Joint Tactical Operations Centre - Governed Decision Architecture

Manage your security, resilience and AI |
in a governed, intelligence-led environment.

Collaborative, multi-stakeholder networks that integrate your information, people, processes and AI agents seamlessly, helping you to synthesise data and achieve fast, trusted outcomes, compliance and defensible decision advantage.

DORA

DORA

Requires financial entities to evidence ICT governance and incident response.

Penalty: Up to €10m or 2% of global turnover.

NIS2

NIS2

Requires documented risk management and incident reporting for essential and important services.

Penalty: Up to €10m or 2% of global turnover for essential entities.

SM&CR

SM&CR

Senior Managers & Certification Regime: named senior individuals must be personally accountable for decisions within their scope, with an auditable record.

Penalty: Unlimited FCA fines; criminal prosecution possible.

s166 FSMA

s166 FSMA

Firms must produce complete, accurate records of how decisions were made and governed when the FCA demands them.

Penalty: Enforcement action, public censure, and significant financial penalties.

EU AI Act

EU AI Act

High-risk AI systems require logs, human oversight evidence, and documentation of how AI-influenced decisions were controlled.

Penalty: Up to €35m or 7% of global turnover.

HIPAA

HIPAA

Requires documented evidence of who accessed, used, or disclosed protected health information and under what authority.

Penalty: Civil penalties up to $1.9m per category; criminal penalties up to $250k and 10 years imprisonment.

FINRA

FINRA

Broker-dealers must maintain complete records of decisions and communications, with supervisory controls demonstrably in place.

Penalty: Fines into the tens of millions; potential suspension or industry bar.

GDPR

GDPR

Organisations must demonstrate lawful basis for data processing and evidence that data subjects' rights are upheld in practice.

Penalty: Up to €20m or 4% of global turnover.

FedRAMP

FedRAMP

Cloud providers seeking US federal contracts must demonstrate continuous monitoring and an auditable record of system governance.

Penalty: Loss of authorisation to operate and disqualification from federal contracts.

Duty of Care

Duty of Care

Requires evidence that reasonable steps to prevent foreseeable harm were actually taken, not merely stated in policy.

Penalty: Unlimited civil liability in negligence claims.

<10 min
Deployment time
Sovereign-capable
BYOD, BYOK, BYOM, BYOI
AI-queryable
Rapidly synthesise data. Reconstruct on demand.
Immutable
Every record, permanently attributed
The Commercial Problem

How do you operate effectively in an AI-first and regulated market?

Every organisation faces the same challenge: remaining competitive while being able to prove how consequential decisions were made.

01

Do Nothing

  • Remain exposed across DORA, NIS2, the EU AI Act, GDPR and beyond.
  • Limited ability to evidence how consequential decisions were made.
  • High regulatory, insurance and legal risk.
  • Evidence remains fragmented and silo'd.

Maximum EU AI Act penalty:
€35 million

02

Build In-house

  • Complex, time-consuming and resource-intensive.
  • Systems still need to be maintained, integrated and updated as regulations evolve.
  • Years of development and ongoing maintenance cost.
  • Evidence remains fragmented and silo'd.

Years of investment.
Ongoing liability exposure.

03

Buy The Stack

  • Multiple separate tools, vendor relationships and implementation projects.
  • Sensitive operational data handled differently across separate systems.
  • Sovereignty risk at every seam.
  • Evidence remains fragmented and silo'd.

Full stack ≈£600k / year
before implementation

04

Deploy a JTOC

  • One governed operational environment.
  • Security & governance capabilities integrated.
  • Sovereign by architecture.
  • Evidence generated as a byproduct of operations, and accessible on demand.

Deployable in 10 minutes
No procurement cycle
No 6 month integration project
≈2% of the equivalent stack cost

The Compliance Challenge

Can you prove how consequential decisions were made?

Across high risk sectors, regulations threaten significant penalties if you or your clients cannot evidence decision making.

Departments are siloed. Data is fragmented. AI is deployed without sufficient oversight. During operations and incidents, the same questions arise:

  • Who was present?
  • What did they know?
  • What was relied upon?
  • What did they authorise?
  • What changed, and when?
  • What did they choose not to do?

A technical log doesn't say who was accountable, or why.
Building and maintaining systems to improve compliance capability is time and resource intensive.

  • The JTOC is a governed decision environment
  • Each workspace is deployable in 10 minutes
  • Manage your physical, cyber & AI operations within it
  • Evidence is generated and accessible as a byproduct
  • Ideal for individual projects, SMBs or jurisdictions
What the JTOC provides

Multiple operational challenges. One consolidated solution.

