Handvantage

THE PRODUCT

Vantage Workspace.

The platform we built because the alternative — assembling the AI work surface out of twelve vendors with twelve identities and twelve audit logs — wasn't a purchase, it was a project.

Vantage Workspace is a single-tenant AI workspace for regulated organizations: one isolated instance per customer, with managed-private, private-cloud, and customer-hosted deployment options. The selected configuration determines the boundary, policy model, and approved public or local model routes.

This page documents what's in it, how it's built, and where the architectural decisions came from.

vantage workspace / owner view
Vantage Workspace owner view showing measured finance and pipeline signals with a clear statement that no external action was taken.
Demonstrated owner workflow — measured operating signals, bounded authority, and an explicit no-action state.

THE PLATFORM

Seven pillars. One identity.

Most AI products sit beside the work. Vantage Workspace is the workspace the work happens in: email, files, chat, meetings, documents, signing, identity, and AI Workers operating across all of them.

Each pillar leads with what your team actually does with it. The architectural detail is in the body for the engineers and architects who care; for everyone else, read the headlines.

Your team’s inbox, ten minutes shorter.

Mail sits inside the workspace identity boundary. In a guided workflow, an AI Worker can prepare a draft for human review rather than silently completing an external communication. The connected mailbox route and final-send authority are qualified for the customer's environment.

The proof should show the source message, draft, named reviewer, approval state, and retained event. It should stop at preview or approval unless the customer has explicitly authorized the send path.

Files and browser editing inside the same workspace identity.

The Files surface provides workspace storage, browser access, preview, and editing through the shared sign-in experience. It gives a team a practical place to keep the documents used by a governed workflow.

AI retrieval is scoped and verified per workflow. The denied path is designed to fail closed; an entitled per-document path is not treated as generally proven until it is exercised with the customer's selected source and role.

Team conversation under the workspace sign-in.

The Chat surface provides rooms, direct conversation, and file-sharing inside the workspace sign-in. It keeps team communication near the work without turning a third-party chat identity into the control model.

Where an AI Worker participates, the buyer proof confirms the invocation route, attribution, posting authority, and retained event for that exact workflow.

Meetings available from the same workspace launcher.

The Meet surface gives teams a video-conferencing route from the workspace. Sign-in behavior, network reachability, and the meeting boundary are verified in the selected deployment.

Recording, transcription, calendar, and action-item automation are qualified before they enter a customer proof. An available meeting surface is not itself evidence that those downstream workflows are configured.

Draft in Desk, then hand the artifact to the reviewer.

Documents can be edited in the workspace while Desk supports guided drafting and analysis. The useful boundary is between producing content and granting authority to publish, sign, or send it.

A proof names the source document, expected draft, reviewer, rejection rule, and final artifact location. Saved-document handoff is qualified for the selected route instead of promised from a generated answer alone.

The finance surface is part of the workspace, not a Xero dependency.

Vantage Books runs on the bundled ERPNext environment. It gives the team a native route for customers, invoices, receivables, payables, expenses, payments, and financial summaries. The AI Worker can read that operating context and prepare finance work inside the same identity and review model as the rest of the workspace.

Xero can be connected as an additional ledger route where it fits the organization. It extends the finance surface; it does not create it. Actions that change finance records are presented for human confirmation, while read paths support close review, exception handling, and operating questions in plain language.

Named teammates that handle the work nobody enjoys.

The AI workforce layer structures work around named roles rather than one general-purpose assistant. A Worker receives a bounded job, source, authority, reviewer, rejection rule, and expected evidence.

Finance, people operations, business operations, sales, marketing, and compliance roles can be demonstrated against verified workflows. Customer-specific roles are qualified through the same proof charter rather than added to the offer by title alone. The buyer-test model is documented on the architecture page.


THE AI WORKFORCE MODEL

Named AI Workers, bounded jobs, visible human authority.

Vantage Workspace structures AI work as named roles with bounded jobs. The buyer should be able to distinguish the human requestor, AI Worker, source, permitted authority, reviewer, and result for the workflow under evaluation.

The proof begins with decision rights: read, draft, recommend, approve, or act. It then tests an allowed path and a denied or approval-gated path, rather than assuming a role label enforces the boundary.

