Completions

Measure swarm · Governance-Router Agent · Nested-autonomy-profile-inheritance skill · Build pillar · Published July 9, 2026

How to build nested-autonomy profile inheritance for AI-governance

This guide explains how to architect the nested-autonomy-profile-inheritance skill on the governance-router agent end-to-end at multi-brand multi-location AI-governance scale: per-portfolio per-corporate per-brand per-location per-franchisee per-role per-canonical-hierarchical-policy-inheritance-spec + per-policy-as-code-spec + per-per-brand-override + per-per-location-override + per-per-franchisee-override + per-per-role-RBAC-ABAC-PBAC-overlay + per-emergency-override-spec + per-cross-brand-acquisition-policy-merge + per-autonomy-tier-spec + per-policy-evaluation-engine + per-policy-version-control + per-policy-effective-date-staging + per-policy-audit-trail + per-portfolio audit-trail.

What you will build

  • Per-portfolio per-canonical-hierarchical-policy-inheritance-spec — per-corporate root policy (HIPAA + FINRA + FDA DTC + CCPA/GDPR/PIPEDA/CASL + FTC Endorsement Guides + cannabis per-state) → brand → location → franchisee → role → AI agent + per-default inherit + per-explicit override + per-locked policy + per-conflict resolution (deny wins + permit wins + explicit wins + deepest wins + LLM-augmented) + per-cycle detection.
  • Per-canonical-policy-as-code-spec — per-policy language (OPA Rego + AWS Cedar + Casbin CSL + Cerbos policy language + Oso Polar + Permit.io DSL) + per-test case + per-CI/CD pipeline + per-static analysis + per-policy bundle + per-decision log.
  • Per-canonical-per-brand-override + per-location-override + per-franchisee-override — per-brand explicit deny/permit + additional constraint + acquisition effective date + FDD Item 12 territorial attestation + per-location state-specific cannabis/alcohol/firearms + jurisdiction CCPA/CPRA/CASL/PIPEDA + per-franchisee FDD Item 12 territorial + data sharing consent + autonomy tier + explicit permit/deny.
  • Per-canonical-per-role-RBAC-ABAC-PBAC-ReBAC-overlay — per-RBAC role (VP Marketing + Brand Director + GM + District Manager + Franchise Business Consultant + Compliance Officer + CCO + General Counsel) + per-ABAC attribute (user + resource + environment + action) + per-PBAC policy + per-ReBAC relationship.
  • Per-canonical-emergency-override-spec — per-break-glass + per-CCO/General Counsel/CISO approval + per-rationale capture + per-time-bound 30-minute/1-hour/24-hour + per-auto-revoke + per-post-action audit + per-stakeholder notification + per-FCC/TCPA/HIPAA/FINRA/FDA attestation.
  • Per-canonical-cross-brand-acquisition-policy-merge + per-autonomy-tier-spec — per-acquired brand policy import + per-acquiring brand policy import + per-merge strategy (set union + set intersection + acquiring wins + acquired wins + stricter wins) + per-acquisition effective-date staging + per-grandfather clause + per-90-day transition + per-FDD Item 17 renewal/termination attestation + per-stakeholder approval + per-Tier-1 supervised (100% human-in-the-loop pre-publish) + per-Tier-2 monitored (sampled human review post-publish + anomaly detection pre-publish) + per-Tier-3 autonomous (AI self-governing + anomaly detection only) + per-AI-agent autonomy tier assignment + per-transition spec + per-rollback.
  • Per-canonical-policy-evaluation-engine + per-version-control + per-effective-date-staging + per-audit-trail — per-OPA + per-AWS Cedar + per-Casbin + per-Cerbos + per-Oso + per-evaluation latency + per-caching + per-fallback on failure + per-circuit breaker + per-Git-style repository + per-PR-style multi-stakeholder review (Compliance Officer + CISO + Operations Manager + Legal/General Counsel) + per-version snapshot + diff + rollback + per-effective-date + per-staged rollout + per-grandfather clause + per-sunset clause + per-90-day lead time + per-canonical audit record (decision-ID + actor user/AI agent + resource-ID + action + policy version + inheritance chain + override rationale + emergency bypass rationale + effective date + FCC/TCPA/HIPAA/FINRA/FDA attestation) + per-SOC2 Type II + per-HIPAA OCR + per-FINRA Rule 3110 + per-FDA Form 2253 + per-CCPA DSAR + per-GDPR DPIA exports + per-immutable WORM storage.

