Domain

Poesis for IT · Domain

The first IT autonomous enterprise platform — IT and operational AI governance as one.

What if the definition of your IT organization — its architecture, obligations, constraints — could govern the real thing: autonomously generated, continuously regulated, deliberately supervised? That is Poesis’s founding thesis — published as research, engineered in the open: one governed, machine-readable source of truth for your IT landscape and for the AI agents that increasingly operate it — artifacts generated, impacts simulated, compliance continuously proven, every autonomous act accountable to the same definitions. That is the foundation of the autonomous enterprise, built where it starts: IT.

The mental model

What Kubernetes did for infrastructure, Poesis does for all of IT: governed autopoiesis.

Kubernetes let you declare the desired state of your infrastructure and trust a reconciliation loop to converge reality toward it. Poesis extends that principle to everything that constitutes your IT: architectures, obligations, constraints, and processes become declared definitions — continuously evaluated against the real system, with drift observed the moment it appears and humans disposing of every consequential change. The estate stops merely being governed and starts regenerating itself against its own definition — autopoiesis, under governance.

What it replaces

11 pains, one governed model.

Each of these pains is sold a separate tool today, each tool holding its own copy of the truth. In Poesis they are facets of the same governed definitions — every pain traceable to the features that address it.

Enterprise architecture

The architecture repository is out of date the day it’s written.

Hand-maintained models detach from the territory the moment delivery moves on — and every decision made on them inherits the drift. The landscape becomes a governed inventory of typed definitions, sourced from the code, contracts, and infrastructure that actually run.

Addressed by GSM Definitions management · GSM Definitions automatic sourcing from code repos

Compliance automation

Compliance is reconstructed in spreadsheets before every audit.

Posture exists only at audit time; between audits, nobody can answer what is actually covered. Continuous appraisal indicators compute measures and findings from the model — GDPR, NIS2, DORA, ISO as a live dashboard.

Addressed by IT compliance evaluation · GSM Ontology management

Impact analysis

Impact analysis is a guess made in a meeting.

Coupling is discovered in incident reviews, after the change shipped. Changes ripple through typed relations, so impact is simulated from the model — traced through the definitions it touches.

Addressed by IT impact simulation

Artifact generation

Every deliverable is hand-crafted, again and again.

ADR packs, evidence, baselines, and roadmaps are rebuilt by hand — and stale against each other by the time they ship. Deliverables are generated from the definitions, each artifact traceable back to the exact definitions it derives from.

Addressed by IT artifact factory

AI-ready governance

AI agents act on stale wikis and tribal knowledge.

Without a trustworthy machine-readable source of truth, agent autonomy is either blocked or reckless. Every definition is typed by a GSM Archetype — humans and AI agents reason and generate from the same governed account of what your systems are and must do.

Addressed by GSM Definitions management · GSM Definitions management RESTful API · MCP

Change governance

Anything can change anything — there is no approval trail.

Definitions, standards, and obligations mutate without review; who approved what, and when, is unanswerable. Every governed change is a validated lifecycle transition — proposed, approved, activated, retired — with the full history retained as the audit trail.

Addressed by GSM Definitions lifecycle enforcement · GSM Definitions retention

Framework composition

Every framework lives in its own silo — and they collide on your desk.

TOGAF, ISO, GDPR, and NIS2 each demand their own registry and their own reconciliation; overlaps and conflicts are discovered by accident. Source models are represented in one typed ontology catalogue and composed through the governance layer — overlaps and conflicts surface in the composer, not in audits.

Addressed by GSM Ontology management · TOGAF

Vendor neutrality

Your governance model is trapped in a vendor’s proprietary format.

Obligations, architecture, and compliance mappings live in tool-specific silos — migrating tools means re-authoring your governance. Definitions follow a vendor-neutral standard — typed, portable, and machine-readable across tools — so the model outlives any product choice, and the unlock compounds with every vendor that adopts it.

Addressed by Eight systemic primitives · Archetyping

Interoperability

Architecture, compliance, and quality tools don’t speak to each other.

Each tool keeps its own model of the same IT reality; integrations are bespoke mappings that rot, and knowledge stays siloed per tool and per team. One vendor-neutral vocabulary and grammar — the OpenTelemetry move, applied to THINK: tools and solutions interoperate through the same typed definitions, and the silos between them fall.

Addressed by Eight systemic primitives · Archetyping · DNA grammar

Agentic delivery

AI agents ship work nobody scoped, gated, or can replay.

Agentic delivery state is trapped in chat sessions; pull requests appear without a mandate; there is no event log and no human authority at the layer where it matters. Delivery runs as governed workflows with a human gate at every layer — every step authorized, every artifact validated, every action journaled in your own git history.

