Skip to main content

Portfolio Authority Scan

See what AI can change before it changes the company.

Invite one consenting portfolio company and bring its existing materials. EMILIA maps where AI can move money, change access or infrastructure, expose data, alter regulated decisions, commit the business, or affect physical operations. The company chooses what to control.

Scan prepares the decision; it does not grant authority or activate Gate. The company keeps its keys, approvals, and detailed evidence.

Start
One company
Coverage
Seven action lanes
Output
Source-linked map
Next move
One Gate boundary
Illustrative company workspaceNo files submitted here
Portfolio companyNorthstar Components
Example only
Money
Change vendor bank detailsAP workflow · payments API
Review
Identity
Grant production administrator accessAccess policy · cloud action inventory
Review
Data
Export customer recordsRunbook · OpenAPI operation
Review
Recommended first boundary
Vendor bank-detail changeOwner confirmation and bypass review required

Every candidate stays linked to its source. Unknown paths and missing evidence remain visible instead of being converted into a confident score.

One company in. One decision out.

Stop asking portfolio teams to inventory AI risk from memory.

The Scan turns existing technical and operating materials into a review queue that a CFO, CTO, security leader, or business owner can correct. The result is not another broad risk score. It is a practical map from evidence to action to the first control decision.

Portfolio Authority Desk

Bring the materials already sitting inside the company.

We agree a buyer-approved intake and handling plan with the portfolio company before any material moves. No public file upload happens on this page, and we do not pretend every arbitrary format is already supported.

Starting inputs

No blank-page questionnaire.

Start with supported, governed evidence the company already knows how to produce.

  • Repository and action inventories
  • MCP and OpenAPI manifests
  • Workflow and approval documents
  • Governed system exports

Company-wide consequence map

Look across the business, not just the finance stack.

Money and assets

Payments, disbursements, and vendor banking changes

Identity and privilege

Access, credentials, roles, and account changes

Systems and code

Cloud, infrastructure, deployments, and production operations

Data and privacy

Disclosure, export, sharing, and protected information

Regulated decisions

Records, determinations, approvals, and case outcomes

External commitments

Contracts, notices, submissions, and business promises

Physical operations

Devices, logistics, facilities, and real-world actions

01

Action register

See where consequences can happen

A source-linked inventory groups candidate actions by consequence, affected system, current owner, and available evidence.

02

Owner questions

Give owners a short list, not a binder

Named company owners confirm, correct, or reject candidates. Missing sources, unknown paths, and unsupported formats stay visible as blind spots.

03

Draft protection plan

Know what to protect next

The reviewed register recommends one bounded action for Gate design, with its executor path, authority owner, evidence needs, and unresolved blockers.

Sponsor may receiveBuyer-agreed coverage and implementation evidence
Portfolio company retainsKeys, policy, approvals, credentials, and detailed records

The engagement path

Scan the company. Protect one boundary. Then earn the rollout.

The assessment makes the first control decision easier. The pilot has one fixed public finance scope. A portfolio program begins only after a consenting company accepts its boundary and operating model.

01First step · scoped intake

For one sponsor and one consenting portfolio company

Portfolio Authority Scan

Set up a buyer-approved company workspace, bring the materials already on hand, and map candidate high-consequence actions across seven operating lanes.

Evidence output

A source-linked action register, owner questions, explicit blind spots, and a draft protection plan with one recommended Gate boundary. No authority is created.

Add and map a portfolio company
021 protected workflow · 90 days · $25K

For one sponsor and one consenting portfolio company

Portfolio Authority Pilot

Take one reviewed finance action from the Scan, validate it in synthetic and buyer-approved read-only modes, and design the completely mediated customer-owned Gate boundary.

Evidence output

A path map, draft control package, authority and evidence rule, acceptance plan, limitations, and buyer-owned go or no-go decision.

Protect one portfolio boundary
03Scoped after boundary acceptance

For a sponsor funding a repeatable rollout pattern

Portfolio Authority Program

Deploy company-owned Gates by consenting portfolio company, operate the accepted boundaries, and add scoped assurance services without centralizing company keys, credentials, or raw action evidence.

Evidence output

Buyer-agreed coverage and control-operation evidence. It is explicitly not an investment-safety certificate.

Discuss a portfolio rollout

Control plus assurance

Evidence for each layer, without a black-box certificate.

Gate controls the crossing. The Assurance Plane can verify, assess, re-perform, and package the resulting evidence. A customer-appointed auditor, underwriter, regulator, or other authorized reviewer keeps its own conclusion.

Posture and coverage evidence are not action admission. Admission evidence is not provider outcome or real-world effect proof. Each claim keeps its own evidence boundary.

Schema v1 · canonical SHA-256 digest · covered and example uncovered paths · fail-closed unknown-ID requirements. The file is illustrative and non-authoritative.

Open verification

Self-directed

Re-perform a supplied assurance package under your own pinned inputs with the open ep-assure procedure.

Tests what the supplied evidence supports. It does not establish source truth or deployment coverage.Run the open procedure

Deployment Assurance

Scoped service

Review complete mediation, bypass routes, trust pins, replay state, failure behavior, retention, and active refusal probes for named boundaries.

A vendor or customer deployment assessment, not independent certification.Inspect Deployment Assurance

Continuous Assurance

Scoped service

Build content-addressed evidence packages on an agreed cadence and re-perform claimed verdicts to name drift, refusals, and missing evidence.

The workpaper leaves an auditor or assurer conclusion blank by construction.Inspect Continuous Assurance

Warranted Gate

Separate contract after baseline

A separately negotiated warranty may cover named Gate behavior at named enforcement points, for a named period and contractual limit.

