Global Active

Global Active

Key-Person Risk Brief

A source-cited brief of the critical knowledge, open commitments, and continuity risks left behind when a key person leaves the company.

A 48-to-72-hour white-glove engagement that turns a key person's work records into an executive brief, a verified evidence trail, and a secure workspace your team can query for ongoing continuity decisions.

Live UI sample

Query a fictional company's work records, including email, chat, and documents, assembled into the same source-linked workspace your engagement will include.

Try the live UI

Sample brief (from actual Enron corpus)

A real Key-Person Risk Brief generated from the public Enron corpus, shown exactly as the engine produced it. This is the complete deliverable, source-cited end-to-end.

See a sample brief

When You Need It

A key person is leaving

Leadership needs to understand open commitments, fragile handoffs, project context, and risk areas quickly.

You need an independent view

Executives need a concise, independent brief supported by facts that trace back to actual source records.

When you can't afford to guess

The context behind customers, deals, systems, obligations, and risks may be scattered across email, documents, LLM histories, meeting notes, exports, and attachments.

What You Receive

Executive brief

A detailed source-cited brief focused on critical knowledge, open commitments, handoff needs, and continuity risks.

See a sample brief built from the public Enron email corpus.

Verified evidence trail

Citations, quote checks, coverage notes, and documented limitations so the brief can be reviewed instead of taken on faith.

Source-linked query browser UI

A private, authenticated workspace where up to three named recipients can ask deep questions across the records and get answers that link straight to the source material behind them, for the agreed access period, normally 30 days after delivery of the brief.

For a sample of how it works, visit here.

Deletion confirmation

You receive your exact destruction date in writing at delivery, based on the agreed retention period, normally 30 days after the brief. We remove hosted access and delete engagement materials, including our own copy of the brief. Final written confirmation states the actual verified completion date; any pending removal is reported separately, never described as complete.

How The Engagement Works

Step 1

Scope and sign

We review the departure event together, identify data sources, timeline, sensitive-material rules, SOW, and data authority. A short intake — about fifteen minutes — captures the exact terms that become your signing documents.

Step 2

Secure intake

Upload your approved ZIP archive directly through the engagement-specific AWS upload page we provide. You do not need to encrypt or password-protect it yourself. Transfer and storage are encrypted. We verify receipt and integrity, then confirm acceptance in writing.

Step 3

Analyze and verify

We normalize, index, investigate, draft, verify citations, review coverage, and prepare the secure workspace.

Step 4

Deliver and close

Your team receives the brief, evidence trail, workspace access, walkthrough, and the exact destruction date in writing.

Data Security

Your data is protected at the model layer. To protect your sensitive corporate data, Key-Person Risk Brief uses Amazon Bedrock with account data retention set to "none." Under this model-service path, prompts and outputs are not retained by the model service, are not used to train AI models, and are not shared with any outside model provider for their own use. It is built for sensitive corporate records, not consumer chatbot use. The entire pipeline — storage, processing, and the client workspace — runs in United States AWS regions, and the no-retention posture is a contractual service commitment, not just a configuration switch. Engagement source material and working results remain in controlled AWS storage until authorized closeout; model-service no-retention does not mean the workspace stores nothing.

Every engagement stays single-client: written data authority, controlled intake, Bedrock no-retention processing, encrypted handling, named-user access, source-cited outputs, and confirmed deletion at closeout.

View the data security flow

Secure AWS uploadEngagement-specific upload page, encrypted transfer and storage, file-integrity check. No client-side encryption step.
Encrypted vaultPer-engagement encrypted storage for receipt, conversion, extraction, and review.
No-retention AI & reviewRecords are processed in Amazon Bedrock with retention set to "none." Citations, coverage, and deliverables are human-reviewed before delivery.
Source-linked query browser UINamed users can ask follow-up questions and inspect source-cited evidence during the agreed access period, normally 30 days.
Deletion closeoutExact destruction date stated at delivery. Final confirmation follows verified data deletion and required access/infrastructure removal.

Boundaries

Key-Person Risk Brief is

  • secure from encrypted upload to confirmed deletion;
  • a white-glove continuity-risk engagement;
  • source-cited and human-reviewed;
  • focused on records the client is authorized to provide;
  • built for urgent executive decision support.

Key-Person Risk Brief is not

  • legal advice;
  • forensics or chain-of-custody evidence handling;
  • eDiscovery;
  • a HIPAA, privilege, HR, or compliance determination;
  • a promise of complete detection or no blind spots.

FAQ

Why can't we just use AI ourselves?

Someone has to own it. Key-Person Risk Brief is not a quick AI prompt. It's extracting, verifying, and organizing years of one person's work into something trustworthy. Your team is already stretched, and a distracting side project is the last thing you need when a key person is walking out the door and you need answers now.

The information you need is scattered and buried. A key employee's knowledge could be spread across years of email, docs, and code. The decisions that matter may be hidden in the noise. Extracting and verifying the results could take days or weeks of work, with no assurance of finding the facts that matter now.

