Appearance
User Guide
Last updated: August 20, 2026
This guide walks a workspace owner or governance contributor through the standard Briard-AI workflow.
Before you begin
You do not need to understand AI governance before you begin. Briard explains each choice and lets you answer I'm not sure when an approved person needs to decide later.
It helps to know who can approve Microsoft 365 or Google Workspace access for your organization. You can also start with Browser Check, add one tool yourself, or take the fictional-data tour without an administrator.
As your work grows, prepare the following outside the platform:
- access to an approved Microsoft 365/Entra administrator for one-time discovery consent, when available;
- a list of AI systems and embedded AI features that cannot be observed through an approved connector;
- an accountable owner for each system;
- approved hosting and data-flow facts;
- the organization's boundary decision;
- applicable framework packs;
- non-regulated evidence files or HTTPS references; and
- reviewers authorized to approve governance statements.
Do not prepare or upload CUI, PHI, payment-card data, credentials, customer production records, raw prompts/outputs, source code, or secrets.
1. Create and secure your account
- Open Create your Briard-AI account.
- Enter the requested identity details and select Start free.
- Open the confirmation email and complete the confirmation flow.
- Sign in. Briard will ask you to add a six-digit code from a free phone app such as Microsoft Authenticator or Google Authenticator.
- Scan the square code with the phone app.
- Enter the six-digit code shown on your phone.
- Save recovery information according to your organization's password and recovery policy.
This second sign-in step protects workspace owners and administrators. Never share a session, password, recovery code, or phone-app setup key.
2. Start your 30-day free trial
Open your workspace after confirming your account. The trial starts when the workspace first opens.
- No payment method is required.
- The trial lasts 30 days and includes Professional features for up to ten AI systems.
- The trial does not renew or create an automatic charge.
- A verified owner chooses a paid plan only if the organization wants to continue afterward.
You can open Billing at any time to see the days remaining or voluntarily subscribe early. You do not need to visit Checkout before finding and governing your AI tools.
Automatic AI discovery
Open Automation setup from the application navigation. Choose the source your organization uses. Briard asks for the simplest available approval and fills in the organization identifier when the provider allows it.
- Choose Microsoft 365, Google Workspace, or Browser Check.
- Select Find my organization ID when Briard offers it. You do not need to search an administrator console first.
- If approval is required, sign in as an authorized administrator or select Send to my IT person. The approval page explains the read-only access before anything is connected.
- Briard verifies the connection and checks approved metadata. Browser Check reviews only the browser information and services you approve.
- Review one suggested tool at a time. Choose Yes, we use this, No, not ours, or I'm not sure.
- Open Dashboard. Approved connections can check again automatically, and an owner can request a fresh check when needed.
Briard reads only the organization or browser metadata explained on the connection screen. It does not collect email or chat message content, files, prompts, model outputs, or regulated payloads.
Likely AI services are added automatically as Discovered - unverified records. Briard deduplicates later observations and records source references, first/last-seen times, and confidence. An accountable person must still confirm or reject the system and supply any owner, purpose, data-class, or boundary decision that approved metadata cannot prove.
No connector can guarantee discovery of every AI use. Browser-only tools, unmanaged personal accounts, local models, API keys hidden from approved sources, and services outside the connected tenant require other approved connectors or manual reporting.
If your organization uses more than one network or environment, return to Connect work tools for each approved source. Give each place a plain name such as Main office, Secure project, or Test lab. Briard shows one place at a time and keeps that place's percentages, answers, proof, findings, tasks, and packages separate. Older records without a place show Name this place; naming one does not delete or rewrite its governance history.
See the Automation Setup Guide for permission purposes, consent behavior, collection boundaries, revocation, and troubleshooting.
3. Register an AI system manually
Open Register AI system and complete:
- System name: the recognizable product, feature, or internal system name.
- Vendor: third party or internal team responsible for the system.
- Model family: optional technical family or classifier name.
- Business owner: accountable person or role.
- Environment name: a plain name for where people use it, such as Main office, Secure project, or Test lab.
- Hosting: Public SaaS, Commercial API, Private cloud VPC, GovCloud, On premise, or Unknown.
- Boundary designation: Inside assessed boundary, Outside boundary, Prohibited from CUI, Unknown, or Not applicable.
- Data classes touched: choose only data the approved workflow is permitted to access. "None sensitive" cannot be combined with another class.
