Case study·DataWhisper × Humanos·cs_datawhisper · v2 · anchored 2026-05-29

DataWhisper’s agents act autonomously inside regulated workflows.

SmartInsights.CortexOS is integrating with Humanos so relevant legally consequential actions an agent takes are verified, and proved, before execution.

SmartInsights.CortexOS is the governance-first agentic operating system for regulated industries. Humanos integrates as its external mandate verifier, branded GuardianShield Consent: the layer that lets a SmartInsights.CortexOS agent prove a human authorized an action, to any party.

Customer
DataWhisperAutonomous AI for regulated industries
Surface area
Legally consequential actionsDisputes · Settlements · KYC · Attestations
Integration
humanos.verify()External mandate verifier at the HITL gate
Runtime
SmartInsights.CortexOSGuardianShield Governance · v5.2
§ 01 · The customer

The governance-first agentic OS for regulated industries.

SmartInsights.CortexOS orchestrates multi-agent teams, called Pelotons, inside enterprise workflows: onboarding, dispute resolution, claims, KYC, attestations. Governance is enforced at the infrastructure boundary, not inside a prompt. Every action passes an 18-stage tool gateway and is recorded in a hash-chained, tamper-evident audit trail.

Inside SmartInsights.CortexOS, the human-in-the-loop (HITL) engine holds legally consequential actions at an approval gate. For the defined class where the approving party is external, or the proof must be independently verifiable, it calls Humanos. GuardianShield, the governance and audit plane, records and proves it — branded inside CortexOS as GuardianShield Consent.

Explore SmartInsights.CortexOS at datawhisper.co.uk.

DataWhisper
Integrated
Channels
Channel governance
Agents
Agentic AI Governance · HITL engine
Core
Orchestration · memory · identity
Roots
GuardianShield · GuardianShield Consent
Runtime
SmartInsights.CortexOS · v5.2
Integration
humanos.verify() · one call
Anchored
2026-05-29 · v2
§ 02 · The design principle

Selective by design, not universal.

GuardianShield Consent does not replace the SmartInsights.CortexOS internal HITL model. Most approvals, escalations and operator overrides resolve inside SmartInsights.CortexOS, with no external dependency and no added latency. Humanos is invoked only when the proof must survive outside DataWhisper’s systems, or the approving party is external. If internal governance is sufficient, the external call never happens.

§ 03 · The integration

One verify() call,
at the SmartInsights.CortexOS HITL gate.

Before a legally consequential action commits, the SmartInsights.CortexOS HITL engine calls humanos.verify(). Identity, scope, counterparty, amount and validity are checked against a signed mandate, and a deterministic allow or deny is returned. No LLM sits in the verification path.

humanos.verify() · called by the SmartInsights.CortexOS HITL gate
2026-05-29 11:14:07.802 UTC
Case
case_DW-018472
dispute.resolve · cortex.peloton
Resolution
£ 4,750.00
Refund to claimant£ 3,200.00
Fee adjustment£ 750.00
Goodwill credit£ 800.00
Total£ 4,750.00
x-humanos-mandate · 0xC44E…F912
Initiated by · DataWhisper dispute-resolution Peloton
on behalf of: Operations Lead, DataWhisper
humanos.verify() · live capture
82 ms
identityclaimant verified
12 ms
scopedispute.resolve · chargeback
22 ms
counterpartyapproved adjudicator list
36 ms
amountwithin £ 25,000 resolution cap
58 ms
validitymandate active to 2026-06-29
71 ms
Authorized · proof emitted · 82 ms
proof:0xC44E…F912 · attached to resolution
✓ COMMIT

Resolution commits.

Within mandate, within constraints, within validity. SmartInsights.CortexOS writes the resolution to the case of record, and a portable proof is attached, verifiable by any party with the right access.

⟲ RECOVER

Recover, then continue.

Out of scope, expired or revoked. The HITL engine requests step-up approval in real time, the mandate is updated, and execution resumes once authorization is valid. The agent never silently fails or guesses.

§ 04 · How the integration works

Five stages, from mandate to proof.

The animation on the right walks through one dispute case end-to-end — issued by DataWhisper Operations, verified by Humanos at the SmartInsights.CortexOS HITL engine gate, and committed only after a deterministic yes/no.

01
§ 01 · Issue

A human authorizes scope.

A DataWhisper Operations Lead authorizes scope, ceiling and validity. Humanos issues a machine-verifiable W3C Verifiable Credential, signed once and reusable across every case.

ApproverOperations Lead · DataWhisper
Scopedispute.resolve · chargeback
Ceiling£ 25,000.00 / case
Valid until2026-06-29
02
§ 02 · Prepare

SmartInsights.CortexOS prepares the action.

The dispute-resolution Peloton assembles the proposed resolution — refund, fee adjustment, goodwill credit — and attaches the mandate to its outbound action as x-humanos-mandate.

Pelotoncortex.dispute.peloton
Casecase_DW-018472
Actionrefund · fee adj · goodwill
Total£ 4,750.00
03
§ 03 · Verify

The HITL engine verifies.

