Methodology
SoftTech AI Registry records identifiable AI capabilities in business software using documented evidence. The aim is to describe what a capability does, what it can access, how it is controlled and how it changes over time — without turning those observations into scores, rankings or recommendations.
Unit of analysis
Each registry record represents one identifiable AI capability, not an entire vendor or product.
Evidence standard
Prefer vendor documentation, release notes, support documentation, developer documentation, trust/security documentation and other primary sources. Secondary sources may be used only where appropriate and should be clearly identified.
What we record
Function, data access, action capability, external actions, human confirmation, permission basis, administrative controls, default state, availability, licensing, model/provider information, limitations and uncertainty.
Recorded terms
Some characteristics use controlled terms so that capabilities can be recorded consistently across different vendors and products.
- Generative only
- The recorded capability generates or transforms information but is not recorded as independently executing operational actions.
- Read only
- The capability can retrieve or inspect information but is not recorded as modifying data or executing operational actions.
- Can take actions
- The capability can perform an action that changes data, configuration, workflow state or another operational outcome.
- External actions
- Indicates whether the capability can take actions outside its immediate product or service. Conditional means this depends on configuration, integrations or the particular action being used.
- Human confirmation
- Records whether an action requires explicit human confirmation before execution. Conditional means confirmation requirements vary by action or configuration.
- Permission basis
- Describes the identity or permissions under which the capability accesses information or performs actions. This may be the user's permissions, an administrative role, a dedicated agent identity, separate permissions, or a mixture of mechanisms.
- Mixed
- More than one permission or identity mechanism can apply depending on configuration or use.
- Not established
- The reviewed public evidence does not establish an answer. It must not be interpreted as “No”.
- Unknown
- The characteristic cannot currently be determined from the evidence available to the registry.
- Default state
- Records whether the capability is enabled, disabled or conditional by default where public evidence establishes this.
Uncertainty
Missing information must not be converted into a negative claim. If something cannot be established from public evidence, record it as unknown, not established or explain the uncertainty directly.
Verification
Published records should be tied to identifiable evidence and carry a last verified date.
Capability changes
When a verified capability changes, preserve the previous state, create a change event, record the new state and keep the history visible. Do not silently overwrite meaningful historical states.
What the registry does not do
No scores, risk ratings, vendor rankings, recommendations, sponsored conclusions or pay-to-play coverage.
The registry records evidence. Interpretation remains separate.