- Framework packs: Core is always included. Add CMMC, TRAIGA, or HIPAA only when applicable and entitled.
- Purpose statement: at least 200 characters covering business purpose, users, inputs, outputs, decision role, prohibited data, and required human review.
Example purpose pattern:
The system supports [approved business purpose] for [authorized users]. Inputs are limited to [approved non-regulated categories], and outputs are used for [advisory/draft/classification purpose]. It may not receive [prohibited data]. A human owner reviews [specified decisions or external outputs] before use.
Use this structure, but replace the brackets with accurate governance metadata. Do not paste sample customer data.
Select Create registry record. The new system opens in AI Systems.
4. Answer mapped questions
- Open AI Systems and select the system.
- Review each question's category, help text, and mapped control codes.
- Select the answer that reflects the approved current state, not the desired future state.
- Add metadata-only explanation where the question permits free text.
- Save the answer.
- Review any rule finding and remediation options.
Understanding coverage
- Not assessed: no current answer.
- Attested: an answer exists, but qualifying evidence is not linked.
- Partially evidenced: some support exists, but the mapped requirement is incomplete.
- Evidenced: the answer and linked support satisfy the deterministic evidence rule.
- Gap: the answer, support, or required condition does not meet the mapped rule.
These are workflow states, not audit findings or legal conclusions.
Complete the eight Texas investigation records
For a TRAIGA-enabled system, select Review the 8 records on the AI tool page.
- Briard opens the first unfinished record and shows progress as 0 of 8 through 8 of 8.
- Write one short, factual answer. Categories 1 and 3 start as drafts when the registered purpose and information classes already supply reliable facts.
- Optionally expand Add document or evidence references and enter one approved filename, evidence ID, or HTTPS link per line.
- Select Save draft when facts still need review, or Save and mark ready when the answer is complete enough for an accountable reviewer.
- Briard advances to the next unfinished record. Repeat until all eight are ready for review.
The eight records correspond separately to Texas Business and Commerce Code Section 552.103(b): purpose/use/deployment/benefits; programming or training data; input categories; output categories; performance metrics; known limitations; monitoring and safeguards; and other relevant documentation. Use categories and references only. Do not paste prompts, responses, customer records, credentials, or sensitive content.
5. Attach evidence
File evidence
- Save the mapped answer first.
- Open Evidence upload.
- Choose the system and saved answer the evidence supports.
- Select an approved file: PDF, CSV, XLS, XLSX, DOC, DOCX, PNG, JPG, or JPEG, no larger than 25 MB.
- Select Upload and scan.
- Wait for upload, SHA-256 verification, malware scanning, and sealing to finish.
- Confirm Scan passed before relying on the evidence.
If the result is pending, failed, or quarantined, the file is not approved for use in the workflow. Follow the Troubleshooting Guide.
HTTPS reference evidence
Where a question accepts a reference, use an approved HTTPS URL that points reviewers to the authoritative source. Do not use a URL that bypasses access controls or publicly exposes restricted material.
Evidence quality tips
A strong evidence reference identifies:
- the exact control or statement supported;
- the owner and review date;
- the applicable system and environment;
- the version or effective period; and
- how a reviewer can verify authenticity.
Avoid generic evidence attached to every question without a clear relationship.
6. Review governance readiness
For a TRAIGA-enabled system, open the NIST AI RMF + TRAIGA panel on the system page.
Keep the Texas legal tracks distinct during review:
- TRAIGA does not impose a general affirmative inventory duty.
- 1 TAC Section 219.21 requires each Texas state agency and local government to designate an AI Risk Officer and establish a process to identify and inventory heightened-scrutiny AI implementations.
- Chapter 219 took effect March 18, 2026, without the additional 90-day period requested during rulemaking.
- DIR did not issue an inventory or risk-assessment form, statewide repository, or shared platform. Briard-AI records are customer working records, not official DIR forms.
- Review the summary counts and the GOVERN, MAP, MEASURE, and MANAGE grouping.
- Open each mapping to see question status, controls, evidence, and source links.
- Resolve incorrect answers or missing evidence at the source question.
- Do not change an answer solely to improve the score; the record must reflect the approved current state.
The panel is designed to prepare a review record. It does not state that the organization substantially complies with NIST, qualifies for a TRAIGA protection, or has completed legal analysis.
