#GMMWorks / Governance
Built for your change board, your CISO and your auditor.
Every change GMMCode delivers carries the answer to "who approved this, against which rules, with what evidence?" The LLM is swappable. The governance is not optional.
What a regulated pilot needs on day one.
Data residency
For Indian customers the platform can run in the AWS India region.
Provenance per change
Every verdict records the model, prompt hash, registry version and tool versions. Every change carries its decision trail.
Human approvals
Approval policies per decision type, quorum groups, SLA due times, reminders, escalation and delegation.
Segregation of duties
Enforced at decision time: no role approves its own work, and production never bypasses an approval.
Checks that cite the rule. Verdicts you can repeat.
Tools run first (scanners, SBOM, licence policy). Then small governance language models review the artefact, and each must cite the standard it applies. One registry decides which checks may block a delivery.
- 35 specialist checks run on every code change. Nine objective standards checks may block; 26 judgement checks advise.
- Judgement advises, it does not block. ITIL change records and PMP project controls inform your change board and PMO.
- Only what applies. A finding outside the story's scope becomes a recorded follow-up, filed in Jira and listed to you at closure, not a silent rejection.
Checker registry
9 blocking 26 advisory
Reproducibility, measured not claimed
Same 22 real files, checked three times. The first measurement agreed on 77% of verdicts. Now an unchanged file gets back its stored, provenance-stamped verdict, and the platform agrees with itself 100% of the time. The model on its own reaches 91%; voting on the two least stable checks is the next step.
Your house rules, checked on every change.
Standards are grouped by domain, and the checks that apply are chosen per artefact. Customer house standards are added alongside ours.
An evidence bundle, built as the work happens.
Not assembled the week before the audit. Each story's bundle is exportable and attached to the decision it supports.
Approvals and verdicts
Every gate verdict and human decision, pinned to the artefact version it judged.
Supply chain
OSV scanning with KEV and EPSS, a CycloneDX SBOM and licence policy results.
Tests and releases
Test and integration reports, release baselines and the follow-ups raised.
ITIL change records
Change classification, request-for-change and post-implementation review drafts for your change board.
Compliance mapping
A compliance auditor role maps delivery evidence to frameworks such as SOC 2, GDPR, the DPDP Act and RBI IT guidance.
Production feedback
GMMDesk turns a confirmed production defect into an approved Jira bug that returns to the board.
Bring one requirement and your auditor's questions.
We will run it through #GMMWorks on your Jira board and walk your risk team through the evidence.