#GMMWorks / Governance

Governance For banks and regulated teams

Built for your change board, your CISO and your auditor.

Every change GMMCode delivers carries the answer to "who approved this, against which rules, with what evidence?" The LLM is swappable. The governance is not optional.

01 Pilot essentials

What a regulated pilot needs on day one.

Data residency

For Indian customers the platform can run in the AWS India region.

Provenance per change

Every verdict records the model, prompt hash, registry version and tool versions. Every change carries its decision trail.

Human approvals

Approval policies per decision type, quorum groups, SLA due times, reminders, escalation and delegation.

Segregation of duties

Enforced at decision time: no role approves its own work, and production never bypasses an approval.

02 The governance mesh

Checks that cite the rule. Verdicts you can repeat.

Tools run first (scanners, SBOM, licence policy). Then small governance language models review the artefact, and each must cite the standard it applies. One registry decides which checks may block a delivery.

  • 35 specialist checks run on every code change. Nine objective standards checks may block; 26 judgement checks advise.
  • Judgement advises, it does not block. ITIL change records and PMP project controls inform your change board and PMO.
  • Only what applies. A finding outside the story's scope becomes a recorded follow-up, filed in Jira and listed to you at closure, not a silent rejection.

Checker registry

9 blocking   26 advisory

Reproducibility, measured not claimed

Same 22 real files, checked three times. The first measurement agreed on 77% of verdicts. Now an unchanged file gets back its stored, provenance-stamped verdict, and the platform agrees with itself 100% of the time. The model on its own reaches 91%; voting on the two least stable checks is the next step.

first run 77%model 91%platform 100% · target 95%
03 Standards

Your house rules, checked on every change.

Standards are grouped by domain, and the checks that apply are chosen per artefact. Customer house standards are added alongside ours.

Code documentationChange managementException handlingStructured loggingAudit trailSecurity coding (OWASP)TestingDesign patternsNamingData persistencePerformanceDevOps readinessAPI designCompliance patternsConcurrencyData privacy
04 Evidence

An evidence bundle, built as the work happens.

Not assembled the week before the audit. Each story's bundle is exportable and attached to the decision it supports.

Approvals and verdicts

Every gate verdict and human decision, pinned to the artefact version it judged.

Supply chain

OSV scanning with KEV and EPSS, a CycloneDX SBOM and licence policy results.

Tests and releases

Test and integration reports, release baselines and the follow-ups raised.

ITIL change records

Change classification, request-for-change and post-implementation review drafts for your change board.

Compliance mapping

A compliance auditor role maps delivery evidence to frameworks such as SOC 2, GDPR, the DPDP Act and RBI IT guidance.

Production feedback

GMMDesk turns a confirmed production defect into an approved Jira bug that returns to the board.

Bring one requirement and your auditor's questions.

We will run it through #GMMWorks on your Jira board and walk your risk team through the evidence.