# All the capabilities, by workspace.

> All capabilities is a visual map of the ColossalX console: each module as one tile, grouped by its six workspaces (Command Center, AI Gateway, Agent Security, Risk and Testing, Compliance and GRC, Administration) and by verb. Each tile gives one line on what the module does today, with detail on hover or tap.

Each module of the ColossalX console, grouped by the six workspaces it lives in. Filter by what it does, then hover or tap a tile for the detail.

Canonical page: https://colossalx.tech/platform/all · Last reviewed: 7 Oct 2026

This page lists 92 capabilities in 6 workspaces. Each line is the module's name, the verb it serves (See, Control, Prove or Govern), what it does today and, where one exists, the link to its page.

## The threat and the control

- **The threat:** A long module list hides which ones answer your question, and which are still partly built.
- **The control:** Each module is described as it works today, grouped by workspace and by verb.

## Command Center (8 capabilities)

Your first screen: posture, open work and the assistant.

- **Dashboard (See).** How safe and governed your AI is today One screen shows the trust grade, the alerts that matter, the traffic the gateway handled and where compliance stands. A count that cannot be read shows a dash, never a zero.
- **Issues (Govern).** One queue of owned work, closed on evidence Findings from testing, scanning, intelligence, audit and compliance land in one issue with an owner and a due date. A risk acceptance has to expire, so work cannot quietly disappear. [How it works](https://colossalx.tech/platform/how-it-works)
- **Insights (See).** What needs acting on this week, in order Measured insights such as overdue fixes, untested agents and spend spikes, each with its evidence and the rule that fired. An AI brief ranks them and must cite them.
- **Trust Score (Govern).** A grade that explains why it moved Five pillars, graded A+ to F, with what pulls the score down and which evidence is missing. A grade resting on thin evidence is labelled provisional. [ColossalX Trust Engine](https://colossalx.tech/platform/trust-engine)
- **Monitoring (See).** Health of the platform itself, by component A live health check lists each service of the platform with its current status, so IT can confirm the workspace itself is running.
- **Assets & Topology (See).** Providers, agents and sensitive data, one map An interactive map of the AI supply chain: model providers, agents and the classified data around them, with live status on each node. Where a list cannot be read, it says so. [AI inventory and agent map](https://colossalx.tech/platform/ai-inventory)
- **Assistant (See).** Ask your security workspace in plain language Nine lookups and nine confirm-first actions run under your own permissions. When an answer is an action, it arrives as a card you approve, never something the model runs itself. [ColossalX Assistant](https://colossalx.tech/assistant)
- **My Policies (Govern).** Policies in force, accepted by each person Published policies show their version and owner. People accept each one by version, and a new version asks again, leaving the record an auditor will ask for.

## AI Gateway (16 capabilities)

Each model call governed, from keys to consent.

