TRUST & RESPONSIBILITY

Responsible AI

Last reviewed: 2 September 2026 · Privacy policy

One record. A shared direction.

Amara’s learner recordProgramme · people · progress
DeliverySessions & resources
FundingILR preparation
QualityEvidence & actions
GatewayReadiness & approval

Journey’s model-backed AI is available to Journey Advanced providers subject to provider configuration and the required DPIA and release approvals. Confirm the enabled workflows, permissions and applicable controls during onboarding. The programme-bound drafting workflow fails closed unless the provider, tenant entitlement and its applicable production controls are configured.

Responsible AI means using artificial intelligence to assist people rather than replace their judgement. Journey has distinct governed AI workflows: programme-bound evidence and feedback drafting, proposed knowledge and skill links for review, four fixed Director Insight views, and Journey AI conversations that retrieve authorised record facts through controlled tools. Each workflow has its own purpose and access boundary. None makes high-stakes decisions on its own.

Governed AI workflow types

  • Preparing learner evidence drafts and tutor or assessor feedback for the authorised user to review and adapt.
  • Proposing knowledge and skill links from submitted evidence for staff to accept, reject or amend.
  • Supporting clear, evidence-based descriptions; the provider's existing human workflow remains the source of record.
  • Preparing a source-linked, read-only Director Insight view for one of four fixed questions: provider performance, funding exposure, operational status or selected learner-support facts.
  • Answering authorised operational questions through Journey AI: controlled tools retrieve permitted learner, delivery, funding, quality or gateway facts, and the conversation provides source references and the recorded context for human review.

Programme-bound drafting and the fixed Director Insight views are bounded workflows, not a general learner or staff chat service. In those workflows, the model has no web browsing, tools, direct database access, notification-sending or autonomous action capability. Journey AI is a separate conversational workflow: application-controlled read tools retrieve authorised record facts. This does not give the model unrestricted database access or permission to change source records.

Director Insight: fixed operational views

Director Insight provides four defined operational views. An authorised Director selects a view; Journey prepares a minimised snapshot from records that role may access, returns a source-linked observation and leaves the source data unchanged. Journey AI provides the separate conversational experience, using controlled tools to answer questions within the person’s authorised provider, role, site and learner scope. Confirm which workflows are enabled for your organisation.

The output supports leadership review; it is not a funding decision, inspection judgement, safeguarding decision or learner-status decision. A person checks the cited records and decides what happens next.

What Journey's AI never does

  • It does not compute or decide funding figures, which are calculated server-side against published, versioned funding-rule packs.
  • It does not decide gateway, EPA or compliance outcomes, which are confirmed by people and rules.
  • It does not automatically mark evidence, change KSB progress, change learner status, or verify behaviours. Behaviour evidence requires attributable workplace evidence and any required employer verification or sign-off.

Human in the loop

Programme-bound AI output is a draft or suggestion for a person. Director Insight and Journey AI provide information for review, not an automated decision. The assessor retains the authority to disagree with, amend or reject a draft while viewing the underlying evidence and can continue without AI. For a conversational answer, the responsible person checks the sources and recorded context before acting. Staff review AI-assisted content before it informs a decision, and controlled audit history records the actions people take.

Privacy by design

For the programme-bound evidence and feedback workflow, bounded learner-authored content may be processed for that authorised purpose. Journey applies pattern-based redaction to direct identifiers it detects and excludes credentials, payment data, raw signatures and document bytes. Redaction cannot guarantee that all personal data is removed, so the DPIA and authorised workflow boundary remain required controls. Tenant-scoped helpers verify that any referenced record belongs to the user’s organisation before a call is made.

Journey AI retrieves record facts through tools that apply provider, role, permission and learner access checks. Do not assume the drafting workflow’s redaction, provider settings or retention arrangements apply unchanged to the conversation. Confirm the processing and retention arrangements for each enabled workflow through your provider’s onboarding and data-protection review.

Governed and metered

Within the programme-bound drafting workflow, every AI call is metered and recorded in an AI usage ledger that stores compact metadata, not raw prompt content. A configured application-side spend reservation cap is checked before a request; Vercel AI Gateway’s API-key budget is a separate soft, defence-in-depth control. Unknown pricing or a control failure prevents the call rather than bypassing the cap.