Where other systems require multiple separate tools, the JTOC addresses each within a single governed operating environment.
Governance operates continuously through architecture, not documents.

Identity and Access

Commander's Intent defines who has authority to act. Every stakeholder individually invited. Every action attributed to a verified identity.

£

Standalone Market Cost

Okta, Microsoft Entra or equivalent. Enterprise identity and access management typically costs £30,000 - £80,000 per year, before implementation.

Data Protection

Sovereign isolated instance per organisation. BYOD, BYOK, BYOM, BYOI. Data ingested and synthesised within the boundary. Nothing leaves to a shared or open system.

£

Standalone Market Cost

Microsoft Purview, Varonis or equivalent. Enterprise data protection and sovereignty typically costs £25,000 - £60,000 per year.

Agent and Input Security

MCP-compatible agent connectivity under Commander's Intent. Every query crossing the MCP boundary attributed and logged.

£

Standalone Market Cost

TrueFoundry, IntentGate or equivalent. Agent security and input controls typically cost £20,000 - £50,000 per year.

Multi-Stakeholder Collaboration

Executive, operational and supporting teams, legal counsel, insurers, regulators, clients, in one governed workspace. Full situational awareness. Every exchange attributed.

£

Standalone Market Cost

Microsoft 365 E5, Slack Enterprise or equivalent. Governed collaboration infrastructure typically costs £40,000 - £100,000 per year.

JTOC

Collective intelligence architecture for
Security, Resilience and Defence

Each JTOC is up to 50x LESS cost.

- A full security & governance stack is estimated at ≈ £600k / yr.
- The JTOC integrates all 8 capabilities from 2% of that expense.
- No procurement cycle. No 6 month integration project.

Governance and Compliance

Immutable audit log, Decision State Record, evidential export. Every decision permanently attributed and reconstructable across DORA, NIS2, SM&CR, EU AI Act and beyond.

£

Standalone Market Cost

OneTrust GRC and AI Governance or equivalent. Enterprise governance and compliance platforms typically cost £35,000 - £120,000 per year, with a minimum annual contract of £8,000.

Output Validation

Decision State Record captures what intelligence was relied upon, what was excluded, credibility assigned at the time, and the human disposition.

£

Standalone Market Cost

Credo AI, Fiddler or equivalent. AI output validation and explainability tools typically cost £20,000 - £60,000 per year.

Monitoring and Observability

Real-time intelligence synthesis and situational awareness. Data provenance detection surfaces unauthorised modifications to connected data.

£

Standalone Market Cost

Datadog, WhyLabs or equivalent. AI monitoring and observability platforms typically cost £15,000 - £50,000 per year.

Institutional Memory

The governed record persists independently of individuals. Knowledge compounds automatically. Absence and inaction are evidenced, not assumed.

£

Standalone Market Cost

Glean, Confluence Enterprise or equivalent. Enterprise knowledge and institutional memory infrastructure typically costs £25,000 - £80,000 per year.

The AI Lifecycle

Security and governance are not one moment. They are six.

Security provides the environment in which governance can be implemented safely.

AI systems move through 6 phases - from first design through to eventual decommissioning. Phases 1 to 3 belong to your AI development and engineering practices. The JTOC's boundary begins the moment a model goes live - phases 4 to 6 - and, even there, some risks sit outside it.

Every risk below is also marked as either a Security issue (attack surface, malicious actors, technical vulnerabilities) or a Governance issue (decision-making/accountability, enforcement, evidence/transparency). Within its boundary, the JTOC ties each in-scope risk to a specific control - such as Commander's Intent or the Decision State Record - that makes it attributed, evidenced, and reconstructable on demand.

Security: attack surface, malicious actors, technical vulnerabilitiesGovernance: decision-making, accountability, evidence

Click any of the 6 phases above to see their risks - and the controls provided by the JTOC architecture.

Incident Management and Mass Notification

Notify at scale. Authorise every message. Prove it afterwards.

Incidents require more than internal coordination. Staff need instructions, customers need updates, regulators need notice within a defined window.
Sending that notification is itself a consequential decision - what was said, to whom, and when - and it carries the same liability exposure as any other decision made under pressure.

Notify from inside the JTOC

Reach all stakeholders without leaving the governed environment. Connect your familiar channels - including MS Outlook, WhatsApp and SMS - once and they are available the moment an incident begins.

Every communication is attributed

Access to each messaging channel is authorised in advance. Once granted, every message sent is attributed to the individual the moment it happens.

Dispatch is evidenced

What was sent, which group or channel it was sent to, and when, sits permanently in the record. Regulator notification obligations are proven, not assumed.

How it works

From zero to operational in three steps.

