Skip to content
Evan AI Governed compliance
Illustrative demo — synthetic data

Interactive walkthrough

Evan AI: the compliance operating system

One controlled front door from regulatory signal to defensible record

Evan Elias · Head of Strategic Regulatory Compliance · September 2026

All matters, people, companies and regulator actions shown are fictional. Real regulatory frameworks are referenced for illustration only — nothing here is legal advice or reflects any actual employer matter.

Press → to begin

The problem

One head of compliance, a widening regulatory surface

  • 100+matters handled in a single year
  • 20+jurisdictions swept for regulatory intelligence, daily
  • ~10jurisdiction registers, each with its own licence logic
  • 40+external counsel contacts across jurisdictions
  • 1accountable head

What it is

A private Lark bot, governed brain, and registers of record

Reg-intel sweep in 22 jurisdictions · daily External research: search + ask + fetch (labelled) Daily brief · heartbeat out 08:00 SGT · HEARTBEAT_OK or P0_ALERT Governed access per-bot, per-feature entitlements owner-approved · kill switch · ledger Lark Evan’s DM Compliance group chats Forwarded threads and emails The only interface Evan AI OpenClaw · private, self-hosted runtime Brain · identity, standing protocol, tool rules 39 active skills · 29 compliance workflows Gates · HITL, typed send, exec approval I propose, Evan decides Feishu Base + Drive Active Matters · Actions · Decisions Precedents · Obligations-Controls Jurisdiction registers, read-only Numbered evidence folders System of record

Runs in a private cloud environment. Every write and every external send passes through a gate.

Everything it does

29 compliance workflows in seven families, one governed brain

Space or Next step lights the first family

39 active skills

29 compliance workflows plus platform and self-governance skills — refined through daily use

    Live walkthrough · part 1

    From an enforcement letter to a filed matter — nothing written until Evan approves

    Space or Next step forwards the letter

    Evan AI · direct message compliance-intake

    Live walkthrough · part 2

    From a forwarded thread to a governed record

    Space or Next step reveals the thread

    Philippines Compliance (synthetic) forwarded to Evan AI

    Live walkthrough · part 3

    The morning sweep — what changed overnight, mapped to open matters

    Space or Next step starts the 09:00 sweep

    Evan AI · direct message reg-intel · 09:00 SGT cron

    Live walkthrough · part 4

    Product launch assessment, generated from the registers

    Space or Next step asks for the assessment

    Evan AI · direct message product-launch · launch SOP

    Live walkthrough · part 5

    External facts, labelled — the register stays authoritative

    Space or Next step asks the question

    Evan AI · direct message compliance-query

    Live walkthrough · part 6

    The external-send gate

    Space or Next step runs the first attempt

    Evan AI · direct message send gate

    Live walkthrough · part 7

    Counsel and the matter lifecycle — every step a record

    Space or Next step drafts the counsel brief

      Evan AI · direct message counsel-brief · counsel-chase · matter-close

      Live walkthrough · part 8

      The biweekly management summary — a projection of the record

      Space or Next step builds the skeleton

      Feishu doc · Executive briefing executive-update · Mode A

      Live walkthrough · part 9

      Governed access — one service for any clawbot, switched per bot and per feature

      Click Approve subset, or press Space

      co-freedonia · service calls Freedonia Compliance (synthetic)

      The rhythm · day, week, month

      Same shape every morning, alerts only when they matter

      Space or Next step delivers the brief

      Daily brief 08:00 SGT · Evan’s DM

      Controls that make it defensible

      Six design choices, not six policy statements

      1. 01

        Human in the loop on every write

        Every change to a register is proposed as a card with Approve, Modify, Discard and Escalate. Nothing is written until Evan acts.

      2. 02

        Typed-send gate

        External messages leave only on a fresh typed “yes send” or “send it” that satisfies six conditions, with a single-dispatch lock.

      3. 03

        Exec approval on every command

        Every shell execution requires explicit approval. There is no silent automation path.

      4. 04

        Read-only jurisdiction registers

        The jurisdiction registers are read-only to the assistant. Licence facts are consulted, never edited.

      5. 05

        Real-time audit log

        A daily audit log document records every action as it happens, so the trail exists before anyone asks for it.

      6. 06

        Self-improving error register

        Domain-coded errors with pre-flight checklists. Novel errors halt and ask. A monthly scan retires stale rules.

      What Evan AI has done

      System facts, stated plainly

      Compliance workflows
      29
      Active skills
      39
      Registers of record
      10+
      Matters tracked in a year
      100+
      Jurisdictions swept daily
      22
      Error register, active rules
      16

      Daily brief

      Every morning at 08:00 SGT, filed and delivered to Evan's DM

      Intake

      Live since 2026, including thread-context intake

      No productivity claims. The point is that the record exists, is consistent, and can be shown.

      How I’d scale it · a two-quarter shape

      Harden, extend, industrialise

      Q4 Harden

      • Allowlist posture for tools and destinations
      • Structured audit ledger in Base
      • Cron model and heartbeat health monitor
      • Tooling upgrade with rule re-verification
      • Idempotent approve on gated writes
      • Intake v2: approval card before any write, three-register duplicate check

      Q4–Q1 Extend

      • Obligations-controls register live for every licence
      • Counsel instruction lifecycle, brief to close
      • Evidence packs auto-assembled from registers
      • Jurisdiction status one-pagers on demand
      • Research desk: one door over external research tools, three-label provenance rule

      Q1 Industrialise

      • Engineering-owned execution rails
      • Environment separation, QA to prod
      • Observability across bot, gateway and registers
      • Evaluation harness with golden cases
      • A separate business-facing front door, reusing the same governed registers
      • Compliance service: same workflows for any clawbot, per-feature entitlements, kill switch, hash-chained ledger

      The decisions that matter

      Three decisions any AI-assisted legal function must take

      1. 1

        What becomes the system of record for regulatory matters?

        Matters, actions, decisions and remediation need one reference point for Legal and Compliance — named early, before the record fragments.

      2. 2

        Who owns reliability, security and scale?

        Compliance owns the regulatory logic and escalation design; engineering owns the enterprise rails, observability and evaluation. The boundary needs to be explicit.

      3. 3

        What may the system read and write — and what is disclosed?

        A data-access and disclosure policy for AI in Legal and Compliance, settled before the system scales: what it reads, what it writes, and what regulators, counsel and the board are told.

      I propose, Evan decides.

      Illustrative walkthrough — synthetic data throughout. Not legal advice.