Why per-vendor-Okta-Groups-single-account breaks at multi-brand multi-location AI-governance scale

Per-vendor-Okta-canonical-Groups ships per-account per-group per-permission primitive. Per-vendor-Azure-AD + Auth0 + OPA + Casbin + Cerbos + Permit.io + Oso + AWS IAM + AWS Cedar + Google Cloud IAM + HashiCorp Vault + CyberArk + SailPoint + Saviynt-canonical-single-account ship per-vendor per-native RBAC/policy-engine primitives.

At 1-brand-1-tenant scale per-account per-group per-permission primitive is enough. At multi-brand multi-location AI-governance scale per-hierarchical-policy-inheritance-corporate-brand-location-franchisee-role + per-policy-as-code-Rego-OPA-Cedar-Casbin + per-per-brand-override-explicit-deny-permit + per-per-location-override-explicit-deny-permit + per-per-franchisee-override-explicit-deny-permit + per-per-role-RBAC-ABAC-PBAC-overlay + per-emergency-override-break-glass + per-cross-brand-acquisition-policy-merge-set-union-set-intersection + per-autonomy-tier-Tier-1-supervised-Tier-2-monitored-Tier-3-autonomous + per-policy-evaluation-engine-OPA-Cedar-Casbin + per-policy-version-control-Git-PR-style + per-policy-effective-date-staging-per-jurisdiction + per-policy-audit-trail-SOC2-HIPAA-FINRA-FDA-CCPA-GDPR-multi-format-export + per-FDD-Item-12.

Per-cross-vendor-RBAC-policy-engine-fragmentation + per-hierarchical-inheritance-blind + per-policy-as-code-blind + per-per-brand-override-blind + per-per-location-override-blind + per-per-franchisee-override-blind + per-RBAC-ABAC-PBAC-ReBAC-blind + per-emergency-override-blind + per-acquisition-merge-blind + per-autonomy-tier-blind + per-policy-evaluation-blind + per-version-control-blind + per-effective-date-staging-blind + per-multi-format-audit-trail-blind.

The operator-side architecture above per-vendor-RBAC-policy-engine primitive is canonical-hierarchical-policy-inheritance-spec + per-policy-as-code-spec + per-per-brand-override + per-per-location-override + per-per-franchisee-override + per-per-role-RBAC-ABAC-PBAC-overlay + per-emergency-override-spec + per-cross-brand-acquisition-policy-merge + per-autonomy-tier-spec + per-policy-evaluation-engine + per-policy-version-control + per-policy-effective-date-staging + per-policy-audit-trail + per-portfolio-audit-trail.

What is in market today

Per-platform per-IAM-vendor

Okta, Microsoft Azure AD (Entra ID), Auth0 (Okta), AWS IAM, Google Cloud IAM, HashiCorp Vault, CyberArk, SailPoint, Saviynt, ForgeRock (Ping Identity), Ping Identity, PingOne, OneLogin, JumpCloud. Per-account per-group per-permission. Per-canonical-hierarchical-policy-inheritance-canonical-policy-as-code-canonical-per-brand-location-franchisee-override-canonical-RBAC-ABAC-PBAC-ReBAC-overlay is not the primitive.