Each JTOC deploys quickly and operates continuously, with generative and agentic AI supporting both internal and client projects.
Zero Trust security architecture is built in. No lengthy enterprise integration. No infrastructure build. Negligible cost of ownership.

1
Launch your JTOC(s)
  • Deploy as standard SaaS, on private cloud infrastructure, or on-premise.
  • Operational in under 10 minutes.
  • Launch multiple instances to serve different clients, business departments, projects or operations.
  • Each JTOC instance has its own isolated database, governable according to each unique remit.
  • Create full stack corporate or multi-jurisdictional decision infrastructure and switch between instances seamlessly.
SaaSPrivate cloudOn-premiseUnder 10 minutes
2
Configure your intelligence feed and your team
  • Connect your data sources. Upload your documents (policies, SOPs, guidelines, research).
  • Configure your intelligence feeds and your AI agents.
  • Connect your external (mass) communication channels, including MS Outlook, WhatsApp and Slack.
  • Define your stakeholder groups and set access controls.
  • Invite colleagues and supporting personnel, including the executive team, legal counsel, insurers, client POCs.
  • Every invitation is a governed act recorded in the audit trail.
BYODBYOKBYOMBYOI
3
Operate continuously
  • Query your intelligence in natural language and synthesise data across all connected sources.
  • Collaborate in a governed, multi-stakeholder environment with full situational awareness.
  • Build an immutable record of every decision, action, and absence automatically as a byproduct of operations.
  • The JTOC is steady-state infrastructure. It is not incident-response software you activate when something goes wrong. The governance record already exists when you need it.
Who the JTOC serves

From frontline teams to the boardroom.

Tactical

Field Teams and Duty Officers

Real-time coordination during live incidents. Shared situational awareness with full attribution of who knew what, when.

Operational

Head of Security and CISO

Cross-functional decision-making with governance. Every authorisation, escalation, and handoff is permanently recorded.

Strategic

Legal, Insurers and Regulators

Reconstructable evidence of governance at any future point. Proof that decisions were informed, authorised, and documented.

Your Knowledge Base

Infrastructure that is always on, so you build powerful organisational memory.

The JTOC is not incident-response software that you only activate when something goes wrong.

It is steady-state infrastructure that governs every decision, every day.
- When an incident occurs, the governance record already exists.
- When a regulator asks questions, the evidence is already complete.
- When details of a previous project need to be recalled, retained knowledge is available on demand.

Most governance tools require manual activation, manual documentation, and manual compliance. The JTOC inverts this model. Governance is the default state. Every interaction, every decision, every piece of intelligence that enters the workspace is automatically attributed, timestamped, and made permanently queryable.

Regulatory drivers

Built for the regulatory and security landscape ahead.

DORANIS2SM&CRs166 FSMAEU AI ActHIPAAFINRAGDPRFedRAMPDuty of Care

Regulatory frameworks increasingly require organisations to demonstrate not just what they did, but how decisions were governed. DORA mandates ICT incident governance. NIS2 requires documented decision-making during cyber events. SM&CR holds individuals accountable for decisions within their scope.

The JTOC provides the evidence infrastructure these frameworks demand.

When you need a JTOC

Six scenarios. One solution.

Regulatory investigation

Reconstruct exactly who was present, what intelligence was available, and what decisions were made during any incident window.

Insurance claim defence

Provide immutable evidence that your organisation responded appropriately, with the right people, using the right information.

Live incident coordination

Coordinate across legal, cyber, HR, PR, and operations with automatic governance. No manual minute-taking required.

Board and executive reporting

Generate AI-powered summaries of incident response for board reporting, with full attribution and timeline reconstruction.

Non-regulated sectors

Even without regulatory obligation, the JTOC provides the governance infrastructure that insurers increasingly expect and investors reward.

Cross-organisational response

Bring external advisers, insurers, and regulators into a governed workspace without compromising internal security boundaries.

Deployment

Your infrastructure. Your rules.

White-label channel

Include the JTOC, under your own brand, as part of your risk management services portfolio, to help reduce your and your clients' liability exposure, simultaneously.

Osinto identity layer

Leverage the Osinto identity and verification infrastructure for participant authentication and attribution.

MCP-compatible

Model Context Protocol compatibility for integration with AI agents, copilots, and automated decision-support systems.

What practitioners say

From the people who need it most.

We needed to prove to our insurer that the right people were in the room and that decisions were documented in real time. The JTOC gave us that evidence without changing how we actually work.

Head of Security, Financial Services

During a live incident, the last thing you want is to worry about governance. The JTOC handles it silently in the background. When the regulator asked questions six months later, we had everything.

CISO, Critical Infrastructure

Can you prove the decisions you made under pressure?