Federal AI LookupOps turns Splunk lookup edits into governed changes. It is built air-gap-first: no cloud dependencies, no external services, and no telemetry.
Analysts propose candidate changes by uploading a CSV, pasting records, or cloning the current lookup. A deterministic policy engine validates schemas, unique and composite keys, field types (IPv4, IPv6, CIDR, hostname, URL, email, date, boolean, number), enumerations, patterns, blank values, duplicates, and expirations. A key-aware semantic diff shows exactly what will change - additions, removals, field-level modifications, normalization-only changes, and schema changes - each with a stable evidence ID.
Approvers act under enforced separation of duties; self-approval is blocked server-side. Publication captures the production content hash at submission, re-verifies it immediately before the write, publishes only through documented Splunk interfaces, verifies the resulting hash after the write, and preserves the previous version for one-action verified rollback. Every step lands in a hash-chained audit trail with an exportable JSON evidence report. Deterministic offline bundles with SHA-256 manifests move changes safely between enclaves.
Optionally, connect a customer-approved, behind-the-firewall LLM (OpenAI-compatible, Ollama, or custom JSON). AI review runs server-side only with TLS verification always enforced, and provides risk assessment, justification-vs-diff contradiction detection, reviewer questions, policy proposals, normalization patches, dependency impact, and release narratives. Every material AI finding must cite deterministic evidence IDs, and the model has zero authority - it can never approve, publish, or roll back.
Works with your existing SAML login through Splunk's own authentication. Includes role-based capabilities (view, submit, approve, publish, rollback, AI use, AI admin), KV Store-backed state that replicates across search-head clusters, and full documentation.
Support: LC@federal.ai | www.federal.ai