You retain platform control.
Frankie is the intended Cairn platform owner. That role manages the service and its workspaces. Customer records still require customer membership or explicitly granted support access.
Set the scenario. See the decision. Follow the evidence.
Interactive simulation. Use invented data only. Scenarios stay in this page and reset on reload. No payments, emails or support tickets are sent. Role switching illustrates access; it is not a sign-in system.
Preparing the first decision…
This demonstration omits live tool execution, velocity and cumulative limits, content scanning and independently protected evidence storage. Customer policy and integrations must be agreed and tested for a pilot.
Read the product guides →The reviewer sees the proposed action, the matched rules and the policy recorded at the time. An operator cannot approve it, and the requester cannot approve their own request. Approval here records a simulated authorisation; it does not execute a tool.
Search the recorded facts, including scenario names, people, tools and rule IDs. Open an entry to inspect its full record and its link to the previous entry.
Verification recalculates SHA-256 links and checks the exported checkpoint. Test an edited copy to see the break. Browser data can be rewritten; this is not independent proof against its owner.
Choose a persona above to try each view. In the customer application, membership and permissions are enforced on the server. In this public demo, the selector illustrates those permissions.
| Role | Run scenarios | Review holds | Export evidence | Manage customer team |
|---|
Frankie is the intended Cairn platform owner. That role manages the service and its workspaces. Customer records still require customer membership or explicitly granted support access.
Customer owners and administrators assign workspace roles. Operators propose actions; auditors inspect evidence. A requester cannot act as their own second reviewer.
Switch between Northstar and Harbour to illustrate separate ledgers. Both contain invented examples visible in this browser. Live customer isolation requires the deployed application.
“Cairn checks an AI agent’s proposed action against your rules, holds sensitive actions for a second person, and records the decision so your team can inspect it.”
Ask which tools it can call, what a wrong action would cost and who owns the decision. Start with one workflow: customer refunds.
Use Maya’s operator view. Evaluate a routine refund, one needing review and one over the demo limit. Open the matched rules so the buyer sees exactly why the outcome changed.
Open Approvals, then switch to Theo, the customer administrator. Review Maya’s £750 request and record a reason. Explain that approval is bound to this request and policy.
Switch to Robin, the auditor. Search for the rule or scenario. Open the entry, export the evidence, verify it, then test an altered copy. Show the access matrix and the separate customer workspace.
Propose a scoped pilot: agree rules and owners, run known safe and unsafe cases, check approvals and evidence with the customer, then decide whether to integrate. Agree measures and responsibilities before committing to live execution.
Explore a pilot →“This is an interactive demonstration using synthetic data. The policy engine and customer application are built and tested locally. Hosting, identity setup, transactional notifications and the customer’s tool integration still need to be deployed and validated before a live pilot.”
A hash chain makes edits detectable against a trusted checkpoint. It is not a guarantee that the person controlling all storage cannot rewrite it. Independent evidence custody is a separate production requirement.