Consumer AI tools can expose sensitive records. Pasting a departing employee's records into an unapproved consumer tool may expose them to retention, review or training under that service's terms. KPRB uses the governed Amazon Bedrock no-retention path, with separate controlled engagement storage and review.

The data is a legal and privacy minefield. It contains regulated, privileged, and personal material: health information, legal matters, private communications. Handling it without proper scope, consent, and governance isn't just risky. It's a liability your counsel will flag.

An answer you can't verify is worse than no answer at all. Raw AI can produce confident answers with no source and no way to check results against the facts. Act on knowledge you can't trace or verify, and a confident guess becomes an expensive mistake.

That's why this is a managed service, not a tool. We own the process, the security, and the provenance, so you get knowledge you can trust, without exposing your data or your team to the risk of doing it yourself.

Why is KPRB better than AI for this problem?

AI can't hold all the information at once. An LLM can only reason over what fits in its working memory. A key employee's knowledge may span years of email, documents, and code. As the content grows, the model drops earlier detail, loses the thread, and compresses away the nuance that mattered. KPRB extracts and stores the entire body of work intact, so no answer depends on what fit into a single prompt.

AI makes things up. When an LLM doesn't know, the model doesn't say so. AI generates the most plausible-sounding answer, which reads exactly like the truth. For a departed employee's reasoning, a confident fabrication is worse than a blank, because a false answer corrupts every decision built upon it. KPRB ties every answer to actual source material, so there's nothing to invent.

AI has a poor sense of time. An LLM can't reliably tell what came first, what was later reversed, or what's still true. A decision and its reversal look equally valid. Knowing the difference is often the whole point. KPRB preserves the sequence, so you see not just what was decided, but what still stands.

AI doesn't show you where the answer came from. Raw AI gives you a fluent answer with no way to check the source. You can't audit the result, defend it to a board or a court, or confirm the model even used the right inputs. KPRB binds every answer to its exact source, so you can trace it, prove it, and stand behind it.

AI doesn't know what matters. An LLM reads all text as roughly equal. The model misses that one load-bearing decision buried in a routine thread, the offhand constraint that the whole system secretly depends on. KPRB surfaces and preserves exactly those high-significance facts.

How do you keep our data secure?

Controlled processing on AWS. Your engagement uses a dedicated AWS workspace, with AI processing through Amazon Bedrock rather than a consumer chatbot. The upload and client portal use encrypted connections.

Model-service retention set to "none". The required setting is checked at each governed provider launch before processing is allowed. This is distinct from the temporary engagement storage needed to prepare and verify your brief. Client records are not used to train AI models.

Secure upload without extra steps. We provide your engagement-specific AWS upload page. Send the approved ZIP archive without adding your own encryption or password. The connection is encrypted in transit and the material is encrypted at rest. Never send source records or credentials by ordinary email.

Least-privilege access. Access is restricted to the authorized people and processes needed for the engagement. AWS supplies the processing and storage infrastructure; Cloudflare protects named-user portal access. These infrastructure services are not permission to use your records for unrelated purposes.

Every engagement is fully isolated. Each client runs in a dedicated per-engagement workspace on AWS, created for that engagement and destroyed when it ends. Nothing is shared between clients, so there's no possibility of cross-contamination.

Verified closeout. The written delivery notice states the agreed destruction date. Final confirmation follows verified deletion of Provider-controlled engagement material, including our brief copy, and required access and infrastructure removal. If anything remains pending, we tell you what remains rather than claim completion. Retained administrative agreements, invoices and contentless verification evidence are separate from the source corpus and analytical results; any legally required retention exception is handled under the agreements.

How do you protect sensitive and private information?

Protected identifiers are masked before AI processing. Screening masks credentials, personal identifiers, and financial and tax identifiers before the text reaches an AI model. The surrounding business record can remain useful with those values masked. Screening is automated and is not a guarantee of perfect detection.

Sensitive topics are classified separately. After masking, the remaining material is analyzed and classified for topics such as medical information, privileged legal matters, complaints and investigations. Your written ALLOW/BLOCK category election determines what may be used in the brief and query answers. Written approval may include an eligible sensitive category; it never restores always-masked identifiers.

Evidence policy and source context are different. BLOCK prevents analytical use. Full click-to-source context remains Screen-safe but is not category-redacted. Classification is automated; human review means pre-delivery report review, not a required per-email adjudication process.

You define the scope. Information stays inside company boundaries. We work only with data the company already owns and has the right to access: its own systems, accounts, and records.

Trust works best in the open, not in secret. The strongest engagements are ones where the departing employee knows their knowledge is being preserved for the team. Handled transparently, this is a professional handoff, not employee surveillance.

Your rules govern the engagement. You remain in charge of what's collected and how the results are used. We build the process to fit your privacy, HR, and legal requirements, not to work around them.

Facing a key-person transition?

Send a short note with the situation, timing, and data sources. Do not send confidential records by email.

Contact Global Active