7. Record an internal review
In the readiness panel, use Record internal review:
- enter the review date;
- describe the metadata-only scope;
- summarize findings;
- select remediation status;
- describe remediation and policy changes, if any;
- add an approved artifact or HTTPS evidence reference; and
- if a suspected violation was discovered, select the checkbox and provide the required discovery summary.
Records are append-only. If a conclusion changes later, add a new review rather than rewriting history.
8. Record internal testing or red-team activity
Use Record internal test:
- enter the test date;
- describe scope and method without sensitive payloads or exploit material;
- summarize findings and remediation;
- link approved evidence; and
- record whether a suspected violation was discovered.
Store detailed restricted test material in your approved security repository and place only the authorized reference and summary in Briard-AI.
9. Generate an artifact
Open Artifacts.
- Select the artifact type.
- Select the applicable system.
- Review the manifest preview, audience, template version, and ledger head.
- Select Generate artifact.
- Wait for the new record to appear under Recent exports.
- Download the available JSON or PDF. A TRAIGA Cure Binder also supports ZIP.
Before external sharing:
- verify the system and organization identifiers;
- review attested, evidenced, and gap items;
- confirm evidence references are authorized for the recipient;
- verify the ledger and manifest hashes when required;
- remove or correct inaccurate source records through the documented workflow; and
- obtain the appropriate security, compliance, management, and legal review.
10. Review a TRAIGA Cure Binder
The ZIP contains:
registry/system.json;assessment/readiness.json;evidence/evidence-index.json;reviews/internal-reviews.json;testing/testing-log.json;sources/framework-sources.json;texas/sec-552-103-investigative-documentation.json;customer/TEXAS_INVESTIGATIVE_DOCUMENTATION.csv;LEGAL_NOTICE.txt; andmanifest.json.
The manifest lists SHA-256 and size for all 14 package members other than the manifest itself. Verify these hashes before relying on a transferred package. The binder indexes evidence; it does not automatically place every private evidence binary inside the ZIP.
11. Verify the ledger
Open Ledger verify.
- Load the current organization events.
- Start verification.
- Confirm the result reports a clean chain, or preserve the first divergence report.
A clean result means the event sequence and recorded hashes are internally consistent. It does not prove that an attestation was correct or approved.
12. Use the dashboard and training center
- Use Dashboard to see what Briard completed automatically and the focused decisions that still require a person.
- Select Run check now only when an immediate refresh is useful; the scheduled review does not require a user to press it.
- Use Training for guided workflow lessons and reminders about metadata-only use.
- Use Settings to review membership, billing, notification, and security paths.
- Partner-entitled users can use Partner console for client-organization workflow entry points.
13. Manage billing and account security
Billing
During the free trial, Billing shows the remaining days and confirms that there is no automatic charge. A verified owner can choose Solo or Professional at any time. Entering Checkout is a separate choice and is not required to use the trial.
After an owner subscribes, owners and administrators can open the Customer Portal after completing MFA. Subscription changes are reflected after signed provider events update the workspace entitlement.
Account
Use Account to:
- verify your role and organization;
- enroll or verify MFA;
- reset your password;
- open Billing or Settings;
- submit support requests;
- request a workspace export; and
- submit a deletion request.
Workspace export requires Owner/Admin access. Deletion requests require owner verification and retention review; an append-only ledger or other legal obligation may require selected records to be retained.
14. Request support
Open Support and choose the category that best matches the issue. Provide metadata-only details, affected page, approximate time, and visible identifiers. Review Support history before resubmitting.
For urgent suspected security issues, email security@briard-ai.app. For normal product help, email support@briard-ai.app.
Golden-path completion checklist
- [ ] Account confirmed and MFA verified.
- [ ] Free trial or chosen paid plan active.
- [ ] Approved discovery source connected where available.
- [ ] Automatically discovered records confirmed or rejected by an accountable owner.
- [ ] Any system not visible to approved connectors registered manually with an accountable owner and approved purpose.
- [ ] Applicable mapped questions answered accurately.
- [ ] Evidence attached only to the answers it supports.
- [ ] Evidence scan status is clean before use.
- [ ] Readiness gaps reviewed and assigned.
- [ ] Internal review and testing records appended where applicable.
- [ ] Artifact generated from the correct system and ledger head.
- [ ] Export reviewed by authorized stakeholders before sharing.
- [ ] No CUI, PHI, credentials, or prohibited customer content entered into the platform.
