One engine for
every intake.
Turn forms, documents, and cases into governed, AI-assisted decisions — for any government agency or regulated industry, on one multi-tenant platform. Same engine, two surfaces, many domain packs.
Ghasi AI Intake OS is a domain-agnostic intake operating system: intake forms and a citizen portal at the front, document ingestion and AI triage in the middle, case management, workflow, and governed decisions at the core — all bound by audit-clean provenance. One engine serves a citizen or customer (B2C) and the officer or reviewer working their case (B2B), configured per domain through licensable domain packs. The same platform scales from a single agency to a whole-of-government backbone.
Every agency and regulated industry keeps rebuilding the same broken intake stack.
A licensing authority. A benefits office. A bank's onboarding desk. An insurer's claims intake. Different mandates — same failure mode: paper forms, PDFs emailed into shared inboxes, a case system per department that talks to nothing else, and backlogs measured in months. The cost stays invisible until an applicant waits a season for a decision, a document is re-keyed by hand for the third time, or no one can prove who decided what, and when.
Across public bureaucracies and regulated private industries, the typical intake operation runs on a stack that grew by accident:
- Paper forms and walk-in queues — often the only true source of a case's history.
- PDFs and scans emailed into a shared inbox, then manually re-typed into a database.
- A separate, bespoke case system per department or program — none of them integrated.
- Spreadsheets tracking status, SLAs, and backlogs that disagree with each other.
- AI bolted on with no provenance, no consent model, and no human-in-the-loop — or no AI at all.
What this stack costs an operator — public or private:
- Applicants repeat their information at every step; the same documents get re-collected and re-keyed.
- Cases sit in queues for weeks because triage is manual and routing is tribal knowledge.
- Backlogs are carried year to year because throughput never keeps up with intake volume.
- There is no clean audit trail — who saw the case, who decided, and on what evidence is unrecoverable.
- Every new domain, program, or regulation means rebuilding the same intake stack from scratch.
Ghasi AI Intake OS replaces that fragmented stack with one engine. Identity, tenancy, and access policy are shared. The intake form, the ingested document, the AI triage, the case file, the decision, and the audit log are views of the same governed record — configured per domain, isolated per tenant, and provable end to end.
One engine. Two surfaces. Many domain packs.
Ghasi AI Intake OS is designed, from day one, to be the intake backbone of any bureaucracy — at every scale. The same platform serves a single agency or business, a multi-department enterprise, and a national whole-of-government program. It has been specified, architected, and is ready for its first deployments.
Vision (normative): Enable any government agency or regulated industry to run safe, standards-based, AI-assisted intake — from the moment a citizen or customer submits, through document ingestion, triage, and case work, to a governed decision and an audit-clean record — on one multi-tenant engine, under local governance, configured per domain rather than rebuilt per domain.
Reference jurisdictions and active engagements
The platform was specified and architected against the operational realities of real bureaucracies, and is designed for both public agencies and regulated private industries. Each card describes the role a market plays in the platform's story today.
Afghanistan
Original reference jurisdiction. The platform was conceived for the intake realities of Afghan government bureaucracies — RTL languages (Pashto / Dari), sovereign on-prem deployment inside ministry networks, and workflows that must survive constrained infrastructure. The architectural reference for the platform's sovereign, national-scale posture.
Government & regulated industry
Two demand curves, one engine. Public bureaucracies — licensing, permits, benefits, registration, grievance — and regulated private industries — financial onboarding, insurance claims, KYC/AML, compliance intake — run the same platform, configured through different domain packs and tenanted separately.
Asia · MENA · Africa
Target deployment regions. Multi-language, multi-tenant, sovereign-hosting posture is built in — not retrofitted per country. Each domain pack lets a new agency or industry go live on a proven engine instead of a new build.
Submit → Decide → Audit — one lifecycle, one record
The platform follows every case from the moment it is submitted, through ingestion, AI triage, and the officer's decision, to fulfilment and a tamper-evident audit record — the same governed lifecycle whether the intake is a permit application or an insurance claim.
Sovereign & on-prem — runs inside the network you control.
Government intake carries citizens' most sensitive data, and regulated industries answer to hard data-residency rules. Ghasi AI Intake OS is built to run fully inside your own network — sovereign by default, air-gapped when required, with strict tenant isolation enforced all the way down to the database.
