Application Overview

What this app is for

The Regulatory Investigation / Legal Response Manager gives a legal / compliance team one controlled workspace for responding to a regulator. It turns a compulsory notice into a tracked chain of requirements, links every piece of evidence to the requirement it answers, enforces privilege and confidentiality review before anything leaves the building, and produces an auditable submission with a production log and proof of receipt.

The whole point is defensibility: at any moment you can show what was asked, what was collected, who reviewed it for privilege, what was produced or withheld and why, and when it was submitted and received.

The operating chain

RECEIVE                 DECOMPOSE                COLLECT & REVIEW           RESPOND & SUBMIT
regulator + investigation -> requests ->        evidence + privilege  ->   drafts + decisions ->
+ parties                    requirements +      review                     submissions +
                             assignments                                    production items -> receipt
                                                                            |
                                                                            +-- communications + exceptions

Read left to right, that is the sidebar: Investigations → Requests & Requirements → Evidence & Review → Response & Submissions → Comms & Exceptions.

The five functional areas

1. Investigations — the matter and who is involved

Regulator (the authority), Investigation (the matter — status, risk, confidentiality, legal hold, response due) and InvestigationParty (the respondent, external counsel and other participants).

2. Requests & Requirements — what is being asked, broken down

RegulatoryRequest (a notice with statutory basis, due date and extension tracking), Requirement (each discrete thing to produce or answer, with a response type, owner, reviewer and approver), RequirementAssignment (who is doing it, in what role) and ExtensionRequest (time extensions and the regulator's response).

3. Evidence & Review — the material, and its privilege

EvidenceItem (custody, source, hash, confidentiality and privilege status, legal hold) and EvidenceReview (the legal/relevance review — responsive? privileged? redaction required?).

4. Response & Submissions — what is produced, and how it is approved

ResponseDraft (versioned drafts with legal-review/approval status and supersession), ReviewDecision (the recorded review/approval decisions), Submission (a package issued to the regulator, with receipt), and its contents: SubmissionRequirement (which requirements it covers) and ProductionItem (which evidence is produced, redacted or withheld, and on what basis).

5. Comms & Exceptions — the correspondence and the risks

Communication (every incoming/outgoing/internal contact) and IssueException (privilege, deadline and completeness issues raised on the matter).

Two ideas that make it trustworthy

  • Privilege is a first-class attribute. Evidence carries a privilege_status and a legal review that decides responsive/privileged/redaction, and production items record exactly what was redacted or withheld and why — so a waiver is never accidental.
  • Everything hangs off the investigation and its requirements, so any produced document is traceable back to the requirement, the request and the notice that compelled it.

Build status

Phase 1 (this build): the full schema (16 models), navigation, dashboards and a coherent seeded demo are complete and browsable as AI-Safe CRUD.

Phase 2 (documented, not built): the deadline/response engine — the proforma event blocks (request.received, requirement.overdue, submission.issued), the computed formulas (effective_due_at, days_remaining, is_overdue), the dashboard metrics and rules.yaml / workflows.yaml. Today those outcomes are modelled statically in the seed.