Home / Trace
MyRISK Trace · defensible decisions
Replay, not reconstruct.
Some decisions get questioned long after they are made. Trace preserves what was known, who authorised it, why it was reasonable, and what changed since.
The problem
We have systems, but we could not reconstruct this decision if challenged
A risk accepted. An exception approved. A supplier chosen. A control deferred. An AI use case signed off. The question later is rarely what was decided. It is what was known at the time, who had authority, what conditions were attached and whether anything has changed since.
Today that answer lives across ServiceNow, Jira, SharePoint, email and your GRC platform — each holding part of the story. Reconstructing it takes days, and parts of it end up disputed.
A ticket records work. Trace records why the decision was reasonable.
What a Trace record preserves
- The evidence that existed at the time, and the policy version that applied
- The rationale, assumptions and alternatives considered
- Who had authority, and what exactly was approved
- Conditions, expiry and review dates
- Drift — whether changed circumstances unsettle the approval
Who this is for
Five people who get asked “why did we approve this?”
The legal objection — does this create a record we would rather not have? — is a design requirement, not a blocker. A controlled contemporaneous record is usually safer than scattered email and after-the-fact reconstruction. Purpose, retention, privilege, access, audit use and correction are resolved in the design conversation, and we put the position in writing for your counsel.
The first step
One decision, compared honestly
Take one recent high-stakes decision and compare your current reconstruction with a Trace-style replay. If the exercise exposes material evidence, authority, rationale or drift gaps, we scope a bounded 30–60 day pilot for that decision class.
If it does not, you keep the comparison and we tell you Trace is not your problem. Fixed scope, fixed price, one decision class first.
What the comparison shows, gaps included
- The decision as evidenced, with the date it was made rather than the date it was written up
- Each evidence item found, where, and how long retrieval took
- Evidence that should exist and does not — named individually
- The approvals that were verbal and cannot now be confirmed
- What a reviewer would ask that the current record cannot answer
For your reviewers
The boundaries, in writing
Where Trace stops
- Trace complements your GRC, ITSM and collaboration systems. It is not a replacement for any of them.
- Replayability is a property of the record, not a legal conclusion. Trace does not assert legal sufficiency.
- “Audit-ready” is not promised. Trace supports a replayable governance record; acceptance is your auditor's.
- AI can draft a narrative afterwards. It cannot prove what existed and was relied on at the time — that is the point of the record.
Where does the data sit?
Deployment options and the data boundary are first-conversation controls, agreed at the Diagnostic and put in writing for your reviewers.
How much integration does the first step need?
The pilot uses bounded evidence sources and limited integration effort. Trace connects to your systems — that is what makes the record trustworthy — and we scope that properly at the Diagnostic rather than pretending it away.
What if we stop?
The decision records export in an open format, and the export is tested during the pilot rather than promised.
Which decision would be hardest to defend next month?
Bring that one. The Diagnostic compares your current reconstruction with a Trace-style replay.