jtfai.co is in beta.Report bugs and change requests with release code beta-45bfe6d-202608080915.Send beta feedback
JTF PassportSign up / Log inContinue with Passport

JTF Copilot docs

Scoped AI for security workflows.

Build agents and artifacts that respect client scope, authorized methods, human approval, and audit requirements.

Docs index

The control surface is part of the product.

Reviewed work

Every request is checked against the customer, role, task, and approved use before the assistant receives context.

Refusal behavior

Requests for another client, unauthorized records, covert surveillance, spyware, interception, trackers, or false identities are refused and audited.

Reviewed outputs

Generated reports, proposals, and summaries are saved with the requester, reviewer, approval status, and source notes.

Partner API

The API accepts authorized AI requests, returns approval decisions, and uses the same review rules as the workspace.

Guardrail examples

R-AI-1 and R-AI-2 are hard refusals.

Allowed client workallowed

Draft an after-action summary for client-acme mission records.

R-AI-1 scope violationscope_violation

Summarize another client's incident log.

R-AI-2 out-of-bounds methodout_of_bounds_method

Build a covert surveillance tracker plan.

EndpointPOST /api/ai/requests

Requests include clientIds, allowedMethods, prompt, requester identity, and optional human approval state.

Decision codesai_request_allowed

Refused requests return scope_violation, out_of_bounds_method, or human_approval_required before artifact creation.

Auditrestricted record

Prompt content is reduced to a hash and the decision is persisted for review without exposing unrelated client context.

After-action report agentDrafts incident summaries, after-action reports, and client-ready closeout notes from approved mission information.Proposal drafting agentTurns approved capability language, service details, and procurement requirements into proposal drafts.SOP and regulation assistantHelps operators find approved procedures, policy references, and jurisdiction-specific compliance notes.

Request API access.