Terms for using RIVAL
Use this reference when a product term is unfamiliar. Availability statements describe the product as of 19 August 2026. A planned term explains direction. It does not mean that the feature is available now.
Read How the platform works for the complete path from a client's request to a reviewed evidence pack.
Service and people
Operator
The firm that provides the service to client organizations: an MSP, Microsoft partner, or security or compliance consultancy that serves a portfolio of SME clients. Other advisers can use the platform later. It sells the AI governance evidence service as a recurring managed service under its own brand. The EU AI Act uses operator as a broader legal umbrella for several regulated roles. Operator accounts and their first owner are available now.
AI governance evidence service
The recurring managed service an operator sells under its own brand. The client receives a scoped AI governance review, a view of its AI use and controls, and evidence classified by state. It also receives named gaps with owners and a reviewed and approved evidence pack. It sees the changes since the previous review and gets a scheduled refresh before evidence goes stale. The service is planned for the first release.
Active client
A client organization inside an active review cycle. It is the unit the operator subscription counts: three are included, and each additional active client carries the active-client fee. Login activity and the number of people never determine it, and an archived client costs nothing. Active-client billing is planned; no billing exists now.
First-client launch
The starting offer for an operator. It includes onboarding, one client organization, one scoped request or review, and one reviewed evidence pack under the operator's own brand. It also includes a proposal or statement-of-work template supplied during the launch and the pricing and margin tool. The launch fee is credited against the first three subscription months. The offer starts through the contact address on the public site; there is no checkout.
Review cycle
The recurring schedule for one client organization: its cadence, current period, and next review date. A client inside an active review cycle is an active client. Review cycles are planned for the first release.
Owner
The person who controls one operator account, its client portfolio, branding, billing, and seats. The interface shows Owner together with the operator name.
The first owner account and current portfolio controls are available now.
Consultant
A consultant seat inside an operator. A consultant works only in client organizations to which the consultant has access. This role is planned for enterprise.
Managed by
The relationship line under a client organization name. Managed by Northline Partners means that Northline Partners is the Operator responsible for that client organization.
Operator console
The operator's overview across its client organizations. It leads with requests due, reviews awaiting approval, missing and unsupported claims, and stale evidence. It shows clients without a current approved pack and upcoming review dates, and it turns each request and gap into managed work. The current operator dashboard is available now; the complete console is planned for the first release.
Client organization
A business served by an operator. It is the main boundary for people, policies, evidence, and scores. Creating and entering a client organization is available now.
Organization administrator
A person at a client organization with delegated responsibility for people and policy management. The role boundary is available now; its complete management journeys are planned for the first release.
Organization template
An operator-owned configuration that can reuse role profiles, policy sets, and assignment schedules without copying person data. Templates are planned for a later enterprise release.
Person
An employee, contractor, or other AI user inside a client organization. A person is the unit of readiness. Person management is available now.
Workspace
An optional group of people inside a client organization, such as a team or department. Workspace storage exists; workspace management is not yet available.
Tenant
The authorization and data boundary for an operation. An operator owns portfolio data. A client organization owns its people and evidence. Tenant isolation is available now.
Mapping and policy
AI map
The living inventory of AI use in one client organization. It is the organization's AI system inventory. It covers AI tools, people, use cases, data sensitivity, policies, and classifications. The AI map is planned for the first release.
AI tool
An AI system used or reviewed in a client organization, such as a chatbot, copilot, or internal assistant. AI tool management is planned for the first release.
AI tool classification
The review state of one AI tool in one organization, with data-sensitivity notes. The states are approved, unreviewed, and restricted. AI tool classification is planned for the first release.
Role profile
The risk profile for a role in one client organization. It records tools, data classes, possible consequences, and required practice. Role profiles are planned for the first release.
Role track
The role-specific set of scenarios built from one content pack's principles. AI Literacy Core launches with tracks for common employee, management, people, communication, and technical work. Role tracks are planned for the first release.
Policy
A governed document that states expectations for AI use in one client organization. Policies are planned for the first release.
Policy version
One fixed revision of a policy with a change summary, effective date, and acknowledgement state for each person. Policy versions are planned for the first release.
Acknowledgement
A person's recorded confirmation of one policy version. A material policy change also requires a comprehension check. Acknowledgements are planned for the first release.
Comprehension check
One or two questions that check understanding of a material policy change before the acknowledgement records. Comprehension checks are planned for the first release.
Pulse
A monthly check-in of about 30 seconds that helps keep the AI map current. Pulses are planned for the first release.
Practice and content
Assignment
A scheduled unit of work for a person. It can be a drill, acknowledgement, or pulse check-in. Assignments are planned for the first release.
Drill
A realistic decision that takes about 30 seconds to 3 minutes. It contains a situation, decision options, direct feedback, and a transferable principle. Drills are planned for the first release.
Principle
A behavioral rule that transfers between situations, such as checking important claims produced by AI. Principles and the launch content pack are planned for the first release.
Scenario
One authored content unit. It connects a principle, risk pattern, situation frame, role context, tool context, and consequence. One drill renders one scenario. Scenarios are planned for the first release. Scenario authoring does not mean that AI generates them.
Content pack
A maintained set of evidence claims, review structure, gap actions, principles, role tracks, scenarios, and their review and evidence rules for one subject area. AI Governance Core is the content pack included in the service, and it starts a growing library for common work situations. Its links identify affected drills after a source change. Content packs are planned for the first release.
