Govern every agent. Then hand an auditor the proof.
ACTAVA CHRYSO is the governance and training suite for healthcare AI. It writes and versions your AI policies, trains your workforce against them, and runs a registry that tests every deployed agent against 85+ regulatory controls. Every sign-off, score, and run becomes timestamped evidence, so an audit request is a package you generate instead of a quarter you lose.
Agents reach production faster than the governance around them.
Your teams are building agents against claims, charts, and members. The rules that decide whether those agents are allowed to run were written for software that does not reason, and they keep changing underneath you. Governance that lives in a spreadsheet and an annual review cannot keep pace with a workforce that changes every week.
Long-horizon healthcare tasks the best frontier agent finishes on the first try.
End-to-end prior authorization those same agents complete unassisted.
Policy documents the benchmark's tasks are grounded in. Dense policy is where agents fail.
An agent you cannot account for is an agent you cannot defend.
Accountability means knowing which agent acted, under which policy, with which model, and with what result — for every run, not for the handful you sampled. CHRYSO holds that record. It is the governance layer every agent built on ACTAVA already ships with, and it works the same way for the agents your teams built somewhere else.
Read the χ-BENCH studyMost AI governance reports. CHRYSO enforces.
A cost ceiling that stops a run before the invoice arrives. An approval gate a builder cannot route around. An AI inventory the deploy event writes by itself. CHRYSO is not a reporting layer sitting beside your agents — it is the same set of controls the ACTAVA runtime executes against, which is why the record it produces holds up in front of an auditor.
Fig. 01 — the same run, under a reporting layer and under CHRYSO
A dashboard tells you what already happened
Usage charts tell a CFO what an experiment cost. A quota that blocks the run at the gate tells them what it can cost. In healthcare, where one agent run may touch PHI, scheduling, or a member record, after-the-fact reporting is not governance.
Bolted-on governance drifts
A register maintained by hand goes stale the day a builder ships a new version. The CHRYSO register is written by the go-live event itself. When a version changes, attestation re-opens. Drift announces itself instead of aging quietly until the audit.
Locking down builders is not control
Restricting agent authoring to a platform team protects the organization by killing adoption. CHRYSO takes the opposite position: anyone can build, and going live is the governed act.
Write the policy, train the people, and test every agent against both.
An enterprise AI policy suite
Framework-aligned policy templates, versioned and change-tracked, mapped control by control to the standards you answer to. Role-based acknowledgement workflows put the current policy in front of the people it binds — and record that they read it.
See the frameworksTraining that turns policy into competency
Scenario-based curricula written for clinical, administrative, and technical roles, with scored assessments tied to the controls they satisfy. Completion tracking, certificates, and gap analysis come out audit-ready rather than needing to be assembled.
See how it worksA registry that tests every deployed agent
Specialized testing agents validate your agentic systems against 85+ regulatory controls spanning NIST AI RMF, HIPAA, CMS HEI, and ONC HT1. The registry holds the record: which agent, under which policy, against which model, with what result.
Explore KORA:REDSix capabilities, one record
CHRYSO is one system, not six tools bolted together. Policies bind people, training proves they understood, the registry watches the agents, and every one of those events lands in the same evidence store — dated, crosswalked, and ready to hand over.
A policy library that stays current
A living library of AI governance policies, automatically versioned and change-tracked, with every clause mapped to the control it satisfies. Acknowledgement is routed by role, so the people bound by a policy see the version that binds them and their sign-off is dated.
Training that proves competency, not attendance
Scenario-based curricula aligned to HIPAA, NIST AI RMF, and ONC, delivered on demand or on a schedule. Scored assessments draw on control-linked question banks with configurable pass thresholds, and the results generate certificates and a gap analysis rather than a completion list.
A registry that knows every agent
Every AI system, agent, and model registered with an owner, a risk tier, and the frameworks that apply to it. Specialized testing agents validate each one against 85+ regulatory controls before it goes live, and the registry keeps the record of what ran, under what policy, and how it scored.
Monitoring and red-teaming that never stop
Deployed agents are watched against governance thresholds with real-time behavioral telemetry, drift detection, and fairness analysis. Through the KORA:RED integration, CHRYSO probes live agents for PHI leakage, hallucination, bias, prompt injection, and scope-boundary breaks, and alerts before a member is affected.
Evidence that assembles itself
Policy acknowledgements, training completions, assessment scores, and evaluation runs become structured, timestamped artifacts on a tamper-evident log. One item can satisfy requirements in several frameworks at once, so an auditor package scoped to a framework, a control domain, or a period takes minutes rather than a quarter.
Regulatory intelligence that watches the law
Curated feeds track enacted and pending state AI laws alongside federal guidance, mapped to your control environment the moment they take effect. When a rule moves, CHRYSO shows what it touches, recommends the remediation, and puts the deadline on the calendar.
Six places the runtime stops, checks, and writes it down.
