Modules
Every module in Overwatch is engineered for one job: catch what matters, record it cleanly, and give administrators the controls to act. Nothing in this surface is decorative.
Platform Administrator Access
Strict SSO + MFA gating for every Overwatch surface.
Overwatch is restricted to designated VeraGen platform administrators. Authentication requires single sign-on with enforced multi-factor verification, hardware key support, and continuous session validation. Every access — successful or denied — is logged as an immutable audit event with actor, IP, device, and intent metadata.
- SAML / OIDC SSO
- Hardware-key MFA enforced
- Session-level audit trail
- Role-based scoping per surface
Real-Time AI Monitoring Engine
Every signal across every VeraGen app, captured the moment it happens.
The monitoring engine ingests AI signals from across the platform — Tellagent chatbot prompts and completions, Cortex generated content, InForm submissions, Thrive survey responses, PromptPay transactions, and Bases publishes. Each signal is classified, scored, and persisted before it ever reaches an end user surface.
Incident Dashboard
Dense, functional console for triage under pressure.
A single command surface for active incidents across the platform. Administrators see live counts by severity, filter by app, jurisdiction, account, or classifier version, and drill into any incident to view the full evidentiary record — signal, classification, policy match, and recommended action.
Severity Ratings & Classification
Four tiers. Calibrated thresholds. Auditable rationale.
Every incident is scored against a four-tier severity model: Low, Medium, High, and Critical. Scoring weighs harm potential, audience scope, jurisdictional exposure, and regulatory implication. The classifier’s reasoning, version, and confidence are attached to every record — administrators see why a score landed where it did.
Notification & Alert Management
Right signal, right responder, right channel.
Alerts are routed by severity, app, and policy domain to the correct internal responder — Trust & Safety, Compliance, Legal, or Law Enforcement Liaison. Channels include in-console, email, SMS, PagerDuty, and signed webhook for downstream SIEM integration.
Account Suspension Controls
Direct enforcement when policy requires it.
Administrators can suspend, restrict, or quarantine any account across the platform from inside the incident record. Actions cascade across every VeraGen app, revoke active sessions, preserve all artifacts in evidentiary storage, and notify the account holder per platform policy.
7-Year Audit Log
Write-once, cryptographically sealed, court-ready.
Every signal, classification, decision, and administrator action is recorded in an immutable audit log retained for seven years. Records are hash-chained, optionally notarized to an external timestamp authority, and exportable as a sealed evidence package with chain-of-custody manifest.
Law Enforcement Export & API
Built for NCMEC, FBI IC3, and ICAC reporting workflows.
When a Critical incident requires external reporting, Overwatch produces statute-aligned exports for the National Center for Missing & Exploited Children (NCMEC CyberTipline), the FBI Internet Crime Complaint Center (IC3), and Internet Crimes Against Children (ICAC) task forces. Authenticated APIs support direct ingestion into partner systems.
Central Prompt Governance
One policy surface for every AI prompt across the platform.
Overwatch hosts the canonical prompt and policy library used by every VeraGen app. System prompts, guardrails, refusal templates, and allowed-tool manifests are versioned, reviewed, and rolled out from a single location — with rollback, A/B controls, and full change history.