This means three things at runtime:

  1. Attribution is testable. The demonstrated event should identify the human and AI Worker involved in the run.
  2. Authority is explicit. A draft is not an approval, and an approval is not permission to send or post.
  3. The failure path is exercised. The buyer asks for an out-of-scope source or higher-authority action and inspects the refusal or human approval gate.

Customer-specific roles can be configured after the job and evidence standard are agreed. The role name is not the proof; the observed authority boundary and retained event are.

The full workforce specification, including scope declaration and evidence outputs, is documented on the architecture page.


The runtime

One configured environment. One workflow to verify.

On-prem Agentic AI deployment rack: Governance & Compliance Crown, Observability & Incident Response Kit, Mission Engine Plane, Vector Index Cartridge, Local Model Pod, Secret Vault & Key Management, Network Segmentation Panel, Storage Array, Compute Blade Stack, Enterprise Rack Chassis.

Vantage Workspace is deployed as a single-tenant environment. Managed-private, private-cloud, and customer-hosted options are scoped to the customer's operating model, identity source, data boundary, model routes, and support responsibilities.

The architecture separates the work surface from the control layers that govern identity, policy, model access, tool authority, memory, and evidence. That separation matters because a reviewer can test a specific workflow and inspect which controls participated, instead of inferring control from a vendor diagram.

Identity can be provided by the workspace or federated to an approved customer identity provider. The proof should demonstrate the user, AI Worker, role, and approval boundary that apply to the chosen job, including what happens when access is not granted.

Integrations are qualified before they enter the proof. A buyer names the source system, permitted read or write, reviewer, rejection rule, and record to retain. That prevents an available connector from being mistaken for a proven operating workflow.

  • TENANCY

    Single tenant

    One configured customer environment

  • IDENTITY

    Named actors

    Human and AI Worker roles

  • MODEL ROUTE

    Customer approved

    Public, private, or local

  • AUTHORITY

    Role scoped

    Read, draft, approve, or act

  • EVIDENCE

    Attributable

    Decision and outcome retained

  • DEPLOYMENT

    Choice

    Managed-private · private-cloud · customer-hosted


DEPLOYMENT

Choose the operating boundary before the infrastructure pattern.

Vantage Workspace is single tenant. The deployment decision starts with the customer's data, identity, model-route, operations, and support requirements, then selects a managed-private, private-cloud, or customer-hosted pattern.

Managed-private is suited to teams that want a dedicated environment with Handvantage operating the approved service boundary. Private-cloud places the environment in a customer-approved cloud account or region. Customer-hosted is considered where the customer has the operational capacity and the requirement to run the environment.

None of those labels proves sovereignty by itself. During the proof, the parties name where the workspace runs, where each source resides, which model route is approved, what content may cross that route, who operates the environment, and what evidence the customer can retrieve.

Restricted or disconnected deployment requirements are qualified separately. The product team verifies the required model, update, support, identity, and evidence paths before describing a configuration as offline or air-gapped.

deployment / evidence chain
Editorial illustration showing a digital action connected to a sealed operating record and a review artifact.
Deployment choice is only one part of the answer. The selected source, model route, authority, decision, and retained evidence must travel with it.

EVIDENCE

A buyer should be able to reconstruct the demonstrated job.

The evidence test begins with one bounded workflow: who asked, which AI Worker acted, which source was touched, which policy or approval applied, which model route was used, and what outcome followed. The buyer retrieves the record from the demonstrated environment rather than accepting a prepared screenshot.

Vantage Workspace records attributable events for governed workflows. Coverage is assessed per workflow and configuration; the website does not treat an audit-log capability as proof that every possible application action is captured.

A useful evidence review asks for:

  • The named human and AI Worker involved in the run
  • The source, model route, policy decision, and approval boundary in scope
  • The outcome, refusal, or escalation the run actually produced
  • The assessment window and loaded framework mappings
  • A rerun selected by the buyer, with the resulting evidence retrieved again

Assessment reports map observed evidence to the selected framework templates. They are decision-support artifacts, not an audit opinion, certification, or assurance statement about the customer organization.

The framework mappings and buyer-verification method are described on the compliance page.

workspace.local / trust / events
A governed-workflow event showing sensitive data detected in an AI Worker draft and the configured boundary decision recorded for review.
A demonstrated boundary event: sensitive data detected, decision recorded, outcome available for review.

