Case study · Military & Defense

A defence integrator ran AI against controlled data with the boundary enforced, not promised

Clearance-scoped roles and a fail-closed boundary let controlled programme data reach a model at all — under conditions the programme office could verify.

Defence systems integrator · controlled programme environment · published September 30, 2026

0

controlled-data routes to unapproved endpoints

100%

of directives classified before routing

Approved

programme office sign-off for AI assistance

previously prohibited outright

48%

reduction in documentation drafting hours

Summary

A defence systems integrator needed AI assistance on documentation inside a controlled programme environment. Orcher enforced clearance-scoped access and a fail-closed data boundary per directive, with evidence for the programme office produced by execution itself.

Orcher components enforced

The situation

What was happening before Orcher.

  • Programme rules prohibited controlled data reaching any endpoint without a verified handling posture.
  • A blanket prohibition had been the default, which meant no AI assistance at all on the programme.
  • Any approved approach had to produce evidence the programme office could review without a special project.

What Orcher enforced

The control surface, component by component.

  • Directives are classified before routing, and the gateway fails closed when classification, clearance and endpoint posture do not agree.
  • Role bindings are clearance-scoped: an agent can never see data the directing engineer could not see.
  • Model selection is constrained to endpoints approved for the specific classification, with the decision recorded.
  • The ledger produces per-directive evidence that the programme office reads as its standing control report.

The data

Measured over the engagement window.

ClassificationApproved endpointsDirectivesRefused pre-routeEvidence produced
UnclassifiedAll approved14,2000Per directive
Controlled — general2 endpoints6,85031Per directive
Controlled — programme1 endpoint2,14088Per directive
RestrictedNone0412 attempts blockedPer attempt

Routing outcomes by classification over the engagement period.

Outcomes

What the organisation did next.

  • AI assistance exists on the programme at all, which was the binary outcome that mattered.
  • The programme office reviews a standing report rather than commissioning audits.
  • Blocked attempts became a training signal for engineers about what the classification rules actually mean.
  • The pattern is being reviewed for a second programme with tighter constraints.
The question was never whether the model was useful. It was whether we could prove, afterwards, exactly where the data went.
Programme Security Officer, defence systems integrator (partner declined attribution by name)

Read further

The research behind this engagement.

Disclosure. Design-partner engagement, anonymised at the partner's request. Figures are measured by Orcher's own observability and ledger instrumentation over the stated period and have not been independently audited. Market figures carry their own source line.

More engagements

Other organisations that had to prove the same thing.

Run this pattern on your own workflow

Design partners deploy Orcher on one directive class, instrument it the way this study was instrumented, and keep the evidence whatever they decide afterwards.