What’s new in PulseAI 2.8
Four improvements, live today in Canada and the United States. Most of them build on the Policy Center: once your own AI policy is in force, this release is about what happens to the gaps it finds.
Owners and due dates on policy findings
A finding tells you what is unmet. It can now also say who is fixing it, and by when. Admins and managers can give an open policy finding a named owner and a remediation due date, and each finding keeps a history of who changed either one and when.
An open finding that passes its due date is marked overdue, and the findings list can be filtered to the findings assigned to you, the ones nobody owns yet, and the ones that are overdue. Assigning an owner never changes a finding’s status: a finding is resolved when your registry shows the gap is closed, not when someone takes it on.
Policy questions in attestation
Some policy rules cannot be decided from a registry. Whether a human reviews a system’s output before it is acted on, for example, is something a person has to attest to. Those rules are now asked where that attestation already happens: in your attestation cycles.
When an accountable owner reviews a system for attestation, the rules from your policy in force that apply to that system and cannot be checked automatically appear as questions, each with the rule and the passage of your policy it comes from. The attester answers each one as met, not met, or not applicable, with a note required for the last two, and the answers are recorded with the certification. A system cannot be certified with a question left unanswered.
Re-evaluation whenever your registry changes
Your policy rules have always been checked every day. They are now also checked when the things they are about change: when a use case or tool is added, edited, or removed, when an AI Impact Assessment changes, when a model link is updated or removed, and when the policy’s owner or review date changes. A change that arrives while an evaluation is already running is picked up in a follow-up run rather than dropped.
The daily run remains, for what only the calendar can change: a review date coming due, or an exception expiring.
See how each account signs in
User Management has a new Sign-in column that shows, for every account, how it can actually sign in: with a password, through single sign-on, with either, or not at all, with the identity provider named. Your own profile page shows the same for your account.
It reports what works rather than what is configured. An account linked to an identity provider that has been disabled, or that has no verified domain, is not shown as able to use single sign-on.
More from the Policy Center
On a system’s page, the statement that it meets your policy now appears only when an evaluation has completed since the system was added, at least one applicable rule could be checked, and nothing is open or accepted under an exception. Where some rules can only be attested, it says so. And when you choose a PDF larger than the 4.5 MB PulseAI can read, the upload dialog tells you before you upload it; the document is still stored and versioned.