- **Overview (Control).** See AI traffic and what was stopped One screen shows request volume against blocked requests, policy matches, provider health and any active kill switch. A figure that cannot be read shows a dash, never a zero. [AI gateway](https://colossalx.tech/platform/ai-gateway)
- **Providers & Keys (Control).** Bring your own keys, hosted or self-hosted Connect 31 provider families, including self-hosted models. Your keys are sealed at rest and never shown again, and provider health is scored from the traffic that actually passed. [AI gateway](https://colossalx.tech/platform/ai-gateway)
- **Guardrails & Policies (Control).** Write a control, see if it runs Each policy row says whether the control is really in force and why not, if it is not. A count shows requests where a control could not run. [Runtime guardrails](https://colossalx.tech/platform/runtime-guardrails)
- **Model Access (Control).** Decide which models each team may reach Set which people and contexts may use which models, with per-request and daily allowances. Switch any model off in one place; retired models are never offered. [AI gateway](https://colossalx.tech/platform/ai-gateway)
- **Traffic Logs (See).** A record of who asked, and what happened Each request that reaches the gateway is stored with the person, the model that answered, tokens, cost and whether a control stopped it. Per-request decisions can be read back through the API. [AI gateway](https://colossalx.tech/platform/ai-gateway)
- **Playground (Prove).** Test a prompt or agent behind real guardrails Try a prompt, or build and test a whole agent, through the same controls production traffic meets. Then register it and send it for approval. [AI gateway](https://colossalx.tech/platform/ai-gateway)
- **Kill Switch (Control).** One switch halts AI, narrowly or broadly Halt AI for the whole workspace, one provider, one model or one person, with a written reason on record. Provider and model switches catch requests that name them. [Detection and response](https://colossalx.tech/platform/detection-response)
- **Shadow AI (See).** Find the AI nobody approved, decide once Discover AI tools from gateway traffic, 13 collector types and a browser sensor. One decision becomes a standing rule, and the product says where a block really takes effect. [Shadow AI](https://colossalx.tech/platform/shadow-ai)
- **Content Scanning (Control).** Scan prompts and answers for sensitive identifiers Add your own identifiers, such as a policy number format, and try them on sample text. Plant canary tripwires in prompts, documents or database rows: a leak opens a critical incident. [Data protection in AI traffic](https://colossalx.tech/platform/ai-data-protection)
- **Data Governance (Govern).** Classified data assets, retention and consent One inventory of data assets with their classification, retention and recent consent. Retention flags, archives or anonymises on schedule and never hard-deletes.
- **Consent (Control).** Withdraw consent, and the next request stops When a person withdraws consent for AI use, the gateway refuses their next request and logs it. It covers the inference-context purpose for signed-in users, and records a gap when the check cannot run. [Runtime consent](https://colossalx.tech/platform/runtime-consent)
- **AI Tool Registry (Control).** Allow, monitor or block each agent tool A control view of the MCP Firewall rules: allow, monitor or block each tool an agent can call. It is a rule list, not a discovered inventory of tools. [ColossalX MCP Firewall](https://colossalx.tech/platform/mcp-firewall)
- **MCP Servers (See).** See each MCP server your agents reach Learned from real requests, nothing added by hand: who reached each server and which tools it offered. Approve or block it with a reason; a blocked server is refused for all agents. [ColossalX MCP Firewall](https://colossalx.tech/platform/mcp-firewall)
- **AI App Catalog (See).** A starter risk catalogue of GenAI apps Score GenAI apps on data handling, compliance, security and terms, then record your own assessment. The starter scores are editorial judgements to re-assess, not measurements. [Data protection in AI traffic](https://colossalx.tech/platform/ai-data-protection)
- **Telemetry (See).** Requests, blocks, tokens and spend over time Charts of request volume with blocked traffic, top models and provider mix, plus tokens and cost, over a range you choose. Export the hourly series as CSV. [AI spend](https://colossalx.tech/platform/ai-spend)
- **Data Lineage (See).** Which agent sent which data to which model Drawn from real traffic: personal-data kinds sent to a model against those found and held back, and kinds returned in answers. Impact analysis shows what a change would touch. [Data lineage](https://colossalx.tech/platform/data-lineage)

## Agent Security (28 capabilities)

Find, identify, admit, test and contain agents.

