Notes from the team building HelixGate. Enterprise governance, architecture decisions, supplier risk, EU AI Act, audit readiness — written for practitioners, not search engines.
A short read on why an enterprise governance platform is a category in its own right — not a Jira plugin, not a SharePoint skin, not a GRC tool. The thesis behind the nine domains and one immutable trail.
Read the pieceWhat an ADR is, what a good one looks like, and the seven-phase lifecycle that turns it from a wiki page into governed evidence.
Article 27 FRIA, Article 53 GPAI, Article 72 monitoring, Article 73 incident clock. Mapped to actions, not lawyer jargon.
Five Case Model, three approval bands, benefits realisation. What changes when the workflow lives in a register, not in inboxes.
30/60/90-day alerts, auto-renewal traps, surviving obligations, supplier-spend roll-ups. The patterns that keep procurement honest.
Critical / High / Medium / Low. Why the tier matters, what each obligates, and how cascading attestations work in practice.
Why most ISMS implementations pass the audit on paper and fail on practice — and what closing that gap actually looks like.
The technical controls that map directly to CC6 and CC7, the evidence that comes for free if your system is built right, and the gaps you have to close manually.
Where they overlap, where they don’t, and why most GRC tools struggle to govern the upstream decisions that create risk.
Owner, tier, lifecycle, dependencies, commercial. The five fields without which a service catalogue is just a spreadsheet.
What a capability is, how it differs from a service, and why mapping them is the single most useful EA activity for an Investment Board.
A 30-day plan to introduce ADRs into an organisation that doesn’t have them — without breaking the architecture team’s morale.
The category we’re building in — defined plainly, with examples and counter-examples.
If your governance lives in spreadsheets and email, here’s exactly what changes — and exactly what you give up.
Where ServiceNow is the right answer, where HelixGate is, and why the trade-off comes down to time-to-value vs configurability.
EA tools focus on the map. HelixGate focuses on the decisions that change the map. Where each fits.
We write about what customers ask us. Email [email protected] with a question, and we’ll add it to the queue.