Control over AI
Documentation
Accountability

Accountability: what you can substantiate

The screen that shows, per GDPR and NIS2 control, what the figures carry and what they honestly do not.

Accountability lays the figures BeeSensible already collects next to the controls of a framework, and shows per control whether those figures carry it. The screen does not establish that you comply with the law. It shows what you can substantiate with measurements, and what you cannot.

Accountability in the dashboardUnder Accountability in the menu, once an admin has switched the screen on.

Switch it on first

Accountability is off by default. An admin switches it on under Organisation, in Organisation settings, with the Accountability dashboard toggle. Nothing extra is collected: the screen works with the data Realtime Privacy and AI Governance already produce.

See Organisation settings for that toggle and what else lives on that screen.

The two frameworks

You pick the framework at the top. There are two, each with its own boundary stated on the screen itself.

Frameworks

FrameworkWhat it covers here
GDPRControls about processing personal data towards AI tools. Subjects outside that channel, such as email, file sharing and physical transfer, are not in it.
Cybersecurity Act (NIS2)One segment of the duty of care: the AI-use channel and the view of your AI suppliers. Continuity, cryptography and multi-factor authentication are listed explicitly as not applicable.

That second line is deliberate. NIS2 has ten kinds of measures; BeeSensible touches a few of them. By putting the rest visibly on "Not applicable" instead of leaving them out, you see straight away how large the part is that this report does not cover.

The four statuses

Every control gets one of four statuses. The difference between them is the point of the screen.

Status per control

StatusWhat it means
SubstantiatedEvery condition met.
PartialThe measurement exists, not every threshold is met.
Not substantiatedNo measurement available.
Not applicableOutside this measurement.

Open a control and Calculation shows where the status comes from. The table itself has three columns: the control, what the evidence is, and the status.

The three layers

Controls are grouped by the source of their evidence.

  • Substantiated from visibility: based on all observed AI tools. The record of processing activities, for instance, in which every observed tool is logged with vendor, hosting region, training policy and your decision.
  • Substantiated from intervention: based on what happened while people were typing. Data minimisation, for instance: critical data handled before it was sent.
  • Outside what we measure: named, not omitted.

The coverage gates

Above the table sit three gates. They decide whether a measurement has enough body to carry anything; if a gate is not met, a control drops to Partial or to "no basis".

Coverage

GateWhat it looks at
VisibilityHow many observed tools have a decision of their own from the organisation.
Seat coverageHow many of your seats are active, against a configurable threshold.
Intervention volume coverageWhich share of measured AI use sits in a supported app.

Thresholds are configurable and sit at their default value. The screen says so itself, so a reader knows this is not an absolute norm.

The four headline figures

Above the frameworks sit four numbers for the chosen period: Critical detected (red markings), Critical handled (masked, replaced or removed, with the norm alongside), Critical sent anyway, and Standard detected as context without a norm.

Of those four, one asks for action, and the screen says as much: critical sent anyway. The rest is there to weigh that number against.

What it is not

Two controls make that clearest. For personal data breach notification and for notification to the NCSC, the screen says BeeSensible provides the signal, not a reporting process to the regulator. That stays your own process.

What stays private

The figures behind this screen are the same aggregated figures as everywhere else in the dashboard: counts per type, app, action and period. No message content, no per-employee view, and no user id in the behavioural data.