Per-platform per-policy-engine-vendor

Open Policy Agent (OPA), AWS Cedar, Casbin, Cerbos, Permit.io, Oso, Styra, Aserto, Topaz, Pomerium, Speakeasy, Inscape, AuthZed (SpiceDB). Per-instance per-policy-bundle primitive. Per-canonical-policy-language-canonical-Rego-Cedar-Casbin-Cerbos-Oso-Polar-Permit.io-DSL-canonical-test-case-canonical-CI-CD-canonical-static-analysis-canonical-bundle-canonical-decision-log is not the primitive.

Per-platform per-secrets-management-vendor

HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, Google Secret Manager, CyberArk Conjur, Akeyless, Doppler, Infisical, 1Password Secrets Automation. Per-account per-secret primitive. Per-canonical-per-emergency-override-canonical-break-glass-canonical-CCO-General-Counsel-CISO-approval-canonical-time-bound-30-min-1-hour-24-hour-canonical-auto-revoke-canonical-post-action-audit is not the primitive.

Per-platform per-policy-version-control-platform

GitHub, GitLab, Bitbucket, Azure Repos, Gitea, Codeberg. Per-developer-account per-code-repository primitive. Per-canonical-policy-Git-style-canonical-PR-style-multi-stakeholder-review-canonical-Compliance-Officer-CISO-Operations-Manager-Legal-General-Counsel-canonical-version-snapshot-canonical-version-diff-canonical-version-rollback is not the primitive.

How the architecture is built

  1. Per-portfolio per-canonical-corporate-root-policy-substrate. Per-HIPAA + per-FINRA + per-FDA-DTC + per-CCPA-GDPR-PIPEDA-CASL + per-FTC-Endorsement-Guides + per-cannabis-per-state canonical-corporate-policy.
  2. Per-portfolio per-canonical-hierarchical-policy-inheritance-spec. Per-corporate-to-brand + per-brand-to-location + per-location-to-franchisee + per-franchisee-to-role + per-role-to-AI-agent + per-default-inherit + per-explicit-override + per-locked-policy + per-conflict-resolution + per-cycle-detection canonical-inheritance.
  3. Per-portfolio per-canonical-policy-as-code-spec. Per-OPA-Rego + per-AWS-Cedar + per-Casbin-CSL + per-Cerbos + per-Oso-Polar + per-Permit.io-DSL + per-test-case + per-CI-CD + per-static-analysis + per-bundle + per-decision-log canonical-policy-as-code.
  4. Per-portfolio per-canonical-per-brand-per-location-per-franchisee-override. Per-explicit-deny + per-explicit-permit + per-additional-constraint + per-state-specific + per-jurisdiction + per-FDD-Item-12-attestation + per-data-sharing-consent + per-autonomy-tier canonical-override.
  5. Per-portfolio per-canonical-per-role-RBAC-ABAC-PBAC-ReBAC-overlay. Per-RBAC + per-ABAC + per-PBAC + per-ReBAC canonical-overlay.
  6. Per-portfolio per-canonical-emergency-override-spec. Per-break-glass + per-CCO-General-Counsel-CISO-approval + per-rationale-capture + per-time-bound + per-auto-revoke + per-post-action-audit + per-stakeholder-notification + per-FCC-TCPA-HIPAA-FINRA-FDA-attestation canonical-emergency.
  7. Per-portfolio per-canonical-cross-brand-acquisition-policy-merge. Per-acquired-policy-import + per-acquiring-policy-import + per-merge-strategy + per-effective-date-staging + per-grandfather + per-90-day-transition + per-FDD-Item-17-attestation + per-stakeholder-approval canonical-acquisition.
  8. Per-portfolio per-canonical-autonomy-tier-spec. Per-Tier-1-supervised + per-Tier-2-monitored + per-Tier-3-autonomous + per-AI-agent-assignment + per-transition + per-rollback canonical-autonomy-tier.
  9. Per-portfolio per-canonical-policy-evaluation-engine. Per-OPA + per-AWS-Cedar + per-Casbin + per-Cerbos + per-Oso + per-latency + per-caching + per-fallback + per-circuit-breaker canonical-evaluation.
  10. Per-portfolio per-canonical-policy-version-control. Per-Git-style + per-PR-style-multi-stakeholder-review + per-version-snapshot + per-version-diff + per-version-rollback canonical-version-control.
  11. Per-portfolio per-canonical-policy-effective-date-staging. Per-effective-date + per-staged-rollout + per-grandfather + per-sunset + per-90-day-lead-time canonical-staging.
  12. Per-portfolio per-canonical-policy-audit-trail. Per-decision-canonical-audit-record + per-SOC2-Type-II + per-HIPAA-OCR + per-FINRA-Rule-3110 + per-FDA-Form-2253 + per-CCPA-DSAR + per-GDPR-DPIA + per-immutable-WORM canonical-audit.
  13. Per-portfolio per-governance-router-agent-bundle. Per-rbac-software + per-borderline-routing + per-multi-stakeholder-approval-routing + per-multi-dimensional-threshold-routing + per-ai-agent-guardrails + per-ai-agent-governance + per-ai-routing-decision-audit-trail + per-tiered-content-filtering canonical-bundle.

