Australian Government AI governance platform

Every AI use case, governed.

One governance thread from use case to runtime.

The use case is the unit of accountability and the running AI system is the unit of control. Remit binds them end to end at the Operate Gate.

  • 01Register

    Every AI use case on one register, checked against the policy’s own in-scope criteria. AI proposes; a person decides.

  • 02Assess

    The DTA impact assessment, guided: official questions, guidance and risk matrix, with the agency’s evidence beside each answer.

  • 03Approve

    Evidence-backed sign-off with conditions. Records lock at approval, and every later change is reasoned and audited.

  • 04Discover

    Finds the agents, models and identities running on your platforms, read-only, and proposes the use case each serves.

  • 05Operate Gate

    A use case reaches Operate only once its approval, system, identities, region and controls stand. An unanswered check holds it.

  • 06Assure

    Continuous at every stage: register integrity, platform risk and security signals, incidents to your service desk, the DTA register.

  • Policy-native

    Appendix C, the DTA impact assessment and the register, in the DTA’s own words and formats. Nothing to configure.

  • Evidence-backed

    Answers cite the agency’s own documents, so approvers see the proof before they sign.

  • Continuously assured

    Records checked against their evidence, and running agents against their platforms’ own risk and security signals.

  • Connected to runtime

    Read-only connections to the cloud and AI platforms your agents run on, and incidents ticketed into your own service desk.

Product update · September 2026 · 1:58

Where Remit stands today. Every screen real.

Seven problems agencies meet with AI today, then the fourteen capabilities Remit brings to them, each shown on the product’s own screen from its demonstration agency. Built first for Australian Government agencies; going global next, with policy packs for each jurisdiction’s AI framework. We still have features to build, and we share each step as we go.

Read the words on screen (the film has music and no speech)

Opening

  • AI is moving into production.

The reality today

  • AI arrives faster than it can be registered.
  • Approvals stop at a signed document.
  • Agents run on platforms no register can see.
  • Nobody can say what changed since approval.
  • Evidence is scattered across inboxes and drives.
  • Policy moves. Records don’t.
  • Assurance becomes a spreadsheet exercise.
  • Governance has to move at the speed of AI.

Introducing

  • Introducing Remit, AI governance platform.
  • One governance thread from use case to runtime.

Business accountability

  • 01 Home: the whole portfolio, and what is held at the Operate Gate.
  • 02 AI use case register: every use case’s scope, assessment and inherent risk, at a glance.

Policy

  • 03 Policy scope check and intake: Appendix C, asked in the policy’s own words.
  • 04 AI impact assessment: the DTA’s assessment tool as a guided workflow.
  • 05 Approvals and conditions: evidence-backed sign-off, with conditions that hold.

Runtime control

  • 06 Runtime inventory: every agent actually running, read from each platform and linked to its use case.
  • 07 Connected platforms: each cloud and AI platform, read-only, environment by environment.
  • 08 Agent security: the platform’s own security verdicts on the agent, and three jailbreak attempts, blocked.
  • 09 The Operate Gate: every deployment checked before it operates, and held until it passes.

Control validation

  • 10 Runtime check: seven steps, from the use case to the platform’s own reporting, on demand.
  • 11 ISM assurance: ASD ISM controls, evaluated against what the platform reports.
  • 12 Register integrity: every record checked against its evidence; each finding waits for a person.

Evidence and reporting

  • 13 Reporting and DTA export: the register in the DTA’s own format, ready to submit.
  • 14 Audit log: append-only. Every action, by whom, and why.

Close

  • Fourteen capabilities. One connected platform.
  • One governance thread from use case to runtime.
  • Private preview coming soon. remitai.com.au

Why Remit

Most tools manage a slice. No one owns the thread.

Model platforms run the AI, agent registries list it, GRC tools hold the approvals and service desks hold the incidents, so accountability breaks between approval and runtime. Remit keeps one governance record across all of them, built for the Australian Government policy from the first use case.

Built for the Australian Government policy

The policy scope check asks the policy’s own Appendix C sentences. The assessment is the DTA’s AI impact assessment tool, question for question. The register exports in the DTA’s own format. Nothing to configure before the first use case.

