The process is yours. The AI works inside it.
Forge is built on three principles. They are not a feature list. They are an argument about where AI should sit in an organisation that has to answer for its work.
They are also three dimensions of one thing: control of how AI is used in a company, so the work is defensible and provable to stakeholders, customers, auditors and regulators. Redaction covers privacy. A process you determine, with AI working inside it, covers reliability. The record covers accountability.
Control here does not mean restricting what your people may do with AI. It means the company keeps control of what leaves, of how the work is done, and of what can be shown afterwards, without anyone having to remember a rule.
Principle one
Protect the data by construction, not by policy.
The usual answer to confidential material reaching an AI tool is a policy telling people not to do it. Policies do not fail because people are careless. They fail because the material that most needs help is the material you least want exposed, and the person with the deadline is the one deciding.
So Forge removes it before it can leave. Email addresses, phone numbers and card numbers are replaced with placeholders on the way out, and the real values are put back into the answer the person reads. It is on by default, and an administrator can require it across the organisation so that nobody can switch it off for themselves.
Being exact about this matters more than sounding thorough. Forge redacts structured personal details of those kinds. It does not claim to recognise every sensitive thing in every document, and a promise that broad would be worth less than the narrow one that is true.
Do not tell people not to leak the data. Build a system where the exposure does not happen in the first place.
Principle two
Bring AI into the workflow. Do not hand the workflow to AI.
An agent is given a goal and works out its own steps. For open-ended work that is the right design, and the industry is right to pursue it. For a business document process it means the steps can come out differently on the next run, and nothing records which ones were taken.
Forge inverts that. Your organisation defines what happens and in what order, and each part of the job goes to whatever is actually good at it.
- AI models read, interpret and reason over the document.
- Your own programs handle computation and data processing.
- Deterministic rules enforce your policies, checks and business logic.
- People review and approve where judgement is required.
The AI is a component of the process rather than its controller. The next step does not change because a model decided it should.
This is not a claim that agents have no place in business. It is a narrower claim, and a firmer one: where predictability, reliability and accountability matter more than autonomy, the process should be deterministic and the AI should be used where reasoning genuinely helps.
Agentic AI optimises for autonomy. Forge optimises for predictable business outcomes.
Principle three
Make the work reconstructable.
Governance is a word every vendor uses. The concrete version is a question an auditor asks six months later, about one document, and the only useful answer is evidence.
Who brought this document in, and what happened to it?
- Who introduced it, and when.
- Who was permitted to reach it.
- What was sent to a model, and what was masked before it went.
- Which program ran, and which rules were applied.
- What the AI produced, and what the rules decided.
- Who reviewed it, and who approved it.
- What was finally produced, and what it cost.
Every important step leaves a record, and the record is content-free: it holds who did what and when, not the text of anyone’s work. Oversight does not have to mean reading your people’s conversations, and it should not.
Not “we have governance”. Six months later, you can reconstruct what happened.
Why the features belong together.
Read as a product list, Forge looks like an assortment of security and workflow features. Read against the principles, each one is an implementation of a specific commitment.
| Redaction before the model | Protect |
| Access granted per project | Protect |
| Defined workflows | Control |
| Your own programs, run sealed | Control |
| Deterministic rules | Control |
| Human review and approval | Control and prove |
| Audit log, usage attribution, retention evidence | Prove |
AI should be a component inside an organisation’s controlled operating process, not an autonomous replacement for the process itself.