Cost, value, approval, runtime authority, compliance, and attestation. Every one of them is shipped behavior rather than roadmap, and every one of them acts on the run instead of describing it afterwards.
A spend ceiling that stops the work
Every agent run is metered at the inference call, at each model provider's actual rates, and converted into one tenant-facing measure: the Orchestration Unit. Finance reads one number, not a stack of provider bills.
- One Orchestration Unit as the single usage measure shared by runtime metering, ROI projections, and quotas.
- A monthly quota per organization, with warnings at 50% and 80% of the ceiling.
- At 100%, the run gate refuses to start the run. The ceiling is enforcement, not a notification.
- A per-request usage ledger priced at the moment of use, so a later price change never rewrites history.
The business case is computed, not written
Each organization tunes its own cost model: dollars per unit, units per run, build and maintenance assumptions. Every agent's ROI justification is derived from that model against locked configuration, then reconciled against what actually ran.
- A ranked value-driver catalog per organization; an agent's contribution is graded against it, never self-declared.
- The justification packet is computed at submission from locked state — it cannot be hand-authored or borrowed from a template.
- KPI actuals land per run, so attainment sits beside the projection.
- A drifted business case is flagged as stale rather than quietly presented as current.
Anyone can build. Going live is a decision.
A citizen developer builds freely in draft. Submission locks a version and hands the reviewer a complete package: configuration, the computed justification, and a performance baseline from evaluation. Behind it sits a state machine, not a message thread.
- A six-state review lifecycle: submitted, in review, changes requested, approved, declined, withdrawn.
- At most one open submission per agent; resubmission after changes continues the same review.
- A pre-submission readiness meter that clears only when a completed evaluation baseline exists for that exact version.
- Reviewer triage stays private, so review status never leaks to the builder mid-decision.
Approval inside the run, not just before it
An agent about to take a consequential action raises an interrupt to a named approval group and waits. Reviewers respond in the product or from Slack, under a quorum policy the organization sets. Human-in-the-loop is a runtime control here, not a design principle on a slide.
- Approval groups with configurable policy, quorum, and timeout; requests reach every member.
- Each approved side effect is claimed in a ledger before execution, so a retrying agent cannot submit it twice.
- The ledger stores metadata only: no arguments, no results, no new PHI surface.
- Access to another team's agent routes a co-sign request to its owner and returns a real answer.
An AI inventory that writes itself
Regulators are converging on one question: which AI systems do you operate, and who signed off. On CHRYSO, agents register themselves at go-live, sync when a version changes, and retire at shutdown. The inventory is a product of deployment, not an annual exercise.
- System characteristics answered in tiers — derived from configuration, inferred, or entered manually — then attested by a human.
- A changed answer flips the system to reconfirm, so sign-off re-opens instead of silently aging.
- Control frameworks are published centrally and consumed by reference, with versioned publications.
- Evidence is collected once and mapped to every control it satisfies across NIST AI RMF, HIPAA, CMS HEI, and ONC HT1.
A record built for the auditor
Policy, training, and access each resolve to signed, timestamped, content-anchored facts, written by the transitions themselves into an org-scoped log with no update or delete path in the code.
- Policy versions require a two-approver quorum, with one vote per approver and activation in the same transaction.
- Acknowledgment binds to the exact policy version, with actor, timestamp, and content hash; a new activation re-opens acknowledgment.
- Training completions carry a recertification window; expiry removes the control credit they earned.
- Support access is a credentialed, time-boxed session with a stated reason and a customer-side revoke.
Specifications
Shipped behavior, not roadmapBuilt for the standards that decide whether your AI is allowed to run.
Deep, native support for the frameworks that govern AI in healthcare and the public sector — and for the state laws that keep landing between them.
NIST AI Risk Management Framework
The authoritative federal framework for AI risk governance. CHRYSO maps every function — Govern, Map, Measure, Manage — to executable controls, evidence requirements, and named accountability.
HIPAA Privacy & Security Rules
Compliance across AI systems that process, generate, or interact with protected health information, with control evidence spanning both the Privacy Rule and the Security Rule.
CMS Health Equity Initiative
Algorithmic fairness in coverage and utilization management, with bias monitoring and disparity documentation built for the CMS auditors who ask for it.
ONC Health IT Certification (HT1)
Certification requirements for health IT deploying AI: algorithm transparency, clinical decision support governance, and the information-blocking provisions that reach AI-generated output.
State AI laws & emerging regulation
Enacted and pending state AI law — automated decision-making, algorithmic accountability, disclosure, consumer rights, and healthcare-specific mandates — mapped to your control environment the moment it takes effect.
Controls mapped across frameworks, always current.
Major frameworks fully supported: NIST, HIPAA, CMS, and ONC.
Continuous agent monitoring with real-time safety guardrails.
Every control mapped. Every gap visible.
One source of truth for your compliance posture — structured by framework, tracked by status, and current the moment the underlying evidence changes.
