Skip to content
GM-OS

The operating system we run Grand Minds Technology on.

Controlled records, people, pipeline and approvals in one system, with the governance built into the data model rather than written down beside it. Available to run your company too.

70
data models
17
information zones
10
controlled document types
355
rules under test

It is not a demonstration. It is the system that holds our own contracts, employment records, board minutes and pipeline, and the figures above are read from it as this page renders.

What it does

Six modules, one register underneath.

Controlled records

A document register with a lifecycle, not a folder of files.

Every record carries an identifier, an owner, a custodian, a confidentiality level and a retention class. Approved versions are never overwritten — a revision becomes a new controlled version that supersedes the old one, and the chain back through it survives.

People and HR

Employment records, document packs, joiners, movers and leavers.

Each role carries a required document pack, tracked from missing to provided to verified — because somebody uploading a file is not somebody in HR having looked at it, and for a right-to-work check that difference is the whole control. Closing a leaver revokes sessions and suspends the account in the same transaction that records it.

Pipeline

Customers, opportunities and stage history.

Stage changes are events rather than a column, so a pipeline can be reconstructed as it stood on any date instead of only as it looks today.

Approvals and autonomy

A matrix saying what may happen automatically and what may not.

Anything not marked automatic lands in an approval queue with a named decider. External sends, signatures, payroll, bank details and permanent deletion are gated by default.

Organisation

Entities, branches, departments and reporting lines.

The hierarchy is data the access rules read, not a chart someone maintains separately. Who can see a record follows from where they sit.

AI agents

Agents that act inside the same rules as people.

Each agent has a declared scope and a set of things it may never do, whatever it is granted. An agent cannot be given a capability its identity is prohibited from holding — the prohibition wins over the grant.

Governance

The controls are the product.

Most systems record what happened. These rules decide what is allowed to happen, and they are enforced in the domain layer where they cannot be clicked past.

Document lifecycle

Records move through 8 states — DRAFT → IN_REVIEW → APPROVED → EXECUTED → SUPERSEDED → ARCHIVED → DELETION_PENDING → DELETED — and the edges are enforced, not advisory. Approval requires a named approver and a locked version. Marking something executed requires evidence. Superseding requires the identifier of the replacement.

Two-person disposal

Deleting a controlled record requires a retention date that has passed and two distinct authorisers. One person cannot dispose of a record alone, and a record under legal hold cannot be proposed for disposal at all — the hold outranks every other permission in the system, including the chief executive's.

Access by zone and clearance

Information sits in 17 zones, and each role holds a grant per zone. Confidentiality runs public, internal, confidential, restricted, privileged; restricted and privileged records additionally require a named access list. People do not see folders they have no grant in.

Second factor

Time-based one-time passwords to RFC 6238, required of anyone who can approve, anyone with a group-wide reach, and anyone holding an elevated capability. A session that has passed the password but not the second factor authenticates nothing except the right to finish signing in.

Content-addressed storage

Files are stored under their own SHA-256, so the checksum recorded against a record is literally the name of the object on disk rather than a field kept in step with it. Identical content is stored once, and reads verify the digest before serving.

Isolation

Each customer's data lives in its own database schema. The connection carries the boundary, so a query cannot return another customer's rows — correctness is a property of the connection rather than of every query remembering a filter. Enterprise customers can have a dedicated database instead; it is the same platform with a different connection string.

Controlled document types
CodeTypeDefault retention
POLPolicyperm
SOPStandard Operating Procedureactive+7y
CTRContractexpiry+10y
MINMeeting Minutes10y
DECDecision Recordperm
INVInvoicestatutory
HRFEmployee Recordemployment+statutory
PRJProject Recordclose+7y
TECTechnical Recordactive+5y
MKTMarketing Assetactive+3y

Information zones

  • System
  • Group governance
  • Legal entities
  • Strategy and portfolio
  • People and organization
  • Legal risk compliance
  • Commercial
  • Delivery and projects
  • Finance and procurement
  • Products and technology
  • Marketing and brand
  • Operations and admin
  • Inbox and quarantine
  • Templates
  • Records and archive
  • Examples
  • Reference blueprint
Plans

What each tier covers.

trial

Evaluate it with real records.

  • 5 people
  • 1 GB of records
  • Isolated schema

team

A single company, one entity.

  • 25 people
  • 50 GB of records
  • Isolated schema

business

Several entities and branches.

  • 200 people
  • 500 GB of records
  • Isolated schema

enterprise

Dedicated database, data residency, your own domain.

  • Unlimited people
  • Storage to suit
  • Dedicated database

Every tier gets the same controls. The difference is scale and where the data sits — the governance is not an upgrade.

Next

Ask for a walkthrough.

Tell us roughly how many people and what you need to keep control of. We will show you the running system rather than slides.