- **AI Agent Map (See).** The agents you run, and what they touch A live map of agents, the models they call, the declared tools and data they touch and who they delegate to, with attacker paths to your data lit up. [AI inventory and agent map](https://colossalx.tech/platform/ai-inventory)
- **Agent Registry (See).** A governed catalogue: registered is not approved Agents enter four ways: registered by hand, found in code, discovered in traffic or attested from CI or the cloud. Approval needs an owner and a second approver. [AI inventory and agent map](https://colossalx.tech/platform/ai-inventory)
- **LLM Inventory (See).** Models and AI libraries your code imports The models your gateway offers, and the AI SDKs, agent frameworks and MCP libraries your code actually imports. The code-discovered list is the strong part today. [AI inventory and agent map](https://colossalx.tech/platform/ai-inventory)
- **SBOM & AI-BOM (See).** Software parts listed, AI parts set apart A bill of materials for each repository that separates ordinary libraries from the AI inside it, exportable as CycloneDX or SPDX, with approved baselines and drift alerts. [AI bill of materials](https://colossalx.tech/platform/ai-bill-of-materials)
- **Repo Security (Prove).** Secrets, dependencies and unsafe code, one scan One scan per repository across 8 source-control providers: secrets, vulnerable dependencies, insecure code and personal data. False positives teach the scanner; findings become tickets and build gates. [Code security](https://colossalx.tech/platform/code-security)
- **Code Scan (Prove).** Paste code, get findings and suggested fixes Paste code or point at a repository and get findings mapped to OWASP web and LLM categories, each with a suggested fix. A quick check; serious repository work goes to Repo Security. [Code security](https://colossalx.tech/platform/code-security)
- **Scan Governance (Govern).** Approve what code may be fetched for scanning Decide which code may be fetched, who approved it, and keep an audit trail of each request. Source is read in memory; findings are kept, not the source. [Code security](https://colossalx.tech/platform/code-security)
- **Live App Scan (Prove).** Test running apps, APIs and AI endpoints Safe checks on any public site; deeper active, API and LLM checks only on domains you have proven you own. A build gate blocks only on new problems. [Code security](https://colossalx.tech/platform/code-security)
- **AI Red-Team (Prove).** Attack your own chatbots, APIs and agents Paste a chatbot, API or session URL and get the exact attack, the exact reply, the verdict and the framework reference for each break. [Red-teaming and validation](https://colossalx.tech/platform/red-teaming)
- **Supply Chain & Runtime (Control).** Stop a poisoned model file before it loads Model files are inspected, never executed, and a poisoned artifact is stopped at the gate. Containment of machine-speed agents is opt-in, on limits you set. [Code security](https://colossalx.tech/platform/code-security)
- **Guardrail Profiles (Control).** Write safety rules once, roll out gradually Reusable profiles follow the agent. Try a change on real traffic without enforcing it, roll it out to a few agents, enforce, and roll it back at any step. [Runtime guardrails](https://colossalx.tech/platform/runtime-guardrails)
- **Threat Intelligence (Prove).** Threats matched to the AI you run Intelligence is matched to your SBOM, models, agents and vendors and reviewed by a person. Each threat ends in a recorded decision: owned work, a watch, a simulation or a no. [Threat intelligence](https://colossalx.tech/platform/threat-intelligence)
- **MCP Firewall (Control).** Default-deny rules in front of agent tools Per-agent rules, a scanner for poisoned tool descriptions, tool pinning and a tester you can run before anything goes live. Argument checks are built in. [ColossalX MCP Firewall](https://colossalx.tech/platform/mcp-firewall)
- **OWASP Assessments (Prove).** Each agent assessed against OWASP Agentic risks Each agent's configured controls are assessed against the OWASP Top 10 for Agentic Applications, showing which risks are covered and which are open. It is a configured-controls assessment, not an attack. [OWASP Agentic Top 10](https://colossalx.tech/frameworks/owasp-agentic-top-10)
- **Trust Zones (Control).** Per-agent limits, measured on each request Give each agent a zone with limits you set: call rate, session length, tokens, tools and model hosts. Each request is measured and each breach recorded; refusal is a rule you switch on. [Agent access, earned](https://colossalx.tech/platform/agent-access)
- **Prompt Injection Lab (Prove).** See whether a pasted prompt is an attack See if a prompt is an injection or a jailbreak, the technique it uses and how it maps to OWASP and MITRE ATLAS, then what your gateway actually stopped in the last day. [Prompt Injection Lab](https://colossalx.tech/platform/prompt-injection-lab)
- **Agent code inspection (Control).** Code a model hands an agent, read first Code a model hands an agent is read for what it does before the agent gets it. It is read, never run. [Detection and response](https://colossalx.tech/platform/detection-response)
- **Control Tower (Control).** Fleet posture, spend and the agent behind refusals A fleet control room: posture, violations, spend, kill-switch state and an agent leaderboard in one view, with the agent named behind each refusal. [Agent operations](https://colossalx.tech/platform/agent-operations)
- **Orchestrator (Control).** Chain agents into workflows a person can join Design workflows that ask agents, branch on their answers, wait for a human decision and contain or escalate. Each agent step runs through the gateway as that agent. [Agent operations](https://colossalx.tech/platform/agent-operations)
- **Agent Lifecycle (Govern).** An append-only history of each agent's state Where each agent stands, what changed this month and who changed it, from an append-only history of its lifecycle states. [Agent operations](https://colossalx.tech/platform/agent-operations)
- **Agent Governance (Govern).** Controls in force over agents, with a trail The controls in force over your agents, how the fleet behaved against them, and a trail of who changed what. Enforced means a rule on the request path reads it. [Agent operations](https://colossalx.tech/platform/agent-operations)
- **Session Recordings (Control).** Replay an agent's session request by request Record an agent, or your own privileged session, for a set time with full prompts and responses, then replay it with the decision each guardrail made on each request. [Agent operations](https://colossalx.tech/platform/agent-operations)
- **Agent Identity (Control).** Agents prove who they are, cryptographically Each agent gets a cryptographic identity, post-quantum hybrid on open standards, with signed requests that cannot be replayed, delegation that only narrows and a revocation list anyone can check. [Agent identity](https://colossalx.tech/platform/agent-identity)
- **Gate Enrolment (Control).** Choose which agents may pass your gate Enrol the agents allowed through the zero-trust gate, with expiry dates and one-click revocation. Roll it out in monitor mode first, then enforce when you are ready. [Agent access, earned](https://colossalx.tech/platform/agent-access)
- **Access Graph (Control).** Review each agent's granted access in one place One place to review the just-in-time access granted to each agent, and catch grants that ran past their approval or still belong to an agent you shut down. [Agent access, earned](https://colossalx.tech/platform/agent-access)
- **Access Requests (Control).** Just-in-time access instead of standing privilege One agent, one tool, until a date, approved by someone else and revocable at any time. Access that expires replaces standing privilege. [Agent access, earned](https://colossalx.tech/platform/agent-access)
- **Fingerprinting (See).** Recognise agents by what they do Recognise each agent by its behaviour, see when that behaviour moves, and find out which known agent an anonymous caller really is. A baseline needs the agent's traffic to pass the gateway. [AI inventory and agent map](https://colossalx.tech/platform/ai-inventory)
- **Intent Verification (Control).** Check an agent's purpose against its zone An agent's declared purpose is checked against what its trust zone allows before a sensitive operation, and each live tool call is checked against the same scope. [Agent identity](https://colossalx.tech/platform/agent-identity)