A ministry can run the entire platform inside its own air-gapped data centre, with no public-internet dependency and citizen data that never leaves the country. Updates ship on signed offline media; every tenant's records are isolated by Postgres row-level security. That is what sovereign deployment means here — not a marketing slide.
How sovereignty is enforced
On-prem & air-gapped
Deploy inside a ministry data centre or an enterprise private cloud. The air-gapped option ships container images, charts, and updates on signed offline media — no public-internet dependency, no vendor phone-home.
Data residency by design
Citizen and customer data stays where the regulator requires it. Object storage, database, cache, and message bus are all hosted within your sovereign boundary — never exported to a shared cloud you do not control.
Tenant isolation with RLS
Every tenant-scoped table carries a tenant_id and Postgres row-level security; the service role cannot bypass RLS. Each transaction binds its tenant context first, so one tenant can never read another's records — even through a repository bug.
Works behind government firewalls
No dependency on external identity providers or SaaS endpoints. The platform integrates with the identity, network, and security controls already inside the agency perimeter, and operates entirely within it.
What it does well
Isolated per tenant
Tenant identity is a first-class concept carried through every layer — auth context, application code, database, cache, object storage, message headers, logs, and audit events. Isolation is enforced, not assumed.
Sovereign by default
The default deployment is country-hosted and self-contained. Nothing about the platform assumes an outbound connection to a vendor, so a national program runs in the country it serves.
Portable & reproducible
Multi-stage, signed container images and infrastructure-as-code make the whole stack reproducible offline. The same artefacts run on a single server or a full high-availability cluster.
Auditable at the boundary
Every cross-boundary movement of data is explicit and logged. Cross-tenant data movement is forbidden by default; where a genuine transfer is needed it is modelled as an audited, consent-gated flow.
AI-First — intelligence in the workflow, governed by design.
AI is not a feature we bolted on. It is infrastructure — on the same level as identity, tenancy, and audit. Every service consumes AI through one governed gateway with provenance, consent, per-tenant budgets, and human-in-the-loop on every decision. Behind the gateway sits a provider-agnostic adapter over Anthropic, OpenAI, Gemini, Bedrock, Vertex, and Azure OpenAI.
AI assists. People decide. The audit trail proves it.
Document extraction & OCR
Scanned forms, PDFs, and handwritten submissions become structured, validated data — no re-keying. The evidence stays linked to the case so a reviewer can always check the source.
AI triage & classification
Incoming cases are classified, prioritised, and routed to the right queue at the moment of intake — turning a manual sorting backlog into a scored, explainable recommendation.
Eligibility & decision support
Rules and precedent are surfaced alongside the case: eligibility checks, missing-document flags, and recommended dispositions — presented to the officer, never substituted for them.
Case-history summarization
Long case files, prior submissions, and correspondence are summarized into a reviewable brief, so an officer picks up a case with the full story instead of thirty pages to re-read.
Multilingual applicant assistance
Applicants get help completing intake in their own language — including RTL scripts — with AI that explains requirements and validates entries before submission, cutting rejected forms.
Provider-agnostic & budgeted
Every model call goes through one LLM provider adapter with per-tenant budgets enforced at the gateway. Models can be swapped, replaced, or moved on-prem without touching feature code or blowing a budget.
One governed gateway, every AI call.
- Provenance on every output — model, version, prompt category, who accepted it, redaction applied, and the decision it fed — all recorded, all queryable against the case.
- Consent and access policy — who can use which model for which purpose is policy-driven, not implicit, and cross-checked on every call before a request ever reaches a provider.
- PII redaction and safety filtering — uniform across every feature. Pre- and post-moderation are gateway responsibilities, not something each team re-implements and gets wrong.
- Human decisions gate every outcome — AI never approves, denies, or finalises a case on its own. It classifies, extracts, and recommends; a named officer decides, and the audit trail proves it.
- No vendor lock-in at the call site — services see only the platform's AI port, never a vendor SDK. Providers can be swapped or moved on-device without a single change to business code.
One case. One safe story. Every actor, a first-class user.
Submission → document ingestion → validation → AI triage → case assignment → review and decision → fulfilment → audit. Every stage is owned by a service that shares the same identity, tenancy, and audit log — so handoffs are clean and the case file stays whole from the first form field to the final decision record.