The HITL engine calls humanos.verify() against the mandate. Identity, scope, counterparty, amount and validity are checked in 82 ms — deterministic, no LLM in the path.

CallerHITL engine
Identityclaimant verified · 12 ms
Amount£ 4,750 ≤ £ 25,000 · 58 ms
Latency82 ms total
04
§ 04 · Settle

Commit, or step up.

Authorized → SmartInsights.CortexOS commits the resolution. Out of scope — a £45,000 settlement against a £25,000 ceiling — the gate blocks and triggers a real-time step-up.

Committed£ 4,750.00 · written to case-of-record
Blocked£ 45,000.00 · out_of_scope
Recoverstep-up · SMS · resumes
05
§ 05 · Prove

Anchor the proof.

Each authorized action emits a cryptographic proof, recorded in both the SmartInsights.CortexOS tamper-evident audit trail and the independent consent record. Auditors, regulators and partners verify it directly, without reconstructing internal logs.

Proof IDproof:0xC44E…F912
Attachedcase.receipt
VerifiersAuditor · Regulator · Banking partner
Resultindependently verifiable · forever
Live · humanos.verify() · DataWhisper × case_DW-018472
§ 01 · Issue
01 · Issue · mandate signed by Operations Lead
mandatesigned
subject: "cortex.dispute.agent",
principal: "ops.lead@datawhisper.co.uk",
action: "dispute.resolve",
scope: ["dispute.resolve", "chargeback"],
counterparty: approved_adjudicator_list,
amount_max: "£ 25,000.00 / case",
valid_until: "2026-06-29"
02·03·04 · Prepare → Verify → Settle
  1. A1Refund £ 3,200.00 → claimant.accountauthorizedmissingrequesting…approvedout_of_scope
    case_DW-018472 · within mandate scope
  2. A2Apply £ 750.00 fee adjustmentauthorizedmissingrequesting…approvedout_of_scope
    case_DW-018472 · within £ 25,000 cap
  3. A3Settle £ 45,000.00 high-risk claimauthorizedmissingrequesting…approvedout_of_scope
    case_DW-091284 · exceeds £ 25,000 ceiling
  4. A4Approve new category: warranty.disputeauthorizedmissingrequesting…approvedout_of_scope
    step-up SMS → Ops Lead · resolves · resumes
verify() — called by the HITL engine, not by the agent
await humanos.verify({ subject, action, amount, counterparty, mandate }) // 82 ms · deterministic
committed · £ 4,750.00 · case_DW-018472
0xC44E…F912
05 · Prove · dual record — CortexOS audit trail + independent consent record
proof.jsonsigned
{
  "who_approved": "Operations Lead · DataWhisper",
  "case_ref": "case_DW-018472",
  "action": "dispute.resolve",
  "amount": "£ 4,750.00",
  "scope": ["dispute.resolve", "chargeback"],
  "mandate": "0xC44E…F912",
  "validity": "≤ 2026-06-29",
  "timestamp": "2026-05-29T11:14:07.802Z",
  "signature": "0xC44E…F912"
}
AuditorRegulatorBanking partnerverify(proof)true
✓ proof attached · independently verifiable · forever
§ 05 · What it delivers

Provable authorization, by default.

01 · Verified

Verified before execution.

Relevant legally consequential actions are verified before they commit. The verify call is inline at the HITL gate, not after the agent has acted.

02 · Deterministic

Probabilistic AI, deterministic answer.

Agents stay probabilistic in reasoning. The act-or-not boundary is a yes or no, with no LLM in the verification path.

03 · External reach

Human-in-the-loop beyond the operator.

Approval and consent can come from external counterparties and data subjects, not only internal operators. The loop extends past DataWhisper’s boundary.

04 · Portable

Authorization travels with the action.

Issue once, verify anywhere. The proof is recorded in the SmartInsights.CortexOS tamper-evident audit trail, lives inside GuardianShield Governance, and is verifiable by any permitted party.

§ 06 · Where it applies

Anywhere a regulated agent acts on a human’s authority.

01

Disputes & chargebacks

Refunds, settlements and goodwill credits, each authorized at the gate and carrying a portable proof.

Engage & Grow · Fraud & Risk
refundsettlecredit
02

High-value payment execution

Above an operator-defined threshold, cryptographic proof that a human authorized execution at a specific amount.

Engage & Grow · Fraud & Risk
approveexecuteprove
03

KYB / KYC & sanctions

A signed human authorization record provides audit-ready evidence for FCA or equivalent review.

AI Onboarding
kycsanctionfile
04

Contract & terms acceptance

Tamper-proof evidence that a counterparty accepted terms at a specific time and scope.

Engage & Grow
acceptattestaudit
§ 07 · Close

AI agents execute inside regulated environments, within provable, independently verifiable boundaries.

DataWhisper · Autonomous AI for regulated industries · datawhisper.co.uk

Explore SmartInsights.CortexOS Talk with us