Safe AI diagnostics

The AI helps reason about evidence. It does not become the authority.

Northwatch separates the assistant that explains a problem from the systems that decide access, approve diagnostics, contact computers, and retain evidence.

Boundaries that remain outside the model

Customer and user access

The server determines which customer, machines, conversations, and evidence a user may access.

Machine identity

Each enrolled Windows agent has protected credentials. The AI cannot invent or impersonate an endpoint.

Diagnostic permissions

Only defined operations can be requested, and each request is checked before it reaches a computer.

Evidence and citations

Diagnostic explanations are designed to remain connected to the evidence and findings that support them.

Conversation separation

Customer conversations, retrieved material, tool results, and machine context must not cross customer boundaries.

Human authorization

The AI may help propose a future repair, but it cannot silently approve or release a change to a customer computer.

Technical foundation

Northwatch uses a signed Windows agent, encrypted connections, protected machine identity, server-controlled diagnostic tools, a durable operations queue, and auditable evidence storage. These controls let the assistant investigate without receiving broad infrastructure authority.