AI Governance Core
The content pack included in the service. It supplies the base evidence claims, evidence rules, review structure, gap actions, and the AI Literacy Core component that supports an organization's AI-literacy measures. It is not compliance with, or certification under, a law. Maintained packs can extend the service later. AI Governance Core is planned for the first release.
AI Literacy Core
The literacy component inside AI Governance Core. It supplies maintained principles, role tracks, scenarios, and short drills with review rules and source lineage. A drill is one way to close a gap that a review finds; it is not standalone training. AI Literacy Core is planned for the first release.
Mastery
A person's demonstrated judgment for one principle in the person's role context. Strong mastery reduces repetition. Struggle increases targeted practice. Mastery is planned for the first release.
Freshness
How current a score, acknowledgement, classification, or practice state is. Freshness is planned for the first release.
Decay
The configured reduction of freshness over time. Decay prompts the smallest useful intervention. Decay is planned for the first release.
Refresh
The smallest useful action after decay or a change, such as one question, drill, or acknowledgement. Refreshes are planned for the first release.
Evidence and method
Request
An external or internal question about how a client organization controls AI: a customer questionnaire, an insurer, an auditor, a tender, or the board. The operator records who asked, why, which scope, when it is due, the source material, and the individual questions. Each question links to the review claims that answer it. Requests and questions are recorded by hand; automated parsing is not part of the service. Requests are planned for the first release.
Evidence source
The way evidence enters a client organization. The supported inputs are manual entry, a file upload or reference, an approved CSV import, and a Microsoft 365 audit-log export or supported audit export. Each import keeps its source, importer, and time. Direct connectors to other tools come later, and none exists today. Evidence sources are planned for the first release.
Evidence event
One append-only record of a meaningful action: who did what, when, in which tenant, and under which policy or assignment. The evidence-event foundation is available now. Drill-answer evidence is planned for the first release.
Evidence ledger
The append-only store of evidence events for one client organization. Normal product behavior does not update or delete a written event. The evidence-ledger foundation is available now.
Evidence pack
The reviewed, versioned, and dated export that an approved evidence review produces for one scope and period, with a PDF and data files. It appears under the operator's own brand. Every statement links to the records behind it. The pack includes the response index for the request it answers and the changes since the previous approved review. It documents recorded actions and current state. Evidence packs are planned for the first release. They are not a certificate, a legal opinion, or a compliance guarantee, and no third party is obliged to accept them.
Evidence review
A named review inside one client organization. It records who asked, why, which period, and which AI uses, roles, policies, and controls it covers. It links each claim to evidence, gives each claim a state, and ends in human approval and an evidence pack. Approval freezes the review; a correction creates a new review version. Evidence reviews are planned for the first release.
Evidence state
The state of one evidence review claim. Current: a supporting record exists and is within its review window. Stale: the record exists but its window has passed. Missing: the required record or control does not exist. Unsupported: records exist but do not substantiate the claim, with a recorded reason. Not applicable: the claim does not apply to the covered scope, with a recorded reason. Evidence states are planned for the first release.
Evidence gap
A claim that is stale, missing, or unsupported. Every gap names an owner and one next action. Evidence gaps are planned for the first release.
Readiness score
One client-organization score with visible components. It describes operational confidence, not legal compliance. It is a secondary summary behind the operational states of the operator console, never the main object. Readiness scores are planned for the first release.
System audit log
The platform-owned record of privileged and security-relevant actions. It stays separate from client evidence. System audit logging is available now.
Delegated access
Temporary access that keeps the real human responsible for every action. Its visible state says Logged in as.
Support session
A reasoned, expiring session for authorized platform staff entering one operator. Support sessions are planned and are not available now.
Act-as session
A reasoned, expiring session for an authorized operator actor entering a lower actor in the same scope.
Personal evidence-generating work is unavailable while logged in as a Person. Act-as sessions are planned and are not available now.
Compliance theater
Work that produces completion artifacts without improving readiness. The platform is designed to favor current practice and evidence instead. This is a product doctrine, not a software feature.
RIVAL method
The service loop: Reveal, Identify, Verify, Assemble, Loop. It connects discovery, priorities, practice, evidence, and review. The method is product guidance, not a separate control.
RIVAL review
The recurring operator-led review of a client organization's score, AI map, and evidence. It is a planned service ritual, not a software feature.
Terms with their own journey
These terms have instructions in the article that owns the current behavior:
- Account menu: profile, settings, and sign out. See Manage your account.
- Account: the user-owned area that will consolidate Profile and Preferences. The current Account menu is available; the consolidated area is planned.
- Navigation sidebar: the desktop list of work areas for the current Tenant Context. On a small screen the same destinations open from the bottom Navigation sheet. Docs stays in the guidance group at the bottom.
- Context switcher: the searchable list opened from the current context name when more than one authorized context is available. It changes working scope without changing the signed-in account.
- Operator invitation: an expiring, single-use invitation for the first operator owner. See Accept an operator invitation after you sign in as the invited actor.
- Tenant context: the organization or operator where you choose to work. See Choose where to work after you sign in.
- Language, time zone, date notation, time notation, and number notation: saved presentation settings. See Manage your account after you sign in.