MENUCLOSE
Product · Supervision
Know what employees are doing in enterprise AI, and prove how you supervised it.
Employees already use Claude Enterprise, ChatGPT Enterprise, and ChatGPT Edu. Tallin gives Compliance a defensible record of that work: what happened, what needs review, what was retained, who made each decision, and where coverage is missing. You choose how long records are kept and whether Tallin hosts them or they stay in your environment.
- 09:12:04flaggedrisk rule: client communication
- 09:40:18assignedreviewer: compliance analyst
- 10:02:51content viewedreason recorded, access logged
- 10:09:33dispositionpolicy exception noted, attested
The review workflow
A queue your compliance team can actually work.
Flagged items arrive in a queue ordered by severity and rule. Reviewers open content with a stated reason, assign the next action, and close each item using dispositions from your policy.
- PrioritizeFlagged items arrive ordered by severity and the policy rule involved.
- Open with reasonReviewers state why they need content. Every allowed or denied access is recorded.
- DecideAssign, escalate, or close the item using dispositions from your own policy.
- AttestTallin records the reviewer, timestamp, policy version, and final disposition.

How capture works
Captured from the source of record, archived before it expires.
Tallin reads sanctioned AI activity from the provider's own compliance API, the same interface the provider offers for regulated customers, and lands every message in an append-only archive with a hash chain per conversation. The polling cadence is designed to beat the provider's retention window, so your record outlives theirs.
Custody
Your record, in storage you set the terms on.
Choose a Tallin-hosted archive on object-locked storage, written once and held immutably for the retention you set, or run the archive inside your own VPC, where content never leaves your boundary and only metadata and evidence egress. Review in the Tallin console is available for hosted deployments today; VPC-resident review is on the roadmap.
Not covered
- NOT COVERED
- Personal accounts and unsanctioned tools are not captured. Supervision covers the sanctioned enterprise workspaces you connect.
- NOT COVERED
- The archive holds what the provider's compliance API exposes, on the cadence Tallin polls it. Gaps are reported, never silenced.
- NOT COVERED
- Supervision records and reviews. It does not block, rewrite, or filter content in flight.
Supervision, specified
- Sources
- Claude Enterprise, ChatGPT Enterprise, and ChatGPT Edu through each provider's compliance API.
- Archive
- Message-level and append-only, with per-conversation hash chains. Hosted archives use object-locked storage; write once, immutable retention.
- Access control
- Flagged content opens only with a stated reason. Every access is logged, allowed or denied.
- Review
- A queue by severity and rule, dispositions from your own policy, and an attestation recorded with reviewer identity, timestamp, and policy version.
- Retention
- Configured by you, independent of the provider's own retention window.
- Deployment
- Tallin-hosted archive, or a customer-VPC archive where content stays inside your boundary and only metadata and evidence leave.
Put your sanctioned AI tools under supervision.
Start a 30-day Tallin Supervise or Core trial to map your supervision scope and connect a supported Claude Enterprise, ChatGPT Enterprise, or ChatGPT Edu source. No credit card is required to begin.