Journey AI is included in Advanced within fair use, with usage reporting and warnings before thresholds. The drafting workflow’s specific ledger, reservation-cap and provider-budget implementation should not be assumed to describe the conversation. Confirm the enabled workflow’s usage controls and written terms during onboarding.

Provider data handling and challenge

For programme-bound drafting, Journey sends minimised content through Vercel AI Gateway to OpenAI with store: false. The documented arrangement for that workflow states that OpenAI API data is not used for training by default, while default abuse-monitoring retention may be up to 30 days unless OpenAI approves a different arrangement. Verify the current provider terms and the arrangement applicable to your enabled workflow; this is not a retention promise for Journey AI conversations. There is no absolute guarantee that a model cannot be manipulated, so the drafting workflow combines server-side scope checks, minimisation, closed output validation and human review. A learner or staff member can ask their provider data-protection lead to challenge a draft, suggestion or answer, correct the source record or restrict further AI use.

Validated and safe to fail

Programme-bound drafting responses are validated against an expected shape before use. If the model is unavailable or returns something unexpected, Journey reports that the assisted drafting action is unavailable and leaves the underlying record unchanged rather than guessing.

If Journey suspects a provider, minimisation or instruction-handling incident in the governed drafting workflow, it is designed to disable that runtime path, revoke its dedicated provider credential and preserve minimised audit evidence for security and data-protection review before any re-enable. Confirm the incident and recovery arrangements applicable to other enabled AI workflows during onboarding.

Contact

Questions about how we use AI? Email support@journeyapp.co.uk.

Questions providers ask

  • What is responsible AI in apprenticeship software?

    Responsible AI means using artificial intelligence to assist people rather than replace their judgement, with clear limits on data access, decisions and recorded use. Journey’s workflows include programme-bound drafting, fixed Director Insight views and Journey AI conversations with controlled record-reading tools. Supported funding, gateway, EPA and compliance controls remain separate from the model, with consequential decisions retained by the responsible people.

  • What learner data can Journey Advanced AI process?

    For programme-bound evidence or feedback drafting, only the persisted workflow content needed for the authorised request may be sent through the documented Vercel AI Gateway and OpenAI route. Pattern-based redaction cannot guarantee removal of every personal detail; credentials, payment data, raw signatures and document bytes are excluded. Journey AI instead obtains permitted record facts through controlled tools. The processing, retention and provider settings for each enabled workflow must be confirmed separately; the drafting controls are not a blanket promise for conversational data.

  • What can Director Insight tell a Director?

    Director Insight offers an authorised Journey Advanced Director four fixed, read-only views: provider performance, funding exposure, an operational snapshot or selected learner-support facts. It uses a minimised snapshot, links observations to their source and changes no record. Journey AI is the separate conversational workflow for authorised questions. A person reviews the underlying records before acting in either case.

  • Can AI make a funding or compliance decision on its own?

    No. AI output is a draft or a suggestion for a person. Funding figures, gateway and EPA readiness, and compliance outcomes are computed server-side against versioned rules and confirmed by staff — never decided by a model.

  • How is AI use kept within budget and monitored?

    In the programme-bound drafting workflow, each call is metered in a compact-metadata ledger rather than a raw-prompt log. An application-side spend reservation cap is checked before the request, with a separate soft Vercel AI Gateway budget; unknown pricing or an unavailable required control fails closed. Journey AI is included within Advanced fair use, with usage reporting and threshold warnings. Confirm the controls for each enabled workflow rather than assuming both use the same budget or retention implementation.

  • What happens if the AI model is unavailable?

    The programme-bound drafting action reports that it is unavailable and leaves learner, evidence and assessment records unchanged. Users can continue the normal human workflow without a draft. In Journey AI, a response derived from the same authorised tools without model narration is labelled as a deterministic response. Neither route grants the model permission to change the underlying record.

See what changes
when it all connects.

Bring your learners’ journey, your team’s questions and your next ambition.