Every material action: policy-gated, reviewed, released, on the record.
Nothing executes until one of your people signs it. That is the architecture, not a configuration setting — which is why the artefacts a regulator asks for fall out of normal operation here instead of being assembled for an audit.
Two gates. No exceptions.
The first gate asks whether the file is complete. The second asks whether the right person is deciding. Both are recorded, both are yours to tighten, and neither can be skipped by raising an autonomy setting.
Finding
A case needs a decision - context assembles from your systems.
Agent review
Specialist analyses challenge the recommendation - policy, compliance, evidence.
GATE 1Consensus
A structured verdict - rationale, disagreements, unresolved evidence.
Human approval
The named quality, clearing or compliance owner decides. Nothing runs without this.
✓ GATE 2Execution
Only approved actions execute in your systems - logged and signed.
logged · signedArticle 18 is answered by design, not by policy.
Under the UAE Personal Data Protection Law, a decision producing legal effects cannot simply be automated. Most vendors meet that with a written policy and a review process. TeamIntel meets it structurally: a material action has no execution path that does not pass through a named human release. There is no setting that turns it off, because there is nothing to turn off.
The decision is a person’s
The agent team assembles the case, cites every determination and states what it could not verify. A named approver in your organisation releases it, rejects it, or sends it back.
The reasoning is readable
Every fact carries its document, version and page or article, so the person releasing it can check the two or three that matter rather than trusting the whole file.
The record survives the decision
What was checked, what was not, who released it and when — written down as the case runs, not reconstructed later when somebody asks.
Regulatory figures on this page are drawn from secondary reporting retrieved on 27 July 2026 (Al Tamimi & Company; GCC Board Directors Institute; DIFC and ICC publications). Confirm the current text of any instrument before relying on it contractually.
Regulation 10, as a by-product of running.
The DIFC regime is the region’s only AI-specific instrument, and it asks a firm to appoint an Autonomous Systems Officer and maintain four things. Here is where each one comes from.
- An impact assessment — produced per queue before the first shift, from the scope you agreed: what the system reads, what it produces, who releases it, what happens when it is wrong.
- A system register — the queues in operation, their autonomy tier, their named approver and their data scope. It is the operating configuration, so it cannot drift from reality.
- An incident record — every rejection, every case sent back, every threshold miss and the rework that followed, with dates.
- A named accountable person — on your side, per queue, recorded before the queue starts.
Regulatory figures on this page are drawn from secondary reporting retrieved on 27 July 2026 (Al Tamimi & Company; GCC Board Directors Institute; DIFC and ICC publications). Confirm the current text of any instrument before relying on it contractually.
The boundary is permanent, not a phase.
Most vendors describe what they would like access to. This is the opposite: five categories we do not ask for, do not plan as a later stage, and do not renegotiate. It is part of the data-processing agreement, so widening it would be a contract change you would have to sign — not a setting somebody adjusts.
- Slack, Teams or e-mail content
- Source code of any kind
- Financial-system access
- Any live or standing integration
- Personnel files or performance data
The English governance pack — this list, the hosting sheet, the Article 18 design note and the Regulation 10 artefact map — is being written and is available on request in the meantime.
Your instance. Your region. Your keys.
A dedicated instance
Not a shared tenant with your data partitioned off. In health and financial services this is an entry condition rather than a feature, and we treat it as one.
In-region hosting
Your cases stay in the region you name, and the sub-processors that touch them are listed in the agreement before you sign it — not referenced by a link that can change.
Customer-managed keys
You hold them. Revoking access is something you do, not something you ask us to do and then verify.
Bring your own model
If your policy requires a specific provider or a model inside your own tenancy, the system runs on it. We are the layer that makes the output signable, not the model vendor.
We never train on your data. Read-only at the start; a write scope into your systems is a separate, logged decision you take later. How the export works.