Approach

Governance is a gate, not a report

Most systems add governance afterwards, as review: a document produced once the decision has already been made and acted on. That arrangement can describe a failure. It cannot prevent one.

We build the other way round. A decision passes defined gates before it reaches anyone, the gates cannot be traded off against each other, and a person remains accountable at the point where it matters. What follows is the same discipline applied across all three platforms, to a student’s assessment, to a research finding, and to whether a piece of work was worth doing.

The framework

Governance by design

In apto the governance gates are not a compliance layer. They are the engine. Every learning experience passes independent validation at every stage, or it does not ship. It is a Learning Constitution, drawn from a defended doctoral thesis and enforced in code.

The six gates

Every decision runs the gauntlet of six meta-governance processes. All six must pass.

MP1

Critical Inquiry & Grounding

Veto-capable

Claims are interrogated and grounded in evidence rather than asserted. Reasoning is logged, not assumed.

MP2

Architectural Integrity

Veto-capable

Cross-component consistency is verified, and every decision is recorded in a formal Architecture Decision Record, built for accreditation audits.

MP3

Vision

Veto-capable

A lexicographic value hierarchy ensures justice and dignity are never traded off for efficiency.

MP4

Grounding & Application

Veto-capable

Abstract designs are validated against the institutional context (regulatory, infrastructure, economic and cultural), and the no-myopia guard is applied.

MP5

Synthesis

The prior gates are integrated into one coherent decision. When something upstream is wrong, this is where it surfaces and is blocked.

MP6

Evaluative Governance

Veto-capable

A non-compensatory four-pillar audit: Efficacy, Fairness, Validity, Governance. Traceability must exceed 90%, and the demographic fairness gap must stay within 2% across all groups.

Non-compensatory by design

One pillar cannot offset another. A strong score on five gates cannot buy a pass on the sixth. If any single gate fails, the decision is quarantined. It is referred back to the responsible agent to fix and resubmit, or escalated to a human in the loop.

Nothing reaches a learner until all six gates pass and the ethics gate is clear.

A continuous ethics veto

Beyond the six gates, a dedicated ethical core can veto at any step, not just at the end. Privacy processing operates on encoded learner signatures, never raw personal data.

A no-myopia guard

Decisions are weighted toward long-term competency over short-term engagement, so the system cannot game a metric at the expense of real learning.

Equity, ecology & privacy

Governance is not only about quality. It is about who the system works for. apto models the learner’s whole context and is built to protect them.

Whole-context modelling. Bronfenbrenner’s five ecological systems: device and bandwidth tier, caregiver time, institution and culture. It works offline, in low-resource settings.
Privacy by architecture. Around 1,000 learning dimensions and zero PII. The codec carries scores, not personal detail, so minimisation is structural rather than configured.

Governance you can audit

Every decision carries a causal trace. See how that plays out for an institution.

Human in the loop

People stay in charge of the AI

The human-in-the-loop engine, HICE, is the part of apto that keeps people in control. It routes AI recommendations to the right people, gauges whether an institution is ready, supports educators through the change, and lets the system and the institution grow together.

What HICE does

Four jobs, all pointed at the same goal: a person is always accountable for what reaches a learner.

A human review gateway

Before an AI recommendation reaches a learner, the right person can review it, approve it, or override it. The decisions that matter are made by people, with the AI doing the analysis underneath.

Institutional readiness

We assess how ready an institution is across six operational domains and match the rollout to it, rather than dropping the same deployment on everyone. No institution is set up to fail.

See the readiness model

Educator transition

Educators move from delivering content to designing learning. Their judgement is an input the system works with and learns from, not something it tries to replace.

Co-evolution

The institution and the system adapt to each other over time. Trust is earned from real decisions and outcomes, rather than assumed on day one.

Why a human layer at all

Most education AI asks the learner to do less and the institution to trust more, with no way to check either. HICE is the opposite. It makes the human decisions visible, gives educators a real say, and earns trust one decision at a time.

It is the human half of governance by design. The other half, the gates every learning experience must pass, lives in the framework.