It does not warrant investment performance, legal compliance, wisdom, source truth, or bypassing actions.Read the warranty boundary
Evidence, not a certificate.EMILIA does not currently operate a public certification scheme and does not issue an audit opinion, accredited certification, insurance conclusion, or investment-safety rating.

Synthetic proof, not company intake

See one finance precheck after you understand the Scan.

The Portfolio Action Risk Lab is a public demonstration, not the assessment. Provision one scoped observe-only key for Northstar Components, a fictional company consenting to this synthetic exercise. Keep one payment-release boundary fixed, then compare a single-signoff result, a dual-signoff result, and a hard refusal.

  • No ERP connection
  • No real account or vendor data
  • No money moved or blocked
  • No production protection implied
OBSERVE ONLY

This synthetic lab evaluates metadata. It does not authorize, block, mutate, or execute a production finance action and does not establish complete mediation.

Consenting sandbox subjectNorthstar Components
FICTIONAL
01 / Provision

Create a scoped key for one fictional payment boundary.

The key is born for observe mode. It cannot turn this exercise into enforcement or reach a production ERP, bank, or payment rail.

The first engagement

One finance workflow. 90 days. $25K.

A fixed scope creates a real decision point: accept a completely mediated Gate design, keep observing, or stop. It does not require a portfolio-wide platform commitment.

01

Map the company, choose the action

Run the Portfolio Authority Scan, review source-linked candidates with company owners, then select one vendor bank-detail change or payment-release path for the fixed pilot.

02

Prepare, then observe

Use Scan to prepare the customer-reviewable draft package, then run synthetic and buyer-approved read-only validation without changing production behavior.

03

Make a buyer-owned decision

Deliver the boundary design, acceptance evidence, limitations, and operating procedure. End with a buyer-owned go or no-go decision; any production Gate implementation is separately scoped.

Buyer receives

A bounded implementation decision, not a promise of universal safety.

  • One protected-workflow definition and path map
  • Customer-pinned authority and evidence rule
  • Observe-mode precheck findings and limitations
  • Boundary acceptance plan and operating procedure
  • Payload-minimized sponsor evidence design

The claim boundary

Control the crossing. Keep the conclusion honest.

On completely mediated covered paths, the exact action must arrive with accepted authority and required evidence before it can enter the consequential provider.

Gate can enforce

The customer's rule at a covered action boundary

Exact action, finite authority, required evidence, refusal, one-time admission state, and an action-bound record under the customer's pinned trust inputs.

Gate does not establish

Truth, wisdom, legality, or a successful effect

Bank-detail correctness, payee identity, fraud absence, provider success, unmediated paths, investment performance, and legal or audit conclusions require separate evidence.

Inspect the engineering and security boundary

Questions operating partners ask

What the portfolio model does and does not mean.

Does EMILIA make a private equity investment safe?

No. EMILIA does not cover every agent risk or make an investment safe. Gate controls one bounded class of action risk at a configured boundary when every covered path to the consequential system crosses the control and the customer configures the authority and evidence rules. Source truth, bypass paths, fraud absence, provider outcome, legality, and business wisdom remain outside the claim.

Does the sponsor control each portfolio company's keys or approvals?

No. The deployment model keeps credentials, trust roots, authority rules, and detailed action evidence with the portfolio company. A sponsor can fund a common control pattern and receive only the buyer-agreed, payload-minimized implementation evidence.

What can a sponsor standardize across the portfolio?

A sponsor can standardize the boundary review, minimum control contract, evidence fields, rollout criteria, and payload-minimized reporting format. Each portfolio company still decides its authority rules and retains its keys, credentials, detailed approvals, and action records.

Does EMILIA issue a certificate for a portfolio company?

No. EMILIA can produce scoped verification results, conformance records, deployment assessments, assurance packages, and workpapers whose inputs and limitations travel with them. These are not an audit opinion, accredited certification, or proof that an organization or investment is safe.

What can an independent reviewer reproduce?

A reviewer can re-run supplied evidence packages under independently pinned keys, profiles, clocks, and input digests, then compare the result with the runtime claim. Re-performance can expose missing or inadmissible evidence and drift; it cannot recover live state that was never recorded or establish source truth.

What do we bring to a Portfolio Authority Scan?

Start with materials the company already has: repository or action inventories, MCP and OpenAPI manifests, workflow and approval documents, and governed system exports. We agree the intake, handling, supported formats, and company owner before materials move. This page is not a public file-upload portal.

What does the Portfolio Authority Scan return?

It returns a customer-reviewable, source-linked action register, owner questions, explicit blind spots, and a draft protection plan with one recommended Gate boundary to investigate first. It does not authorize an action, activate Gate, certify a deployment, or prove that every effect path is mediated. Buyer acceptance and a separately scoped Gate implementation are still required.

What does complete mediation mean?

Every path capable of producing the covered effect must cross Gate at the executor or system-of-record boundary. A sidecar, prompt filter, or voluntary agent call cannot constrain an alternate path that bypasses the deployed control.

Does the Portfolio Action Risk Lab move or block money?

No. It provisions a scoped observe-only sandbox key and evaluates fictional finance-action metadata. It does not connect to an ERP, change vendor data, release a payment, authorize production use, or provide production protection.

What is included in the first pilot?

One buyer-selected vendor bank-detail change or payment-release workflow, 90 days, and a fixed $25K scope. Work remains synthetic and read-only. The pilot ends with a buyer-owned go or no-go decision; any production Gate implementation is separately scoped after buyer acceptance.

Start with one portfolio company

Turn scattered company evidence into the first control decision.

Tell us which consenting company you want to assess. We will agree the workspace, supported materials, company owner, and the smallest scan-to-pilot scope that can produce a defensible next step.

Customer deployment path only. EMILIA is not an insurer, auditor, investment adviser, or accredited certifier and does not make investment-safety claims.