MODULE

Divan — the governance studio

Divan lets you manage roles, retention, redaction, and policy from one place. Compliance writes the rules of AI; the platform enforces them.

Who can ask what — role-based access.
What gets redacted — policy-based redaction.
How long it is kept — retention rules.

Use cases

Role-based access design

Configure, on one screen, that only HR can query HR data and only the credit team can query loan files; exceptions are justified and recorded.

KVKK retention and disposal

Retention periods are defined per data category; expired content is processed under the disposal policy, and the act itself is recorded.

Personal data redaction

Patterns such as national ID numbers, IBANs, and card numbers are masked in answers by policy; institution-specific patterns can be added.

Policy change management

Policy changes are dry-run tested first, pass through an approval flow, then take effect — reducing the risk of accidentally opened access.

Capabilities

Access management

  • Authorization by role, unit, and source
  • Narrowing query scope by role
  • Mapping to existing directory (LDAP / Active Directory) groups

Redaction engine

  • Built-in personal data patterns: national ID, IBAN, card number, phone
  • Institution-specific patterns and dictionaries
  • Masking is applied at answer time; source data is never altered

Retention and disposal

  • Retention periods per source and category
  • Timestamped records of disposal operations
  • Legal-hold exceptions

How it works

  1. 01

    Draft the policy

    Define the access, redaction, or retention rule in a plain interface.

  2. 02

    Test with a dry run

    See the policy’s effect on sample queries before it takes effect.

  3. 03

    Send for approval

    The change passes through your approval flow; the approver is recorded.

  4. 04

    Put it into effect

    The policy applies to all modules at once; no module can opt out.

  5. 05

    Monitor and report

    Enforcement records are watched on a dashboard and reported for audit.

What it delivers

  • Designed to close the policy gap between compliance and IT
  • Turns KVKK retention and disposal obligations into operational rules
  • Access decisions bind to policy, not to individuals
  • All modules obey one governance layer; there is no separate rule set

Why it matters

AI governance cannot be run over email and spreadsheets. Divan gathers access, redaction, and retention into a single layer designed to support KVKK and sector obligations.

Auditability

Every policy change is logged with who, when, and what changed; access decisions and redaction events can be examined after the fact.

Related modules