Every system asks if an action is allowed. None asks if it should happen.

Methodology

We use the model to read. We do not use it to decide.

Enterprise policy is full of graded judgments — how critical is this vendor, is this evidence sufficient, how severe is this gap. Those need a degree, not a guess, and a regulator can ask you to reproduce it.

Fuzzy inference and deterministic rules compared with an LLM deciding on its own
Requirement Fuzzy inference + deterministic rules An LLM deciding on its own
Repeatability Identical inputs produce the same verdict, every run. Output can vary run to run on the same input.
Explainability The rule that fired, and the degree it fired to, can both be shown. A rationale is generated after the fact — not the computation behind it.
Graded concepts Built for “how critical”, “how sufficient” — degrees, not labels. Produces a label; the degree behind it is not defensible.
Calibration Membership functions are tuned by the risk owner, and versioned. You adjust a prompt and hope the effect holds.
Auditability The inference is inspectable and replayable years later. Cannot be reproduced for an examiner.
Failure mode Degrades to escalation — a person is asked. Returns a confident answer that may be wrong.
Reading policy and evidence Not what it is for. This is where the model is genuinely better — and where Tredy uses it.

Fuzzy systems, explainability, V&V and runtime assurance — advised by Kelly Cohen, PhD, Endowed Chair in Aerospace Engineering, University of Cincinnati. Mapped to ISO 42001, NIST AI RMF, DORA, the EU AI Act and ISO 42001.

An LLM alone cannot be asked to show its working three years later. An assurance decision has to be.

Start with one service.

A 30-minute scoping session with your risk owner and your IT contact. We leave with the first service named, the connections listed, and a date.