Governed intelligence infrastructure

One governed intelligence layer.

Designed to connect the systems you already run, read-only, preserving authority over every record. They stay authoritative.

Syndric · connections read-only
Financeread-only
Identityread-only
Operationsread-only
Governed layersource · programme
Programme Aexplicit grant
Programme Bexplicit grant
RecordSourceSync runProgrammeLineage
Record 1financerun 1programme Apreserved
Record 2identityrun 1programme Apreserved
Record 3operationsrun 2programme Bpreserved
Record 4financerun 2programme Bextended
Record 5identityrun 3programme Apreserved
Record 6operationsrun 3checking...preserved
Grant resolution · deny by default
• Programme A: read granted, scoped to its own records.
• Programme B: read granted, scoped to its own records.
• Cross-programme: no policy exists, every crossing refused.
• Absence of a grant is denial, everywhere.
• Enforced in the database, below the application.
✓ resolved before anything is read
Programme B requests a Programme A record
resolving grant
Refused. No grant exists, and absence is denial. The boundary is enforced in the database, below the application.
policy set: empty · every crossing refused
Nothing replaced. Nothing pooled.

The systems work. The questions that span them do not.

A single question can involve the finance system, the payments processor and an operational database, held by different teams with different rules about who may look. Syndric is built to carry that question across them, without moving authority over anything.

Across systems

Cross-system answers

Questions that span finance, operations and casework, answered from governed records, with the supporting records identifiable. Designed on controls that already hold, never promised in their place.

Declared once

Deterministic rules

Conditions the organisation cares about, declared once, evaluated on schedule, producing findings that carry their evidence. Rule truth is deterministic; it is never a model's opinion.

To accountable owners

Scheduled operational intelligence

A regular operational picture, assembled only from what each recipient is entitled to see. The foundation is built to carry it, and authority is settled first, every time.

The governed layer

One Governed Layer

Every record keeps its source, its history and its authority.

Read-only by construction.

The connector contract has no write operation to invoke.

Context preserved.

Source, time, sync run and programme, stamped at ingestion.

Grants decide access.

No record is readable without an explicit grant.

Intelligence, designed on top.

Built to carry answers that trace to entitled records.

“Across multiple departments, the same programme was being tracked in separate systems. Each team could see its own records. Nobody could see where the numbers stopped matching. Once the records were connected, the gaps became visible.”
Illustrative institutional pattern · not a live deployment
The model

Systems connect. Authority stays put.

Syndric is a governed layer above your systems, not another system of record. It does not merge their contents into one undifferentiated store.

How boundaries hold

Connect

Read-only by construction

Connections are read-only by construction: the connector contract has no write, update or delete operation to invoke.

Preserve

Context at ingestion

Every record is stamped as it enters: source, record identity, time, sync run, and the programme it answers to. Lineage is never silently lost.

Resolve

Authority at the data layer

Access requires an explicit grant, enforced in the database itself, below the application. No grant means no access.

Built to carry intelligence

Built to carry intelligence you can defend.

Control first, intelligence on top. These surfaces stand on controls that already hold.

Provenance Proven

Records keep their context

Source, time, sync and programme travel with every record, and transformations extend lineage.

Boundaries Proven

Programme isolation

Enforced in the database, so an application defect alone cannot cross the programme boundary.

Intelligence Designed

Programme-level views

Each programme working from its own operational picture, and only its own. Designed, on controls that hold.

The mechanics

Connected does not mean exposed.

Connecting a system grants no person and no programme any right to see its data. Access requires an explicit grant, enforced in the database itself, and today every crossing between programmes is refused.

record · financestamped ✓
record · identitystamped ✓
record · operationsstamped ✓
derived rowlineage extended

Records keep their context

Every record resolves to its source, its sync run and the programme it answers to.

IFno grant exists
THENaccess is refused
IFthe policy set is empty
THENevery crossing is refused

Absence means denial

A missing, invalid or unavailable rule never widens access. Refusal is the resting state.

Programme Agranted
Programme Bgranted
Cross-programmerefused
Query roleread-only

Boundaries at a glance

Each programme reads its own records, and only its own.

Evidence

Demonstrated, recorded and kept.

Syndric is developed against a written architecture, and every property below has been demonstrated mechanically, with the evidence recorded and kept.