## Risk & Testing (16 capabilities)

Quantify risk, then attack your own defences.

- **Risk Overview (Govern).** AI risk posture, heat map and top risks A live heat map and your top risks, with a maturity read judged from how your register is actually run rather than from a questionnaire. [Risk quantification](https://colossalx.tech/platform/risk-quantification)
- **Risk Register (Govern).** A register that fills itself from findings Entries arrive from compliance gaps, audits, scans, proven attacks and intelligence, de-duplicated and auto-closed. Each risk has an owner and a review date, and is never silently re-scored. [Risk quantification](https://colossalx.tech/platform/risk-quantification)
- **FAIR Analysis (Govern).** Quantify AI risk in money, not colours Enter low, likely and high estimates and get an annual loss range with its tail. The numbers come from your estimates, never from the product. [Risk quantification](https://colossalx.tech/platform/risk-quantification)
- **Vendor Risk (Govern).** Which AI vendors nobody has assessed An inventory of AI vendors you actually depend on, discovered from your gateway and app catalogue, flagging those in use but not assessed. The register itself is a manual list. [Third-party AI risk](https://colossalx.tech/platform/third-party-ai-risk)
- **Risk Sync (Govern).** Send the register to tools you already run Outbound sync of the risk register to your GRC, ticketing and third-party risk tools, signed and replayable. It sends out only; nothing is written back. [Third-party AI risk](https://colossalx.tech/platform/third-party-ai-risk)
- **AEV Simulations (Prove).** Attack your agents in-path, through real controls Attacks run in-path through your real controls and are judged blocked, detected, missed or refused by the model. See which control was meant to stop each probe and what you can close. [Red-teaming and validation](https://colossalx.tech/platform/red-teaming)
- **Exposure (CTEM) (Prove).** Fix first what your tests proved reachable Exposures ranked by validated reachability and business impact, with drift alerts when a defence regresses. One status reads incomplete when a source could not be read. [Exposure management](https://colossalx.tech/platform/exposure-management)
- **Playbooks (Control).** Incident playbooks, rehearsed before they are needed Incident playbooks built as real workflows, rehearsed safely before they are needed, with an honest count of which steps can actually run. [Detection and response](https://colossalx.tech/platform/detection-response)
- **CyberTwins (Prove).** Attack a twin of your agents, not production A twin of your agents with its campaigns, findings and health on one page. Attacks and guardrail tests run against the twin rather than production. [ColossalX CyberTwins](https://colossalx.tech/platform/cybertwins)
- **Red Team Campaigns (Prove).** Campaigns against named agents, with a clear record Run a campaign against named agents through your real gateway. The record says what was attempted and what was not, with narratives for the board, CISO, engineers and regulator. [ColossalX CyberTwins](https://colossalx.tech/platform/cybertwins)
- **Attack Paths (Prove).** Findings chained into routes an attacker could walk Scan findings are chained into the routes an attacker could actually walk, with the evidence behind each step and a fix plan that you decide on. [ColossalX CyberTwins](https://colossalx.tech/platform/cybertwins)
- **Attack Library (Prove).** AI attack scenarios, each runnable on your agents A library of AI attack scenarios mapped to OWASP and MITRE ATLAS, each runnable against your own agents. A newly published technique can be turned into tests the same day. [ColossalX CyberTwins](https://colossalx.tech/platform/cybertwins)
- **Twin Environments (Prove).** Attack a copy, then test the fix Attack a copy of your agents, not production, then try the guardrail fix on the copy and promote it only if it holds. [ColossalX CyberTwins](https://colossalx.tech/platform/cybertwins)
- **Chaos Engineering (Prove).** Break a provider on purpose, watch failover Real faults are injected into AI traffic, with automatic rollback if the experiment hurts more than you planned. A failed experiment opens owned work with a due date. [Resilience](https://colossalx.tech/platform/resilience)
- **Disaster Recovery (Prove).** Backups proven to restore, every week Each week the newest backup is restored into a scratch database and timed, and the recovery time and data loss are recorded. A restore drill is a test, not a live failover. [Resilience](https://colossalx.tech/platform/resilience)
- **MITRE ATLAS coverage (Prove).** Which ATLAS techniques you have actually tested Measured from real runs: techniques exercised, exercisable and untestable are kept apart, so an untested technique is never counted as covered. [Red-teaming and validation](https://colossalx.tech/platform/red-teaming)

