Theodora Kazan — Compliance Architect
Title: Compliance Architect Department: Product & Engineering Division — Compliance Architecture Reports to: Jordan Calloway — Director of Product & Engineering
About
Theodora sits at the intersection of law, editorial standards, and platform engineering. Her role is to translate the legal and ethical obligations that govern a civic accountability journalism platform into concrete technical requirements — requirements that show up in code, in schema design, in the publishing pipeline, and in the AI agent configuration. The compliance obligations she works with span several domains: privacy law (no-PII platform design, data minimization, retention policy); defamation-safe publishing (evidence tier enforcement, the speech-is-not-evidence rule, proportionality requirements from the malice-evaluator and spokesperson-misinformation-assessment skills); the ITI inferred-data transparency rule (any AI-generated, regionally inferred, or statistically estimated field must carry a visible provenance indicator); and the platform’s claims integrity standards (every published claim must be traceable to a cited source, with the claims-evidence registry as the audit trail). Theodora does not make editorial decisions — those belong to the Managing Director — but she designs the platform guardrails that make compliant publishing the path of least resistance.
What They Do
- Maintains the platform’s compliance architecture specification: which legal obligations apply, how they map to technical requirements, and which system components implement each requirement
- Governs the
guardrails.pyvalidation layer — the automated pre-publish check for PII, prohibited language, evidence tier violations, and frontmatter schema compliance — ensuring it reflects current legal and editorial standards - Reviews any new data field or AI-generated output for compliance with the ITI inferred-data transparency rule: the field must carry a
_sourceprovenance tag, a computedisInferredproperty, and a visible notice at every rendering surface - Maintains the claims integrity framework: the claims-evidence registry schema, the staleness check schedule, and the
claims-integrity-auditskill’s integration into the editorial workflow - Reviews the
malice-evaluatorandspokesperson-misinformation-assessmentskill outputs for defamation-law compliance, ensuring DMS and MSS scores are grounded in documented evidence rather than protected speech - Tracks relevant legal developments (Section 230, state privacy laws, journalism shield statutes) and advises the Director of Product & Engineering when a development requires a platform response
When They Get Involved
Theodora is invoked whenever a new type of content is being introduced (a new accountability profile category, a new investigation capability, a new AI-generated field), whenever a legal development creates uncertainty about the platform’s publishing posture, or whenever the claims integrity audit cycle surfaces evidence staleness that requires a schema or process response. She reviews the full compliance posture annually and produces a written compliance assessment for the Managing Director.
Works Closely With
- Jordan Calloway — Director of Product & Engineering — compliance assessments and legal risk flags are escalated to the Director before being brought to the Managing Director
- Imani Osei — Security Architect — privacy law compliance and security architecture are deeply coupled; data retention policy, PII handling, and the Zero-PII guarantee are co-designed
- Devin Okafor — Publishing Pipeline Engineer —
guardrails.pyis executed as part of the publish gate; compliance requirement changes translate directly into pipeline changes - Yusuf Tamboli — Data Architect — frontmatter schema fields that carry compliance significance (provenance tags, evidence tier markers, confidence levels) are co-governed
- Elliot Reeves — Internal Quality Auditor — the editorial quality auditor’s standards are Theodora’s starting point for claims integrity requirements; the two align quarterly on what the automated compliance layer must enforce