The always-on intake baseline
Intake forms & portal
Configurable, multilingual intake forms and a citizen/customer portal. Validation and required-document rules run at submission, so fewer cases arrive incomplete.
Document ingestion
Upload, scan, and email-in channels feed a single ingestion pipeline: capture, OCR/extraction, classification, and virus-scanned storage with immutable object versions.
Case management
Every submission becomes a case with a status lifecycle, assignment, notes, correspondence, and a complete evidence trail — one record instead of scattered inboxes.
Workflow engine
Configurable stages, transitions, SLAs, and escalations. Cases route automatically by type and priority; timers and reminders keep work moving.
Decisions & approvals
Structured dispositions, multi-step approvals, delegation, and e-signature. Each decision records who decided, on what evidence, and against which policy version.
Audit log
Tamper-evident, append-only audit on every action — access, edit, AI call, and decision — queryable per case, per officer, and per tenant for any regulator.
Modular extensions — pay for what you use
On top of the intake core, agencies and businesses license only what they need. There is no duplicate case index across products; every module is a view of the same record under the same identity, tenancy, and access policy.
AI triage & extraction
The governed AI gateway: document extraction, classification, eligibility support, and case summarization — provider-agnostic, budgeted, and provenance-logged on every call.
Domain packs
Pre-built configurations for a domain — forms, workflows, decision rules, terminology, and compliance modes for licensing, benefits, KYC/AML, claims, and more. Configure a new domain instead of rebuilding one.
E-signatures
Standards-based electronic signatures on submissions, decisions, and approvals — with a verifiable signing record bound into the case audit trail.
Payments & fees
Application fees, levies, and charges captured at intake or decision, reconciled against the case, with pluggable payment gateways per jurisdiction.
Notifications
Status updates, requests for information, and decisions delivered by email, SMS, and portal — in the applicant's language, on the channel that actually reaches them.
Analytics & reporting
Throughput, backlog, SLA adherence, and automation-rate dashboards derived from live case data — per program, per tenant, and across agencies where governed to do so.
Every actor in the lifecycle is a first-class user — citizen and customer applicants, case officers and reviewers, agency administrators, compliance and audit officers, domain and program owners, integrators, and leadership. The platform is built around their work, not around an abstract "user".
Case-by-case truth becomes operational truth across the whole organization.
Automatically, governably, and on time. This is where Ghasi AI Intake OS changes the equation for any operator drowning in intake volume — turning a pile of forms into measured throughput, shrinking backlogs, and answers leadership can actually trust.
Operational intake metrics — measured, not estimated
The platform instruments the whole intake lifecycle, so operations stop guessing and start managing to real numbers.
Intake-to-decision time
Every case is timestamped at each stage, so cycle time — submission to decision — is measured per program and per queue, not estimated from a spreadsheet.
Backlog & aging
Live backlog and aging views show what is overdue, in which queue, and for how long — turning "how far behind are we?" into an answerable, per-team question.
Automation rate
Track what share of extraction, triage, and routing is AI-assisted versus manual, so the operational gain of the AI gateway is visible and attributable.
SLA adherence
SLAs and escalation timers are first-class; adherence is reported per program and per officer, with breaches surfaced before they become complaints.
Throughput & workload
Cases in, cases decided, and per-officer workload are measured continuously — so capacity is planned against reality, not last year's averages.
Audit completeness
Every case is checked for a complete, tamper-evident trail; gaps are flagged, so an audit is a query, not a six-week reconstruction project.
Cross-agency oversight, governed by policy
Aggregate oversight is derived from case truth — governed by consent, access policy, and tenant isolation:
- Program dashboards — throughput, backlog, and SLA adherence prepared automatically from live case data, per program and per tenant.
- Whole-of-government rollups — where policy permits, aggregate-only indicators roll up across agencies onto one oversight plane, without exposing another tenant's case records.
- Governed exports — any identifiable export is consent- and access-policy gated; aggregate-only by default, with every export recorded in the audit log.
The impact — in plain terms
Same engine. Three scales. No fork in the codebase.
From a single agency or business to a national whole-of-government backbone — Ghasi AI Intake OS runs on the deployment profile your operation needs. A single office, a multi-department enterprise, and a ministry serving many agencies are all expected to run the same software, just sized, tenanted, and licensed differently.