Frequently asked questions

What is nested-autonomy profile inheritance for AI-governance at multi-brand multi-location scale?

Nested-autonomy profile inheritance runs per-portfolio per-corporate per-brand per-location per-franchisee per-role per-canonical-hierarchical-policy-inheritance-spec + per-canonical-policy-as-code-spec + per-canonical-per-brand-override + per-canonical-per-location-override + per-canonical-per-franchisee-override + per-canonical-per-role-RBAC-ABAC-PBAC-overlay + per-canonical-emergency-override-spec + per-canonical-cross-brand-acquisition-policy-merge + per-canonical-autonomy-tier-spec + per-canonical-policy-evaluation-engine + per-canonical-policy-version-control + per-canonical-policy-effective-date-staging + per-canonical-policy-audit-trail + per-portfolio audit-trail. Per-canonical-hierarchical-policy-inheritance-spec runs per-portfolio per-canonical-corporate-root-policy-spec + per-canonical-corporate-to-brand-inheritance + per-canonical-brand-to-location-inheritance + per-canonical-location-to-franchisee-inheritance + per-canonical-franchisee-to-role-inheritance + per-canonical-role-to-AI-agent-inheritance + per-canonical-policy-inheritance-conflict-resolution. The per-platform RBAC/policy-engine vendor category includes Okta, Microsoft Azure AD (Entra ID), Auth0 (Okta), Open Policy Agent (OPA), Casbin, Cerbos, Permit.io, Oso, AWS IAM, AWS Cedar, Google Cloud IAM, HashiCorp Vault, CyberArk, SailPoint, Saviynt, Styra, Aserto, Topaz, Pomerium.

Why does per-vendor-Okta-canonical-Groups-canonical-single-account break down at multi-brand multi-location AI-governance scale?

Per-vendor-Okta-canonical-Groups ships per-account per-group per-permission primitive. Per-vendor-Azure-AD + per-Auth0 + per-OPA + per-Casbin + per-Cerbos + per-Permit.io + per-Oso + per-AWS-IAM + per-AWS-Cedar + per-Google-Cloud-IAM + per-HashiCorp-Vault + per-CyberArk + per-SailPoint + per-Saviynt-canonical-single-account ship per-vendor per-native RBAC/policy-engine primitives. At 1-brand-1-tenant scale per-account per-group per-permission primitive is enough. At multi-brand multi-location AI-governance scale per-canonical-hierarchical-policy-inheritance-spec-canonical-corporate-brand-location-franchisee-role + per-canonical-policy-as-code-spec-canonical-Rego-OPA-Cedar-Casbin + per-canonical-per-brand-override-canonical-explicit-deny-permit + per-canonical-per-location-override-canonical-explicit-deny-permit + per-canonical-per-franchisee-override-canonical-explicit-deny-permit + per-canonical-per-role-RBAC-ABAC-PBAC-overlay + per-canonical-emergency-override-spec-canonical-break-glass + per-canonical-cross-brand-acquisition-policy-merge-canonical-set-union-set-intersection + per-canonical-autonomy-tier-spec-canonical-Tier-1-supervised-Tier-2-monitored-Tier-3-autonomous + per-canonical-policy-evaluation-engine-canonical-OPA-Cedar-Casbin + per-canonical-policy-version-control-canonical-Git-style-PR-style + per-canonical-policy-effective-date-staging-canonical-per-jurisdiction + per-canonical-policy-audit-trail-canonical-SOC2-HIPAA-FINRA-FDA-CCPA-GDPR-multi-format-export + per-canonical-FDD-Item-12-territorial-rights.