Addressed by Agent authorization · Artifact validation · Workflows

How it compares

Tool classes describe. Poesis defines.

Each tool class holds a partial, descriptive copy of the truth. Poesis holds the governed definition they all derive from.

Concern EA repository GRC suite CMDB / ITSM Poesis for IT
Enterprise architecture Hand-maintained inventory that drifts Out of scope Flat CI lists without architecture semantics Governed inventory of typed definitions, sourced from what runs
Compliance automation Referenced documents Checklist snapshots rebuilt per audit GRC modules on declared controls Posture computed continuously from the model
Impact analysis Static diagrams Out of scope Dependency lists, CAB approvals Blast radius simulated through typed relations
Artifact generation Manual exports and diagrams Audit reports CI reports ADR packs, evidence, baselines, roadmaps — generated, traceable to definitions
Truth sourcing Surveys, imports, curation Integration evidence sampling Discovery scans, manual registration Continuous sourcing from code, contracts, SBOMs, infra — confidence + provenance
AI-ready governance Exports Reports CIs without semantics Typed, governed definitions humans and agents act on

Evaluating a specific tool? LeanIX · Vanta · ServiceNow · Backstage

The agentic era

Agentic AI governance — for the systems your agents act on.

Model governance covers the model as an artifact; it says nothing about what agents may change in your IT. That governance has to live where the systems are defined — and it has to execute at the tempo agents act, not at the tempo audits meet.

Agentic AI governance

Agents inherit the same governed definitions your teams work on.

Obligations are evaluable Directives and Norms, verdicts are deterministic and replayable, and what an agent may trigger is itself a versioned, approved fact in the model — not a server configuration. Every action traceable to the obligation and the owner behind it.

Read: agentic AI governance that executes →

Spec-driven development

Specs that generate systems — and cannot drift from them.

When agents implement from specifications, the spec becomes the primary artifact — so it gets what primary artifacts need: a schema, a lifecycle, attached obligations, and traceability from every generated artifact back to the definitions it derives from.

Read: spec-driven development without spec drift →

Agentic delivery itself — SAFe run by agents under a deterministic harness, a human gate at every layer — is the SAF side of the same governed model.

Works with what you already run

The definition layer, not a replacement.

Poesis does not ask you to rip anything out. The sourcing bench reads the artifacts your stack already produces, and the governed model it builds is a substrate your existing tools can consume.

Git repositories

Source code is read continuously — code index, property graph, and dependency analysis turn what is committed into evidence-backed definition contributions.

API contracts

OpenAPI and service contracts source the interaction surface of your estate — who talks to whom, through what, under which obligations.

SBOMs

Software bills of materials anchor supply-chain truth — every dependency identified with confidence and provenance.

Infrastructure

Kubernetes and Helm artifacts source what is actually deployed — the running shape of the estate, not the intended one.

Named-tool connectors — ServiceNow CMDB, Backstage catalogs, EA repositories — are on the roadmap as knowledge sources feeding the same governed model.

Who it's for

Every IT profile, one governed model.

Architects author, developers consult, ops watch drift, security proves posture — all on the same governed definitions, with no translation silos between them.

CTO / CIO

One governed source of truth for your entire IT estate — and the foundation your AI strategy is missing.

EA, compliance automation, impact analysis, artifact generation, and truth sourcing become facets of one governed model — one budget line instead of five drifting tools, on a vendor-neutral standard.

Talk to us →

Enterprise Architect

An EA repository that cannot drift — sourced from what actually runs.

The inventory is continuously sourced from code, contracts, SBOMs, and infrastructure; impact is simulated through typed relations; ADR packs, baselines, and roadmaps are generated, each traceable to its definitions.

Explore ITIP →

CISO / Security leadership

NIS2, DORA, GDPR, ISO — observed continuously, proven on demand.

Continuous appraisal indicators compute your posture from the model — audit-ready every day, with findings that trace to the exact definitions and revisions they derive from.

Read: continuous regulatory compliance →

Platform / Ops / SRE lead

Kubernetes reconciles your infrastructure. Poesis reconciles everything that governs it.

The declare-and-reconcile principle you already trust, extended to architectures, obligations, and processes — an API and an operator, Helm-deployed on your cluster, not a document store.

Read the docs →

Head of AI

Your AI agents are only as trustworthy as the truth you give them.

Agents and humans reason over the same governed, typed definitions; deterministic governance evaluations wrap agent action — accountable, traceable autonomy in the estate.

Talk to us →

Built on a vendor-neutral standard

Governance you can inspect, not a black box.

Poesis for IT is delivered by ITIP, the first domain application built on the SIE engine and GSM — the vendor-neutral standard for defining systems, as OpenTelemetry is the vendor-neutral standard for observing them.