Three deployment profiles
Single agency or business
One tenant, one program or a handful. Suited to a single licensing authority, a benefits office, or a regulated business onboarding customers. The full engine, sized to one operation.
Multi-department enterprise
Many tenants on a shared engine, each department or program isolated by row-level security and configured with its own domain pack — one platform, one audit standard, many intakes.
National platform
Whole-of-government: many agencies, sovereign hosting, full high availability and observability. A national intake backbone with per-agency tenancy and per-domain licensing on one codebase.
Built for the realities of running intake at scale
Multi-tenancy with RLS
Every agency, department, or business is a tenant, isolated by Postgres row-level security and tenant context on every transaction and every message — so shared infrastructure never means shared data.
Domain-pack licensing
License the domain packs an operation actually runs — licensing, benefits, KYC/AML, claims. Same code, different configuration and license. A new domain is onboarded, not rebuilt.
Sovereign & air-gapped hosting
Country-hosted by default. The air-gapped option ships signed images and updates on offline media, with citizen data kept inside the regulator's boundary and no public-internet dependency.
Speaks the language your auditors and regulators already require.
Nothing here is invented. Everything here is documented, versioned, and traceable to a service that owns it.
APIs & integration
OpenAPI 3.1 for every REST surface, ConnectRPC for service-to-service, and Zod-validated contracts at every boundary — so integrators build against a stable, documented interface.
Identity & access
OAuth2 / OIDC (Keycloak-style) for authentication and app authorization; fine-grained, policy-driven access control; and tenant context bound from the authenticated session, never from a request input.
Privacy & security
GDPR-aligned data-subject rights; ISO 27001 control alignment; OWASP ASVS review-gated development; PII redaction at the AI gateway; secrets managed, never hardcoded.
Records & retention
Records-management and retention with Object Lock (WORM) on object storage; tamper-evident, append-only audit logging on every action for defensible retention and disposal.
Accessibility & e-signature
WCAG-aligned accessibility on citizen-facing surfaces, in LTR and RTL; standards-based electronic signatures with a verifiable signing record bound into the case.
Data isolation
PostgreSQL row-level security for tenant isolation; tenant_id on every scoped table and every message envelope; the transactional-outbox pattern for reliable, ordered, per-tenant eventing.
Standards-first means your auditors, your regulators, and your future partners can trust what they see — without taking our word for it.
Every actor in the system. Every outcome that matters.
The platform was built around the people doing the work — not around an abstract "user".
And why now.
The bespoke, per-department intake stack on the left is what most operators are stuck with. The Ghasi AI Intake OS answer on the right is what gets shipped on day one.
What it looks like in five years.
Two parallel pictures — a whole-of-government intake backbone and a regulated-industry enterprise. Both anchored in the same outcomes.
A national intake backbone, in five years
- Every agency runs its intake — licensing, permits, benefits, registration, grievance — on one sovereign engine instead of a dozen bespoke systems.
- Citizens submit once, in their own language, and every case carries a structured, longitudinal record from submission to decision.
- Document backlogs that took months to key by hand are ingested and triaged in hours, with AI extraction and a human deciding.
- Every decision is audit-clean: who decided, on what evidence, against which policy version — recoverable in a query, not a reconstruction.
- Ministries see live throughput, backlog, and SLA adherence across agencies, governed by consent and tenant isolation.
- A new program or regulation ships as a new domain pack on the same backbone — configured, not rebuilt.
A financial, insurance, or licensing enterprise, in five years
- Customer onboarding, KYC/AML, and claims intake run on one engine, each line of business isolated as its own tenant.
- Documents and applications are extracted into structured, validated data automatically, cutting manual re-keying and rejected submissions.
- AI triage and eligibility support move cases through review faster, while every decision stays with a named, accountable officer.
- Compliance and audit teams get tamper-evident provenance on every action and AI output — and clean export paths to the regulator.
- Operations manage to real metrics — cycle time, backlog, automation rate, SLA adherence — instead of quarterly guesswork.
- A new product or jurisdiction is a new domain pack and a new tenant — live on a proven engine, not a fresh build.
One engine. Every intake. Governed end to end.
Whether you are a government agency modernising a paper-bound intake process, a ministry building a national intake backbone, or a regulated business onboarding customers and processing claims — we should be talking.