Ethics and governance

Trust is earned in the open

The businesses we work with run on people, and the people are the point. This page says what we will and will not do with AI in your business, in terms you can hold us to. It is written for the owner and the board, and it is the position every engagement is run under.

The dignity of work

Our view is that a business is its people, and that the case for AI in an Australian business is more output from the team you have. The recurring load, the re-keying, the month-end scramble and the inbox that never empties are what an AI Employee is for. The judgement, the relationships and the decisions are what your people are for, and they get more of their week back to do them.

We will not write a proposal whose case rests on a smaller team. Where a role can be done by an agent, we say so and we say what the person in that role does next, and that conversation happens with you before anything is deployed.

Eleven things you can hold us to

  1. 01

    A person signs off on every consequential action

    Reading, drafting and analysis run on their own. Anything that changes a record, sends money, reaches a client or leaves the building is proposed and held for a named person to approve. That gate is a design choice and it is not for sale.

  2. 02

    Transparent, with a person in the loop

    Every action an agent takes is visible while it happens and can be reviewed or overridden at any step. Nothing runs in a place your people cannot see.

  3. 03

    Auditable by default

    Every action is recorded with what was done, when, on whose approval and with what data. The audit trail exists before anyone asks for it, and it is yours.

  4. 04

    Your data is never used to train external models

    Client and customer data stays inside your deployment. Skills travel between deployments as the roles mature, and your data stays where it is.

  5. 05

    Australian data residency for Australian deployments

    AI Employees deployed for Australian businesses run on infrastructure in Australia, and personal information is handled under the Australian Privacy Principles.

  6. 06

    Augmentation by design

    Agents extend what your team can already do. Your people keep the roles they hold, and the work left to them is the work that needs a person.

  7. 07

    Self-directed, within its role

    An agent picks up its own next task against its objectives. It does not set those objectives, widen its own access or change its own rules. Those decisions stay with people.

  8. 08

    A position description for every role

    No agent is deployed without a written position description that names its objectives, its KPIs, the systems it can reach and the actions that need sign-off. It is measured against that document and stood down against it.

  9. 09

    Everything we produce is handed over in full

    Assessments, plans, policies, position descriptions, builds and their source. You can act on any of it with us, with someone else, or with your own people, and we write it so all three work.

  10. 10

    An independent security review before any build goes live

    Where MyBizz scopes a build, an independent reviewer checks access, data handling, logging and sign-off points before it reaches production. The reviewer is independent of us and of the builder.

  11. 11

    Honest limits, stated in advance

    We tell you what an agent will not do, where it will be wrong early on, and when the right answer is a person or a process change. If nothing is worth doing yet, the assessment says so.

What an agent never does alone

These are written into every position description and enforced by the platform, with the approval taken in the channel your people already use.

  • Send money, change a bank detail or approve a payment without a person.
  • Send anything to a client, a supplier or a regulator without a person.
  • Change a record of account, a contract or a payroll entry without a person.
  • Reach a system its position description does not name.
  • Widen its own permissions, change its own objectives or rewrite its own rules.
  • Pass your data to a model provider for training, or to any third party you have not approved.

The Australian standards we build to

Governance plans and position descriptions are drafted against the standards that apply to your business, so your own compliance work can point at ours.

Privacy Act, APP 11
Security of personal information: reasonable steps to protect it from misuse, interference, loss and unauthorised access, and to destroy or de-identify it when no longer needed.
APES 110
The Code of Ethics for Professional Accountants. Relevant to every accounting firm we work with, and the standard we hold our own financial advice to.
CPS 234 and CPS 230
Information security and operational risk for APRA-regulated entities and the service providers they rely on. Our governance plans are written so a regulated client can show its own compliance.
Essential Eight
The Australian Cyber Security Centre's baseline mitigation strategies, used as the reference for access, patching, backups and privilege in any deployment we scope.

Certifications held by the Legare platform are published on the Legare site. We publish a certification as our own only once we hold the certificate.

A policy your board can adopt

Most businesses we meet have staff using AI already and no written position on it. Writing that position is part of the AI assessment: an acceptable use policy, the sign-off points, the record keeping, the data rules and who owns each of them. It is drafted in plain language, tested by the AI champions cohort, and handed over for the board to adopt.

Thirty minutes, one conversation

Bring the question your board is asking about AI. We will answer it in plain terms and show you where the sign-off gate, the audit trail and the data rules sit in an engagement, before anything is deployed.

Book a 30 minute conversation