How does per-portfolio per-canonical-hierarchical-policy-inheritance + per-policy-as-code-spec work?

Per-portfolio per-canonical-hierarchical-policy-inheritance-spec runs per-portfolio per-canonical-corporate-root-policy (per-HIPAA-gate + per-FINRA-gate + per-FDA-DTC-gate + per-CCPA-GDPR-PIPEDA-CASL-gate + per-FTC-Endorsement-Guides-gate + per-cannabis-per-state-gate per-canonical-corporate-policy) + per-canonical-corporate-to-brand-inheritance-spec (per-default-inherit + per-explicit-override + per-locked-policy per-canonical-inheritance-spec) + per-canonical-brand-to-location-inheritance + per-canonical-location-to-franchisee-inheritance + per-canonical-franchisee-to-role-inheritance + per-canonical-role-to-AI-agent-inheritance + per-canonical-policy-inheritance-conflict-resolution (per-deny-wins + per-permit-wins + per-explicit-wins + per-deepest-wins + per-LLM-augmented-resolution per-canonical-conflict-rule) + per-canonical-policy-inheritance-cycle-detection. Per-canonical-policy-as-code-spec runs per-portfolio per-canonical-policy-language (per-Open-Policy-Agent-Rego + per-AWS-Cedar + per-Casbin-CSL + per-Cerbos-policy-language + per-Oso-Polar + per-Permit.io-DSL per-canonical-policy-language) + per-canonical-policy-test-case-spec + per-canonical-policy-CI-CD-pipeline + per-canonical-policy-static-analysis + per-canonical-policy-bundle-spec + per-canonical-policy-decision-log-spec.

What does per-portfolio per-canonical-per-brand-override + per-location-override + per-franchisee-override + per-role-RBAC-ABAC-PBAC-overlay do?

Per-portfolio per-canonical-per-brand-override runs per-portfolio per-canonical-per-brand-explicit-deny + per-canonical-per-brand-explicit-permit + per-canonical-per-brand-additional-constraint + per-canonical-per-brand-acquisition-effective-date + per-canonical-per-brand-FDD-Item-12-territorial-attestation. Per-canonical-per-location-override runs per-portfolio per-canonical-per-location-state-specific-cannabis-override + per-canonical-per-location-state-specific-alcohol-override + per-canonical-per-location-state-specific-firearms-override + per-canonical-per-location-jurisdiction-CCPA-CPRA-override + per-canonical-per-location-CASL-PIPEDA-override. Per-canonical-per-franchisee-override runs per-portfolio per-canonical-per-franchisee-FDD-Item-12-territorial-spec + per-canonical-per-franchisee-data-sharing-consent + per-canonical-per-franchisee-autonomy-tier-spec + per-canonical-per-franchisee-explicit-permit-deny. Per-canonical-per-role-RBAC-ABAC-PBAC-overlay runs per-portfolio per-canonical-RBAC-role-based-spec (per-VP-Marketing + per-Brand-Director + per-General-Manager + per-District-Manager + per-Franchise-Business-Consultant + per-Compliance-Officer + per-CCO + per-General-Counsel per-canonical-role) + per-canonical-ABAC-attribute-based-spec (per-user-attribute + per-resource-attribute + per-environment-attribute + per-action-attribute per-canonical-attribute) + per-canonical-PBAC-policy-based-spec + per-canonical-relationship-based-access-control-ReBAC-spec.

