Skip to main content

Govern · Compliance, audit, policy

BUILT

Govern · Compliance, audit, policy

Honos. Who may decide what, on the record.

Nerio sees and proposes. Minerva acts. Honos decides who may authorize what, routes every request to that person by a versioned policy, and keeps the decision with the evidence that was in front of them. It is the part of EOS a risk committee reads.

It works on its own: your people can raise requests directly without Nerio, and without Minerva the decisions export to the systems you already run.

See Honos on the platformSee the record

What it enforces

Six rules, each one a test.

RuleWhat it means
Routing is a functionThe route is computed from the request and the policy version, so the same request on the same policy always goes to the same people, and a changed route means a changed policy, which the version names.
Every clause is namedA request carries every clause that fired, so nobody has to reconstruct why it went to Finance.
A named person decidesEach step records who decided, the clause, the policy version, the evidence they saw and why.
The wrong approver is refusedA decision from someone the step does not name is refused with 403, not logged and ignored.
A rejection is finalA rejected request cannot be approved afterward; a new request is raised instead.
An agent cannot decideA principal may propose; only a person decides, at every step.

The default policy

ClauseWhen it firesStep
spend.over.50kamount over $50,000Finance director
spend.over.10kamount over $10,000Budget owner
risk.highrisk marked highSecurity review
vendor.newa supplier not yet on recordNew supplier check
category.legalcategory is legalCounsel
defaultnothing else firedManager

Every clause, step and threshold is yours to set; the policy is data with a version, not code.

The record and its reports

What was decided leaves as a report anyone can check.

Reports are how the record leaves the building, which is why they live here rather than on a page of their own. Six types. Every figure OBSERVED or DERIVED with its rule named; inference is refused at the boundary. Currency converts only at your own recorded rate, and a report refuses rather than invents one. Each run is sealed with a hash anyone can recompute from the rows, offline, and every run and every read is an entry on your organization's chain.

ReportWho may run it
Ledgerowner, admin, controller
Decisionsowner, admin, auditor
Discrepanciesowner, admin, auditor
AI activityowner, admin, auditor
Tax viewowner, admin, controller
Sealed packowner, admin

Nerio, the read sideMinerva, the write sideRequest an assessment

Fides: what may cross a boundary →

What this enterprise runs

Every module is optional, and that is enforced rather than promised.

Nerio, Minerva, Honos, Fides, Forculus, Portunus, Reports and the analytics modules (scorecards, frameworks, costing and planning) are turned on and off per organization. A call into a module you do not run is refused by name before it reaches the module, so nothing has to remember to check. Dependencies hold in both directions: Minerva cannot be enabled while Honos is off, and Honos cannot be turned off while Minerva is on.

Every change names the person who made it and the reason, and is hash-chained with the rest of your record. An organization with no record runs everything, and turns off what it does not want.

ClauseWhat it means
module.personOnly a named owner or admin turns a module on or off. An agent principal never may.
module.unknownA module that does not exist is refused by name, with the list of those that do.
module.dependencyA module cannot be enabled while something it needs is off. Minerva needs Honos, because it executes only what a person authorized.
module.dependentA module cannot be disabled while something that needs it is on.
module.offA call into a module your organization does not run is refused by name, and the refusal says who can turn it on.

Turn one off on the platform

Forculus: the door between the record and the machine →

Film · two minutes

Who may decide what, on the record.

The six rules and the default policy, a named person deciding with the evidence in front of them, the chain every decision sits on, and why nothing in EOS acts without Honos.

The EOS family

NerioAssessAwareness, insight and resilienceMinervaActionExecute, reverse, recordHonosGovernCompliance, audit, policyFidesPartnersIdentity, collaboration, permissionsForculusIntegrateAPIs, gateways, interoperability, digital and physical, roboticsPortunusTraceIdentity, custody, carbon, end of life

Also from AssetShop

Fourteen other products, none of them part of EOS. Separate products, no shared runtime, tenancy or credential path. Nothing below is included in an EOS evaluation or an EOS contract. Each carries its status, and nothing is called built until it is.

Enter the consumer layer at assetshop.eth EOS is the Enterprise Operating System. The brand layer it belongs to is name-native. Past that line the rules are different, and it is built by Shadow Key.

✓
Privacy notice · no tracking
This site uses no third-party tracking, no advertising cookies, no analytics beacons.
A single first-party cookie remembers your preference for dismissing this notice. We follow GDPR + CCPA + state-equivalent privacy laws by default. Full detail in our Privacy Policy and Cookies Policy.