## Compliance & GRC (15 capabilities)

Frameworks, evidence, audits and policies for the regulator.

- **Frameworks (Govern).** Switch on the frameworks that apply to you Activate the frameworks that apply, such as the EU AI Act, NIST AI RMF and India DPDP, each mapped to or assessed against. Collect fresh evidence on demand. [Frameworks](https://colossalx.tech/frameworks)
- **AI Governance (Govern).** An AI control catalogue, measured from live signals Controls mapped to the EU AI Act, NIST AI RMF, ISO/IEC 42001 and NIS2 and assessed from live signals. Controls without a runtime signal are reported not assessable and left out of the score. [Compliance and AI governance](https://colossalx.tech/platform/compliance)
- **Controls (Govern).** Each control: a decided status, and proof Each control carries a status someone decided and a health label showing whether anything proves it is working now, with the reasons one click away. [Compliance and AI governance](https://colossalx.tech/platform/compliance)
- **Cloud Posture (Govern).** Posture counted from what discovery finds in AWS Counted from the resources discovery finds in your connected AWS account and the configuration audit run against them, with a daily history that starts when recording starts. [Compliance and AI governance](https://colossalx.tech/platform/compliance)
- **Evidence (Govern).** Evidence graded by where it came from Graded A to D by how it was obtained, verified by a second person, kept byte-exact, sealed daily with a trusted timestamp, and withdrawn with a reason, never deleted. [Compliance and AI governance](https://colossalx.tech/platform/compliance)
- **Reports (Govern).** Branded reports, signed off and scheduled Branded PDFs across 11 report types for the board and the auditor, with second-person sign-off, schedules and a flag when a report is out of date.
- **Regulatory Feed (Govern).** Watch regulator pages, with a person confirming Watch the regulator pages that matter to you. New circulars land as candidates for a person to read and confirm, never as unverified compliance content. [Regulatory intelligence](https://colossalx.tech/platform/regulatory-intelligence)
- **Jurisdictions (Govern).** Tell it where you operate; clocks follow Choose where you operate and what kind of entity you are, and the applicable regulators' reporting duties load as a rulebook with deadline clocks. It is starting content for your counsel to review. [Regulatory intelligence](https://colossalx.tech/platform/regulatory-intelligence)
- **Control Validation (Govern).** Test frameworks against live state, with reasons Each control gets a verdict and a stated reason against live platform state. A control with no runtime signal is shown as not assessable instead of being silently passed. [Compliance and AI governance](https://colossalx.tech/platform/compliance)
- **Cross-Mapping (Govern).** Control-to-control mappings, each with a rationale Control-to-control mappings between common frameworks, each with a stated confidence and rationale. A supporting view that shows where one control answers clauses in another framework. [Regulatory intelligence](https://colossalx.tech/platform/regulatory-intelligence)
- **Compliance Calendar (Govern).** Each deadline you carry, on one calendar Framework targets, audit plans, evidence expiry, regulatory reporting stages, finding due dates and risk-acceptance expiries, all built from the records you actually hold. [Regulatory intelligence](https://colossalx.tech/platform/regulatory-intelligence)
- **Audits (Govern).** Plan on risk, finish with a sealed archive Run each engagement through independence declarations, two-person review and management sign-off, ending in a sealed, timestamped archive anyone can verify. Preparer is never reviewer. [Audit](https://colossalx.tech/platform/audit)
- **Policies (Govern).** Write once, publish, collect acceptance by version Generate an AI policy or upload yours and align it. Policies are versioned with a hash of the text, accepted per version by named people, with an auditor proof pack. [Compliance and AI governance](https://colossalx.tech/platform/compliance)
- **Policy Exceptions (Govern).** Risk acceptances that always have an end date Each acceptance records who decided, why and until when, lapses back into open work on its end date, and goes to the board when it exceeds appetite.
- **Incidents (Control).** Runtime AI incidents, deduplicated and ticketed Runtime AI security incidents are deduplicated, ticketed and closed with a resolution note, and measured by trend and mean time to resolve. A runtime board, not a full case manager. [Detection and response](https://colossalx.tech/platform/detection-response)