BOUNDARIES

What Vantage Workspace deliberately does not do.

Most product pages list features. This section lists non-features — the things the platform deliberately does not do, why, and what the alternative is.

Vantage Workspace does not host your model.

The platform integrates with approved LLM providers — OpenAI, Anthropic, Azure OpenAI, AWS Bedrock, Google Vertex, or self-hosted (Ollama, vLLM, TGI). We do not ship a “Handvantage AI model”. The point of the platform is the architecture around the model, not the model itself. If your AI strategy requires a specific model (Claude for legal review, GPT-4 for code, a fine-tuned in-house model for customer support), the platform routes prompts according to the configured policy and records the routing decision. A local-only configuration is the specific case in which zero public-model calls can be claimed.

Customer activity is not used to train a shared Handvantage model.

The demonstrated deployment keeps cost, usage, worker-activity, and audit records in the configured customer environment. Approved external model routes receive only the request content permitted by that route's boundary and policy. The evidence review should verify the selected deployment and route configuration rather than infer a universal local-only posture.

Vantage Workspace does not “auto-improve” from your data.

The platform does not use customer activity to train a shared Handvantage model. Model providers, routes, and versions are selected in the deployment configuration; a reviewer can inspect the configured route and the recorded decision for a demonstrated workflow.

Vantage Workspace does not replace your source of identity.

The platform includes the workspace identity layer AI Workers need, and it can federate to the identity provider you already operate (Okta, Auth0, Microsoft Entra ID, Google Workspace, or Keycloak). It does not try to become your enterprise directory, SIEM, or secrets vault. The decision rationale is documented on the architecture page: identity is too important to re-implement.

Vantage Workspace does not “auto-classify” or “auto-redact” content.

There are policy hooks where a customer can configure classification or redaction (e.g. via a connector to Microsoft Purview, AWS Macie, Google DLP, or a custom classifier). The platform does not ship its own classifier. The reason is operational: classifier behavior drifts over time, and the customer's compliance team needs control over the classifier's training and update cadence.


RELEASE EVIDENCE

Ask what was tested on the build you are evaluating.

Historical sprint counts and rollback records age quickly. A stronger procurement question is whether the vendor can identify the build under review, show the tests that ran against it, disclose known limits, and reproduce one control result in the buyer's presence.

  • Confirm the build identifier displayed by the environment.
  • Choose a control or workflow result the buyer can rerun.
  • Retrieve the evidence produced by that run and compare it with the claim.
  • Record any known limit, dependency, or source-system qualification before the proof is accepted.

The current public proofs and buyer guidance are maintained in the insights archive. Deployment-specific release evidence is reviewed during a qualified evaluation.


BUYER QUESTIONS

The questions a serious evaluation should answer before the pilot.

What is Vantage Workspace?
Vantage Workspace is a single-tenant AI workspace where AI Workers work alongside humans under a shared identity, approval, and evidence model in a customer-controlled environment.
Is Vantage Workspace a SaaS product?
Vantage Workspace is single-tenant rather than a shared multi-tenant application. Deployment options include managed-private, private-cloud, and customer-hosted environments, scoped during the engagement.
Can a customer bring public LLMs like GPT or Claude?
Yes. Customers can use approved public or private models through governed model routes. A specifically configured local-only deployment can operate with zero public-model calls; other configurations apply the same boundary, identity, approval, and evidence controls to customer-approved public routes.
What evidence does the platform produce?
A demonstrated governed workflow can retain the named human, named AI Worker, model route, policy decision, source touched, approval path, and time of action. Buyers should verify the fields and export path required for their workflow during the proof.
Who is Vantage Workspace for?
Vantage Workspace is for regulated organizations and the partners that serve them: CISOs, CTOs, compliance leaders, privacy leaders, heads of data, MSPs, MSSPs, vCISO practices, and security consultancies.

CONTINUE THE CONVERSATION

If you'd like to walk through a deployment, talk to us.

The most useful conversation about Vantage Workspace is the one where we sit with your operator team for thirty minutes and look at your existing identity, audit, and compliance posture. We'll tell you where the platform fits and where it doesn't.

Talk to us about a deployment →

Or write to hello@handvantage.com directly.