Records held on behalf of the public sit under residency and protection obligations that a masked prompt does not satisfy. The safest architecture is the one where nothing crosses at all.
Serve citizens with AI.
Without their data leaving.
Public bodies hold the one dataset that cannot be handed to an external provider, and answer to the one audience that will never accept “the model decided.” Chakali puts agentic AI inside the boundary, under policy your own officials set.
The constraints are not
a matter of preference.
What one ministry may see, another may not. AI that flattens those boundaries in the name of a better answer creates an incident, not a capability.
Anything issued in the authority’s name can be challenged. A drafted response needs a named human owner and a record of what informed it.
Assurances do not survive an evaluation. Controls have to be demonstrable, and the evidence has to be exportable in a form a reviewer accepts.
Real work, inside the boundary.
Your teams compose these from the Skills and Tools that installed Solutions provide. Each one runs under the same identity, policy, approval and evidence model.
Correspondence and case drafting
Draft replies to citizens and to other authorities, grounded in the relevant policy and prior decisions, with the officer who owns the response approving it before anything is issued.
Policy research across the archive
Ask questions across legislation, circulars, prior positions and internal guidance, and get answers with provenance attached rather than a confident paragraph with no sources.
Inter-ministerial briefing packs
Several specialist Agents assemble a position from the same evidence, surface where they disagree, and hand the decision owner one briefing rather than five opinions.
Service desk and intake triage
Classify, route and prioritise incoming requests under rules the department sets, with anything consequential stopping for a person instead of resolving itself.
Every consequential step
has a name against it.
- 01Identity and department
Every request carries who is asking, from which department, holding which entitlements. Nothing runs anonymously.
- 02Classification scope
Retrieval is bounded by what the requester is actually cleared to see — not by what the model could find.
- 03Policy evaluation
Deterministic rules set by your own officials decide whether the work proceeds. The model does not adjudicate its own permissions.
- 04Named approval
Anything issued in the authority’s name waits for the accountable officer, and the approval is bound to that exact action.
- 05Evidence record
Identity, purpose, sources, models, tools, policy decisions, approvals and outcome — retained together and exportable for review.
Deployment follows your risk position.
For classified and protected workloads, Chakali runs entirely disconnected on infrastructure the authority controls.
Inside the government data centre, integrated with the existing identity provider and security controls.
Where an approved national cloud is the standard, the same control model applies with the boundary drawn there instead.
Which modelsClassified and citizen-data workspaces run closed, on open-weight models inside your own infrastructure. Where a department works on already-public material — legislative research, open consultation analysis, published guidance — policy can permit an approved external model for that workspace alone, with the run record showing exactly which model was used and on what. Compare the deployment patterns →