User Guide
This chapter is for end users of Regurai — risk officers, compliance staff, model owners, and auditors who use the application day to day.
Getting started
1. Sign in
Navigate to /auth, enter your work email and password, and complete sign-in. After successful sign-in you will be required to set up multi-factor authentication if you have not already done so (see Authentication & Authorization chapter).
2. Complete MFA enrolment
On first sign-in, you are sent to /mfa-setup:
- Open your authenticator app (Authy, 1Password, Google Authenticator, etc.).
- Scan the QR code shown on screen.
- Enter the 6-digit code your app displays.
- You will be redirected into the application.
On subsequent sign-ins, after entering your password you will be challenged for a 6-digit code from the same authenticator.
3. Land in the dashboard
The default landing route is /app. Use the left sidebar to move between work areas.
Sidebar map
| Section | Where to go | What it does |
|---|---|---|
| Dashboard | /app | At-a-glance KPIs across AI risk and operations |
| AI Models | /app/ai-models | Registry of AI systems in production |
| AI Assessments | /app/ai-assessments | Risk / impact assessments per model |
| AI Approvals | /app/ai-approvals | Approval workflow for promotion to production |
| AI Workforce | /app/ai-workforce | Inventory of AI agents and copilots |
| MRM | /app/mrm | Model Risk Management validation queue |
| Fairness | /app/fairness | Fairness and bias metrics per model |
| Risk | /app/risk | Enterprise risk view |
| Compliance | /app/compliance | Regulatory programme tracking |
| Controls | /app/controls | Control library |
| Evidence | /app/evidence | Evidence packs for audit |
| Audit | /app/audit | Audit programme view |
| Audit Log Viewer | /app/audit-log-viewer | Read-only access audit trail (owner / auditor only) |
| Resilience | /app/resilience | Operational resilience workspace |
| Exceptions | /app/exceptions / /app/exception-center | Policy exceptions and incidents |
| Financial Crime | /app/financial-crime | AML / fraud workspace |
| Digital Twin | /app/digital-twin | Simulation of operational scenarios |
| Simulation | /app/simulation | What-if simulator |
| Coverage | /app/coverage | Coverage of policies and controls |
| Reports | /app/reports | Saved and scheduled reports |
| Notifications | /app/notifications | Inbox of governance notifications |
| Integrations | /app/integrations | Third-party integrations |
| Access Governance | /app/access-governance / …-v2 | Role grants, reviews, audit |
| Profile | /app/profile | Your profile and session |
Common tasks
Register a new AI model
- Open AI Models → New Model.
- Fill in name, owner, business unit, intended use, and data classes.
- Submit for assessment — the system creates a draft AI Assessment.
- The model appears in the registry with status Draft → In Assessment → Approved.
Run an access review
- Open Access Governance v2.
- Filter grants by tenant, role, or expiry.
- For each grant, click Attest or Revoke.
- All actions are written to the audit log immediately.
Pull an evidence pack
- Open Evidence.
- Choose the regulatory framework (DORA, ISO 27001, …) and scope (model / period).
- Click Generate — Regurai packages relevant audit entries, approvals, and control results.
Download the project documentation
Open /docs → Download Project Manual (PDF). The PDF includes a cover page, ToC, bookmarks, and every chapter — selectable and searchable text.
What happens on idle
If you do nothing for 60 minutes, you are signed out automatically and returned to /auth. Unsaved form input is lost — submit work before stepping away.
What happens on too many failed sign-ins
Five failed sign-ins from the same IP within 15 minutes trigger a temporary lockout. The error message is intentionally generic. Wait 15 minutes or contact your administrator.