Evidence-backed, not box-ticked

Answers cite the agency’s own documents. Approvers see the evidence behind every claim, and the register integrity check reads each record against its documents and says where they disagree.

Bound to what actually runs

Each approved use case is linked to the agents, models and identities running on your connected platforms, read-only, and its record holds at the Operate Gate until the evidence stands.

AI that assists and never decides

AI drafts, checks and cites, with every quote verified against its source and every call logged with its cost. It never rates a risk, approves, signs or sends anything to the DTA. Your people decide.

How it works

Seven stages, one governance thread.

Every AI use case moves through the same seven stages, from the policy scope check to the running system, and every stage leaves evidence behind it. Assurance is not a stage: it runs across all seven.

  1. 01

    Register

    Record the use case and run the policy scope check in the policy’s words. AI can propose the answers; a person records the decision.

  2. 02

    Assess

    The DTA impact assessment as a guided workflow: the threshold sections for every in-scope use case, the full assessment where risk demands it.

  3. 03

    Approve

    The approving officer signs off on the evidence, with conditions. The record locks and every later change carries a reason.

  4. 04

    Deploy

    Record what implements the approved use case: the deployment, and the agents, models and identities Remit found running in it.

  5. 05

    Operate Gate

    Remit’s own control. The use case waits here until its approval, running system, identities, region and control evidence all stand.

  6. 06

    Operate

    In operation and read on a schedule: register integrity, the platform’s own risk and security signals on each agent, incidents and reporting.

  7. 07

    Change

    When the use case or what runs it changes, re-validation opens a new assessment version and the thread starts again, history kept.

Runtime control

Governance that reaches the running system.

Most AI governance stops at the approval. Remit reads what is actually running, read-only, and holds every use case to it: the agents, the models they call, the identities they run as, and what each platform itself reports about them.

Discovery, read-only

Cloud resources, AI agents and model deployments, agent identities and agent registries, read through a published register of the only calls Remit may make on each platform.

Linked, never guessed

A platform’s own tag proposes the use case an agent serves, and a person confirms it. One agent seen by two platforms is linked, never merged.

The Operate Gate

Five layers checked for each deployment: governance, architecture, identity and data, region, and assurance. A check nobody could answer holds the gate.

The platform’s own verdicts

The platform’s own risk rating of each agent identity, and its security alerts and blocked actions on each agent. Kept as the platform’s, and never read as safe when nothing is reported.

ISM controls on evidence

Information Security Manual controls evaluated against what the platform reports, with an assessor register for what the evidence cannot show.

A runtime check per agent

On demand, seven steps from the use case to the platform’s own reporting, each saying what it found, how long it took and what it cannot establish.

AI cost

Cloud AI token use, the agency’s own cost export and AI seat licences, attributed to the use cases that spend them where the evidence allows.

No score, no guesswork

No compliance percentage anywhere. A value Remit could not read is shown as not read, with the reason, never as a pass.

Solutions

Built for the people who carry the obligation.

Each role sees the register the way it needs to, and nobody can do what their role does not allow.

Accountable officials

See the whole portfolio, what is awaiting sign-off, what is overdue and what has been reported to the DTA, and export the register when it is due.

Chief data officers and AI centres of excellence

Run the register, the integrity checks and the policy corpus; set who may do what; watch usage and cost of AI assistance.

Assessing and approving officers

Complete the DTA assessment with guidance beside every question, evidence cited beside each answer, and expert input on the questions that need it.

Internal audit and governance committees

A read-only role that sees every record, every version and the append-only history, and changes nothing.

Security and platform teams

See every agent, model and identity running on your connected platforms, what each is linked to, and each platform’s own risk and security signals on it. Remit only reads.

Service desks on ServiceNow, Jira or BMC

AI incidents become tickets in the agency’s own ITSM system, with every update written back and the trail kept in Remit.

Agents and integrations

A public API and an MCP endpoint let agency systems and AI agents read the register and log incidents under an agency key, with the same audit as the screens.

Platform capabilities

Fourteen capabilities. One connected platform.

From the first use case to the running agent and the DTA register, in one workspace. These are the product’s own screens, captured from real infrastructure running demonstration use cases.

Home: the portfolio's figures, the seven-stage governance thread with a count at each stage, priority actions and live signals.

