AI audit trail

Your donor asks where AI was used. You can answer.

Donors are writing their own AI-use policies, and they are not converging: some require disclosure of where AI touched a report, some restrict it in specific sections, some are silent and will not stay silent. An organisation reporting to four donors will soon face four different disclosure obligations on the same text.

The tempting response is a disclaimer. Ours is provenance: because every value in Hoverview carries its origin and its confirming human from the moment it is written, the platform can state, per report and per field, which figures originated from AI extraction, which were AI-generated, and which a named person entered or confirmed, and when. A general-purpose assistant cannot produce that, because it has no schema and no persistence.

Every value knows where it came from

A figure in Hoverview is extracted from a document, generated by AI, or entered by a person, and it is stored with that origin. Extracted values also keep their source document. This is not a report-time reconstruction; it is how the data is written.

Nothing enters unconfirmed

AI output lands in a review queue as a proposal. A named person accepts, edits or discards it, and the confirmation is recorded. A report is assembled from confirmed values, not typed fresh, so the chain from document to figure to report does not break.

AI checks, it does not judge

Hoverview's AI reads documents, proposes records, and checks completeness against a reporting window. It does not score report quality and it does not replace donor discretion. Keeping the generated share small and clearly labelled is a design goal, not a marketing line.

The audit log is append-only

Uploads, extractions, confirmations, edits and approvals are events in an immutable log that outlives the accounts it names. What happened is answerable years later, whoever has since left.

What this is, and what it is not

The provenance record states facts: what was AI-assisted, what was human-entered, what was confirmed and by whom. It never asserts that a report satisfies any particular donor's AI policy: that judgement stays with you and your donor, applied to facts you can finally see. A per-report provenance statement, exportable alongside the report itself, is where this data is headed; the underlying record it would print already exists for every value.

When a donor's AI policy is known, it becomes requirements data in that donor's profile, like their reporting templates and budget rules, never hard-coded behavior.

This page pairs with security and data protection: same audience, same argument. AI processing itself is bounded there, including the no-training commitment.