in-path
- Evidence written by the enforcement itself
- Budgets refused in real time — per principal, per operation
- Refusals and spend published on this page
Disabled model → refused. Exceeded budget → rejected. Missing route → error. Every gate refuses in-path. No tokens, no spend, no exceptions.
Every AI capability is registered as a governed purpose with its own routing, budgets, and audit trail. If a capability is not on this list, it does not reach a model.
chatresume · signup-resumeanalysis · career-analysisjob-extract · job-enrichembeddingintelligence-*Token-level governance tells you what the model cost. Decision-level governance tells you who it helped decide — and that is where hiring law lives.
Assistance, enumerated
Every AI touchpoint in a hiring workflow is a governed purpose — parse, match, analyze, draft. The touchpoint list is a query, not an investigation.
Decisions, recorded
Alongside token events, R1 records hiring decisions with reasoning in the decision audit trail — AI assistance and human verdict, bound together.
Humans, accountable
The system records assistance; people own verdicts. Accountability chains end at a person, which is what regulators and auditors actually ask for.
It records accountability — never content.
- Operation and purpose of every call
- Requested model vs. model that served
- Token counts — prompt, completion, total
- Cost per request, month, principal
- Latency and terminal status
- Route revision in force
- Hashed principal and billable owner
- Prompt text or model responses
- Candidate documents or profiles
- Message or conversation content
- Un-hashed identifiers
Append-only. Monotonic config revisions. History cannot be rewritten — only extended. Exportable for compliance review.
Stated plainly: what the architecture supports today, and what remains ahead.
Employment and recruitment are named high-risk. The obligations — documentation, logging, human oversight — are the artifacts this system produces by executing.
Annex III — high-riskBias audits require enumerating every AI touchpoint in hiring. Purpose-bound governance makes that enumeration a query, not a project.
Audit-ready data modelAdverse-impact review needs the exact boundary of algorithmic assistance in selection. Purposes draw it explicitly, per operation.
Boundary documentedOn the roadmap: independent third-party bias audits, provider attestations, gateway content guardrails. A governance page that overstates is itself a governance failure.
Three rules the system is built on.
Governance must execute
A policy that cannot block a request is a suggestion. Controls run in the request path — enforcement is code, not documentation.
Every token is accounted
No AI request exists outside the ledger. Unlogged spend is a defect, not an edge case.
Humans decide
AI ranks, drafts, extracts, analyzes. Hiring decisions remain with people — the system records assistance, never verdicts.
Proved in public, not requested in private.
Enterprise dashboards ask you to trust them. R1's infrastructure is published, live, and independently checkable — three layers, one position.