01 · Home

The whole portfolio on one screen: use cases at every stage, what is held at the Operate Gate, open incidents and findings, and what needs attention next.

  • Every stage counted live
  • Priority actions by severity
  • Live governance signals
  • Next DTA submission counted down
See it on your use cases

Built for enterprise government environments

  • Cloud and AI platform connectors (read-only)
  • Enterprise single sign-on (OpenID Connect)
  • ServiceNow
  • Jira Service Management
  • BMC Helix
  • REST API
  • MCP
  • WCAG 2.2 AA
  • Deployable in your own environment
  • Designed for IRAP assessment

Trust and security

Built to be examined.

Government buyers ask hard questions. Remit answers them from the code as it stands, and says plainly what has not been done yet.

Enterprise SSO (OpenID Connect)Append-only audit logWCAG 2.2 AAAPI and MCP for agentsDesigned for IRAP assessment

Read the security statement, how Remit uses AI and the accessibility statement.

Single sign-on
Enterprise single sign-on over OpenID Connect, bound per agency to its own directory and staff email domain. Local accounts with lockout and administrator resets where SSO is not yet in place.
Append-only audit
Database triggers refuse updates and deletes on the audit log. Every action, sign-in, export, AI call and administrative change is recorded with who, when and why.
Read-only connections
Every call a connection may make is declared in a published register, and anything else is refused inside the process. Remit never writes into the platforms it reads.
Tenancy
Every query is scoped to the agency. Platform operators see names and counts, never inside an agency’s register.
AI data handling
Two switches (installation key and the agency’s own), only the text a feature needs is sent, every call logged with prompt hash, tokens and cost, and a published statement of exactly what leaves.
Accessibility
WCAG 2.2 AA on every screen, checked by an automated scan over every signed-in page on every build.
Deployment
Runs in your own environment with PostgreSQL and Docker, or as a hosted service. Designed for IRAP assessment; not yet assessed. A security pack is available on request.

Australian Government alignment

What the policy asks for, and what Remit does about it.

Remit is built around the Policy for the responsible use of AI in government v2.0 and its standards. The policy text is the DTA’s, reproduced under CC BY 4.0; the product is independent of the DTA.

Each obligation under the policy and what Remit does about it.
The policy asks forIn Remit
A policy scope check for every AI use caseThe Appendix C in-scope criteria and the experimentation conditions, asked in the policy’s own words, with a documented scope decision on every record, in or out.
AI impact assessment for in-scope use casesThe DTA’s tool as a guided workflow: the threshold assessment (sections 1 to 4) for every in-scope use case, the full assessment (sections 5 to 12) where inherent risk demands it, exported as the DTA’s own Word template.
A register submitted to the DTA every six monthsThe register workbook in the DTA’s format, counted down on every overview, with scope decisions on their own sheet and the field definitions from the Standard for accountability.
Annual review of high-risk use casesReview dates set at approval, re-validation that creates a new version, and the overview’s attention list when either is due.
Accountable official and governance reportingReports to the DTA, the governing body and the accountable official recorded as first-class sign-offs against each use case.
Transparency statementRemit does not write your statement, but it gives you the facts for it: the register, the assessments, and a published statement of how Remit itself uses AI.
AI incidentsAn incident log written to the policy’s own definition, with severities, statuses, outcomes and the ticket in your ICT incident system.

Private preview coming soonTrusted AI. Stronger Australia.

Ready to govern every AI use case, from policy to runtime?

Remit’s private preview opens soon for Australian Government agencies, with other jurisdictions to follow. Bring one high-value AI use case, and we’ll take it with you from the policy scope check to its running system.

  • Secure by design

    Enterprise sign-on, tenancy on every query, an append-only audit log, and read-only connections to your platforms.

  • From policy to runtime

    The policy, the assessment and the register in the DTA’s own words, bound to the systems that actually run.

  • Evidence on every decision

    Answers cite the agency’s own documents, the running system is read rather than assumed, and a person decides.

Contact: send us a message

Be among the first in the private preview

The private preview is coming soon. Register for a place, or for product updates as we build.

I would like

We use these details only to contact you about Remit. They are stored in Remit’s own database, never shared, and deleted on request.