01Isolation enforced by the database. Connected directly to the database as the query role, with the application bypassed, a principal cannot read another programme's records.
02Denial by default. An identity with no grant is refused everything, and a broken permission source refuses rather than continues.
03Audit records cannot be edited. No application role holds the privilege to change or delete them.
04Provenance from the first moment. Every ingested record carries its source, time and sync history, and transformations extend that lineage.
05Ingestion survives failure. An interrupted sync, retried, converges to the same state, and an unexpected source change halts visibly.
06Reproducible releases. The same commit is built twice, and the digests must match before publication.

The evidence behind each of these statements, and the precise boundary of each claim, is documented for review.

The order of operations

Authority is settled before intelligence begins.

01

Signing in is not authority

An authenticated identity has access to nothing until a grant says otherwise, and a missing or broken rule never widens access.

02

Boundaries are enforced in the database

Isolation between programmes is a property of the database, not of application code, so an application defect alone cannot cross the programme boundary.

03

Intelligence cannot grant access

No model output can establish a permission, an authoritative figure or a legal determination. Deterministic systems decide, and the intelligence layer explains.

Most intelligence products decide what to show after they have read everything. Syndric resolves who may see what first, deterministically, below the layer that does the reasoning.

Execution history

We have connected real systems before. Before this platform.

An earlier system, built and run for a private multi-branch operator. It predates the architecture described on this page and does not run it.

6
operating branches connected through one deployment
~500k
rows of transaction history ingested
60+
endpoints integrated from a system with no public documentation
8
structural findings surfaced during the initial deployment

That system's record is evidence of execution, not of this platform's guarantees. Those are being established on their own evidence, and recorded.

Where it applies

Built for organisations with more than one authority inside them.

The architecture fits wherever independent parts of one organisation, or several cooperating organisations, must act on shared questions without surrendering control of their own records. These are deployment patterns the architecture is designed for, not descriptions of existing installations.

Deployment patterns

  • Diversified groups with entity-level authority
  • Government and public-sector programmes
  • Regulated enterprises answerable for every answer
  • Multi-entity operational programmes

What it isn't

  • Not a shared multi-customer data store
  • Not a replacement for the systems you run
  • Not a system of record
  • Not a decision-maker. People decide, it informs
Honest limits

What it doesn't do. Yet.

01The intelligence surfaces are designed, not live. Cross-system answers, rules and scheduled intelligence are what the foundation is built to carry.
02No crossing operates today. The policy model ships empty, and empty means every crossing is refused.
03Isolation is proven at the query plane. The demonstrated boundary is the one a reader of data meets, and its scope is documented precisely.
04Connections are proven against synthetic sources. Source-side behaviour is re-proven for every real system before production.
Security & boundaries

Read-only. Deny by default. Enforced.

Access to your systemsRead-only by construction; no write operation exists read-only
Access to recordsExplicit grants only; absence is denial deny-by-default
Programme boundariesEnforced in the database, at the query plane database
Audit recordsAppend-only, by database privilege append-only
DeletionPropagates through derived stores, audited propagated
ReleasesImmutable, versioned, reproducible reproducible
FAQ

Questions, answered.

What is Syndric, exactly?+

Governed intelligence infrastructure. It is designed to connect, read-only, to the systems a complex organisation already runs, preserving where every record came from and which part of the organisation holds authority over it. Who may see what is enforced at the data layer, and the systems you run stay in place and stay authoritative.

Does connecting systems expose data across programmes?+

No. Connecting a system grants no person and no programme any right to see its data. Access requires an explicit grant, the boundary is enforced in the database itself, and today every crossing between programmes is refused.

What exists today, and what is designed?+

In place and demonstrated: read-only connections by construction, provenance stamped at ingestion, grant-based access enforced in the database, append-only audit, failure-safe ingestion and reproducible releases. Designed on top of that: cross-system answers, deterministic rules and scheduled operational intelligence. The distinction is stated plainly wherever it matters.

Do our systems get replaced?+

No. Syndric is a layer above the systems an organisation runs, not another system of record. Your systems remain the authoritative record, and nothing is merged into one undifferentiated store.

Is our data safe?+

Connections are read-only by construction: the connector contract has no write, update or delete operation to invoke. Access to records requires an explicit grant, audit records cannot be edited by any application role, and deletion propagates through derived stores with the action itself audited.

Will it make decisions about people?+

No. By architectural rule, no model output can establish a permission, an authoritative figure or a legal determination. Deterministic systems decide, the intelligence layer explains, and judging remains a human's job.

How do we engage?+

Start with the questions your technical and governance teams will ask anyway. We built for those. Write to contact@syndric.io and bring your hardest ones.