A routine request goes straight through
Lakeside Clinic's AI asks to file a routine $840 claim. ARBITER checks it against the clinic's rules before the AI runs, lets it through, and signs a certificate recording what was decided and why.
A risky request waits for a person: you
Northwind Bank's AI asks to wire $48,000 to a payee the bank has never paid. The bank's rules say a wire over $10,000 needs a human. Send it, then decide as the bank's reviewer.
Edit a certificate, and the check fails
Take the certificate ARBITER signed for your decision in step 2 and change one thing. Anyone can ask ARBITER to check a certificate, and any edit breaks it.
Decide the wire in step 2 first.
One company cannot see another's data
Both companies share the same ARBITER and the same database. The clinic's own key asks for the bank's wire record.
The AI's tool cannot move the money on its own
Hand the payment tool the real database credential and let it try to move $48,000 by itself, skipping ARBITER. If you approved the wire in step 2, you also see the one way through: a single-use permit for exactly the approved amount.
What is real here, and what is not
- Real: the ARBITER software, the companies' rules, the database and its walls between companies, the human review, the certificates and their check, and the database permissions in step 5.
- Stand-ins: the AI model (canned answers, so the demo is free and repeatable), the two companies, and in step 5 the permit, which this demo issues itself after your approval, standing in for ARBITER.
- Limits: step 5 holds against the tool's own credentials, not against someone with a shell inside the database server. Everything resets every night, and each visitor gets a fair number of clicks.
UNDER CONSTRUCTION
Your own sandbox
Next is a private sandbox for your engineers: your own company account, API key and dashboard, your own rules and your own test traffic, behind the same two-factor sign-in production uses. Until it opens, book the 30 minutes and we will run your scenario live.