## Administration (9 capabilities)

Identity, access, integrations and the product's own AI.

- **Security & Privacy (Control).** Set what employees may upload to the Assistant Set which files employees may upload to the Assistant, with a size cap and allowed file types, and choose to block sensitive content before it reaches a model.
- **Integrations (Govern).** Connect your SIEM, ticketing, cloud and identity tools For each connection, see what ColossalX reads, does and never does. Test it, rotate or revoke it from the row, and set up signed outbound and verified inbound webhooks. [For developers](https://colossalx.tech/developers)
- **Marketplace (Govern).** A catalogue of 120+ integration templates Search templates across SIEM, cloud security, identity, DevOps, ticketing and more, and connect from the card. Depth varies: three SIEMs send natively and the rest receive by signed webhook.
- **Identity Providers (Govern).** Single sign-on with the accounts people have Connect a SAML provider by pasting its metadata, with just-in-time provisioning and Microsoft Entra directory sync. People sign in with the accounts they already have.
- **Access Management (Govern).** Map directory groups to access levels once Map directory groups to access levels once, with custom roles down to the page, MFA required by role and an allowed email-domain list. Each screen tailors itself to the role.
- **API Keys (Govern).** Scoped keys that never outlive their maker Create a key with a lifetime and only the scopes the API checks. A key can never exceed its maker's permissions, the secret shows once, and a CI preset is ready. [For developers](https://colossalx.tech/developers)
- **AI Models (Govern).** Choose where ColossalX's own AI runs Run ColossalX's own AI features on a managed model, your own model and key, or a self-hosted endpoint, per feature, with a live test. Each internal AI call is recorded.
- **Browser Extension (See).** See AI tools on laptops, local models too A browser sensor, rolled out by browser policy, finds AI tools on laptops including local models that no network log can see. It is tested never to read a prompt. [Shadow AI](https://colossalx.tech/platform/shadow-ai)
- **Data Provenance (Govern).** Each record says where it came from Each record is labelled demonstration data or created by your own use, so evaluation numbers can be trusted. Counts are shown per table.

## What ColossalX does not do

- Tiles describe what a module does today; a partly built module is described by what works.
- Plumbing such as email delivery and help guides is left out.
- Frameworks are mapped to and assessed against; ColossalX holds no certification.

*Illustration:* This page · stated, not implied: Scope Console modules, one tile each; Described As they work today; Left out Plumbing and placeholders; Count Taken from the tiles. Stated, not implied.

## Questions

### What does All capabilities cover?

It lists each module in the ColossalX console, grouped by the six workspaces: Command Center, AI Gateway, Agent Security, Risk and Testing, Compliance and GRC, and Administration. Each tile gives one line and a short detail, written from what the module does today, not from what is planned.

### Which modules are left out, and why?

Plumbing such as email delivery and help guides is left out, and so is any page that is a placeholder today. Where a module is only partly built, its tile says what it does now. The count above the tiles is taken from the tiles themselves, so it cannot drift from the page.

### How do the verb and workspace filters work?

See, Control, Prove and Govern say what a module does: find AI, stop unsafe behaviour as it happens, show defences hold, or answer to the board and the regulator. Choose a verb, a workspace or both. A choice with no tiles is dimmed, and the count updates as you filter.

### Where can I read more about one capability?

A tile with a page of its own links to it. Hover, focus or tap a tile for its detail, which is also written into the page for readers and crawlers, and into the Markdown copy of this page. A walkthrough shows the product itself, with your own questions.

---

ColossalX is an AI security and governance platform from Quantexra Labs LLP, delivered as SaaS. Book a walkthrough: https://colossalx.tech/demo · client.success@quantexra.tech