- Multi-framework crosswalk
- One evidence item satisfies requirements in several frameworks at once, so the work is done once rather than once per auditor.
- No manual uploads
- Evidence is generated by policy acknowledgements, training completions, assessment scores, and evaluation runs as they happen.
- One-click packages
- Export a formatted package scoped to any framework, control domain, or audit period, ready for submission.
Illustrative register · sample tenant
A demo that behaved once tells you nothing. Red-team every agent on a schedule.
CHRYSO integrates natively with KORA:RED, the red-team engine built for autonomous agent evaluation. Live agents are probed for PHI leakage, hallucination, bias, prompt injection, and scope-boundary breaks, and watched against behavioral baselines so drift raises an alert before it reaches a member. Every evaluation produces structured evidence mapped to the controls it answers — the same evidence the register above hands to an auditor.
- Failure classes probed on every agent
- 0 failure classes probed
- Monitoring cadence
- 24/7 behavioral monitoring
- Controls an evaluation maps to
- 0+ controls per agent
Governance platforms usually satisfy the risk office or the builders.
CHRYSO is built to satisfy both at once — the same controls, read from two ends. The office that answers for the risk gets limits it can set and a record it did not have to assemble. The teams doing the work get to build without asking permission to start. Holding that authority in-house is the operational half of AI sovereignty.
For the office that owns the risk
CFO, CISO, and CIO get limits with teeth and a record they did not have to assemble.
- Set a monthly ceiling per organization and choose whether breaching it warns or halts.
- See spend by agent, by trend, and per request, priced at the moment of use.
- Approve what goes live with the business case and a performance baseline in the same view.
- Hold an AI-system register that updates itself, backed by an append-only attestation trail.
- Rely on role-based access enforced at the API. Hiding a button is never the control.
For the people who actually build
Clinical, operational, and administrative teams ship agents without a platform-team queue, and without stepping outside policy.
- Build conversationally in a private draft; nothing you try in draft is a governance event.
- A readiness meter shows exactly what is missing before you submit.
- Submission assembles the justification for you, from the configuration you already built.
- Changes requested come back as notes on your agent, and resubmission continues the same review.
- Need another team's agent or data? The request routes to its owner and returns a real answer.
Designed for every regulated AI operator.
Health systems & hospitals
Govern AI-assisted clinical decision support, diagnostic tools, and care coordination agents across HIPAA, ONC, and CMS requirements, with equity standards and patient-safety oversight intact.
Health plans & payers
Satisfy CMS Health Equity Initiative mandates for algorithmic fairness in coverage and utilization management, with bias monitoring and disparity documentation built for CMS auditors.
Government & public sector
Meet federal and state AI accountability requirements: automated decision-making disclosures, impact assessments, and NIST AI RMF compliance for high-risk systems.
Life sciences & pharma
Govern AI in clinical trials, drug discovery, and regulatory submissions with traceable evidence chains, validated model governance, and cross-framework documentation.
AI vendors & technology
Demonstrate regulatory readiness to healthcare and government buyers by keeping HIPAA, NIST AI RMF, and ONC-aligned documentation and third-party evaluation records current.
Compliance & risk teams
Replace fragmented spreadsheets and manual tracking with real-time posture visibility, automated evidence collection, and alerting when the rules change.
From inventory to audit-ready
Three phases, each resting on the one before it. CHRYSO is built to return compliance value in days rather than quarters, so the first audit package is something you generate long before anyone asks for it.
Take inventory.
Every AI system on the books, tiered by risk, with the gap list in hand.
Register every AI system, agent, and model, each one with a named owner.
Classify risk tiers automatically, so the controls that apply are already decided.
Map your posture against every applicable framework and get the gaps on day one.
Operate under policy.
The policy published, the workforce trained, and both on the record.
Publish framework-aligned policies, versioned, with acknowledgement routed by role.
Train clinical, administrative, and technical staff on the curriculum their work needs.
Attest with sign-offs and scores that become control evidence, no manual upload.
Prove it continuously.
Agents watched, probed, and packaged for whoever asks next.
Watch every deployed agent for drift, bias, and threshold breaches, continuously.
Red-team live agents for PHI leakage, hallucination, prompt injection, and scope breaks.
Export an auditor package scoped to any framework, control domain, or audit period.
The governance is the runtime.
Cost is metered where inference happens. The register is written by the deploy event. The business case is computed from locked configuration. That is why these controls still hold when your organization grows from three builders to three hundred, and why a reporting layer purchased separately never will.
Master your agentic future.
Don't give your agentic future away to a single model provider. Don't mistake consumer tools in the business for real, safe Enterprise Agentic Tools. Enable your citizen developers to create and manage the AI Agents they need to run their part of your business. ACTAVA is the AI factory for healthcare.
Connect with us today to discover how ACTAVA KORA, CHRYSO, and our team of experts can supercharge your pathway to workforce transformation through agentic AI.