AIR
Proof Lab
StartEcosystem
Explore (579)Live Systems (52)Pricing
Log InGet API Key✓ Verify It Yourself
H33
H33 HATS
SETUP WIZARD
Onboarding Progress
Step 1 of 5
1
2
3
4
5
Profile
Identity
Governance
Controls
Activate
Step 1 of 5

Organization Profile

Related · tier-1 reading. For the evidence chain that supports the claim, see Claims Evidence.

Tell us about your organization so we can configure your HATS deployment correctly.

Step 2 of 5

Connect Identity Provider

HATS imports your organizational structure — users, roles, and MFA posture — to build the identity layer for governance.

🔐
Okta
Connect Okta to import users, roles, and MFA state across your organization.
Connected
🏢
Azure AD / Entra
Connect Microsoft Entra for identity and device posture signals.
Connected
🌐
Google Workspace
Import users and security settings from Google Workspace.
Connected
⚙️
Manual Setup
Configure participants manually via CSV import or API.
Configured
🔒
HATS imports your organizational structure. No plaintext credentials are stored — only cryptographic attestations of role and MFA state.
Step 3 of 5 — Governance Configuration

Define your governance rules

Q-Sign enforces these rules cryptographically. No silent overrides. No bypasses.

💸
Wire Transfer Governance
High-value transfer approval chain
Amount Threshold
Required Roles
Jurisdiction separation
Wires above this amount require these approvals before execution.
🤖
AI Agent Boundaries
Autonomous action limits
Max Autonomous Amount
Allowed Actions
Auto-escalation on breach
AI agents operate within these bounds. Exceeding triggers human escalation.
🏗️
Infrastructure Changes
Production deployment controls
Required Roles
Dual-approval required
Production deployments and infrastructure changes require these approvals.
🚨
Emergency Override
Executive quorum for critical actions
Emergency Quorum
Time Limit (hours)
Notify all principals
Emergency actions bypass normal flow but require executive quorum and expire.
Policies are hash-committed and immutable once active. Changes require policy supersession with a full audit trail — there is no silent edit path.
Step 4 of 5

Verify Controls

HATS performs an initial sweep of your security control posture. Once your sources are connected, each observed control is recorded into cryptographically attested evidence.

Setup demonstration — this walkthrough sweep shows the flow using sample states until live sources are connected; it is a HATS recording step, not an independent verdict. Independent verification is a separate step at Verification.

🪪
Identity
MFA enforcement, SSO configuration, user provisioning
💻
Endpoint
EDR deployment, patch currency, device compliance
🛡️
Backup
Encrypted backups, restore testing, offsite replication
🔑
Data Protection
Encryption at rest, key management, data classification
📧
Email Security
DMARC, DKIM, SPF, anti-phishing controls
🌐
Network
Segmentation, monitoring, access controls, DNS filtering
Deployment Complete

Your organization is live

HATS is continuously verifying. Q-Sign governance is cryptographically enforced.

HATS ACTIVE
Organization
Identity Provider
Governance Policies
4 active
Controls Verified
6 / 6
HATS Status
ACTIVE
Q-Sign Status
ENFORCING
Your organization is now continuously verified. Governance is cryptographically enforced. Controls are attested every 15 minutes. Posture changes are committed to the audit ledger in real time.
HATS · Records operational evidence

What setup configures

Definition. Setup configures the sources HATS will record from — organization profile, identity provider, Q-Sign governance rules, and the controls to observe. HATS then records and monitors the operational evidence that those declared controls kept operating, over time, into a defined, replayable record. Setup connects the record; it does not itself render the verdict. Verification renders the independent verdict on an existing artifact; HICS assigns a maturity score; Agent-008 governs an AI agent's decision.

What you need to set up

An organization profile, one identity provider connection, your governance rules, and the security controls to observe (identity, endpoint, backup, data protection, email, network). Why a distinct setup step: HATS can only record evidence about controls it has been pointed at, so setup establishes the sources before continuous recording begins. When not to use setup: if you need an outside party to render a verdict on an artifact that already exists, that is Verification; if you need a maturity grade of your program, that is HICS.

Setup records; it does not independently verify

Completing setup starts HATS recording and monitoring operational evidence. The wizard's initial control sweep is a setup demonstration of the flow — it uses sample states until live sources are connected and is a HATS recording step, not an independent verdict. An independent, offline verdict that a recorded artifact reproduces is a separate step performed by Verification. Do not treat HATS monitoring as independent verification.

Which H33 component do I actually need?

Use HATS (setup) when the requirement is continuous operational evidence that controls kept operating.
Use Verification when the requirement is an independent verdict on an existing artifact — not monitoring.
Use HICS when the requirement is a maturity score of a program.
Use Agent-008 when the requirement is to govern an AI agent's decision.

FAQ

What do I need to set up?
An organization profile, an identity provider, your Q-Sign governance rules, and the controls to observe. HATS then records the operational evidence that those controls kept operating.
Is the setup control sweep a live verification?
No. It is a setup demonstration using sample states until live sources are connected. It is a HATS recording step, not an independent verdict on your systems.
Does completing setup mean my systems are independently verified?
No. Setup starts HATS recording and monitoring. An independent, offline verdict that a recorded artifact reproduces is a separate step performed by Verification.
How is HATS setup different from Verification?
Setup configures HATS to record operational evidence over time. Verification renders an independent verdict on an artifact that already exists. Setup connects the record; Verification checks it.

Owner: HATS standard (records/monitors operational evidence) · Evidence anchored on H33-74 · Independent verdict via Verification · Maturity score via HICS · AI-decision governance via Agent-008.