What does per-portfolio per-canonical-emergency-override + per-cross-brand-acquisition-policy-merge + per-autonomy-tier-spec do?

Per-portfolio per-canonical-emergency-override-spec runs per-portfolio per-canonical-break-glass-emergency-spec + per-canonical-emergency-override-CCO-General-Counsel-CISO-approval + per-canonical-emergency-override-rationale-capture + per-canonical-emergency-override-time-bound-30-minute-1-hour-24-hour + per-canonical-emergency-override-auto-revoke + per-canonical-emergency-override-post-action-audit + per-canonical-emergency-override-stakeholder-notification + per-canonical-emergency-override-FCC-TCPA-HIPAA-FINRA-FDA-attestation. Per-canonical-cross-brand-acquisition-policy-merge runs per-portfolio per-canonical-acquired-brand-policy-import + per-canonical-acquiring-brand-policy-import + per-canonical-policy-merge-strategy-spec (per-set-union + per-set-intersection + per-acquiring-wins + per-acquired-wins + per-stricter-wins per-canonical-merge-strategy) + per-canonical-acquisition-effective-date-staging + per-canonical-acquisition-grandfather-clause + per-canonical-acquisition-90-day-transition-spec + per-canonical-acquisition-FDD-Item-17-renewal-termination-attestation + per-canonical-acquisition-stakeholder-approval. Per-canonical-autonomy-tier-spec runs per-portfolio per-canonical-Tier-1-supervised-spec (per-100-percent-human-in-the-loop-pre-publish per-canonical-supervised) + per-canonical-Tier-2-monitored-spec (per-sampled-human-review-post-publish + per-anomaly-detection-pre-publish per-canonical-monitored) + per-canonical-Tier-3-autonomous-spec (per-AI-self-governing + per-anomaly-detection-only per-canonical-autonomous) + per-canonical-per-AI-agent-autonomy-tier-assignment + per-canonical-per-AI-agent-autonomy-tier-transition-spec + per-canonical-per-AI-agent-autonomy-tier-rollback.

What does per-portfolio per-canonical-policy-evaluation-engine + per-version-control + per-effective-date-staging + per-audit-trail + per-governance-router-agent-canonical-bundle do?

Per-portfolio per-canonical-policy-evaluation-engine runs per-portfolio per-canonical-OPA-Open-Policy-Agent-evaluation + per-canonical-AWS-Cedar-evaluation + per-canonical-Casbin-evaluation + per-canonical-Cerbos-evaluation + per-canonical-Oso-evaluation + per-canonical-policy-evaluation-latency-spec + per-canonical-policy-evaluation-caching + per-canonical-policy-evaluation-fallback-on-failure + per-canonical-policy-evaluation-circuit-breaker. Per-canonical-policy-version-control runs per-portfolio per-canonical-policy-Git-style-repository + per-canonical-policy-PR-style-multi-stakeholder-review (per-Compliance-Officer + per-CISO + per-Operations-Manager + per-Legal-General-Counsel per-canonical-stakeholder) + per-canonical-policy-version-snapshot + per-canonical-policy-version-diff + per-canonical-policy-version-rollback. Per-canonical-policy-effective-date-staging runs per-portfolio per-canonical-policy-effective-date + per-canonical-policy-staged-rollout + per-canonical-policy-grandfather-clause + per-canonical-policy-sunset-clause + per-canonical-policy-90-day-lead-time-for-major-shifts. Per-canonical-policy-audit-trail runs per-portfolio per-canonical-per-policy-decision-canonical-audit-record (per-decision-ID + per-actor-user-AI-agent + per-resource-ID + per-action + per-policy-version + per-inheritance-chain + per-override-rationale + per-emergency-bypass-rationale + per-effective-date + per-FCC-TCPA-HIPAA-FINRA-FDA-attestation per-canonical-audit-record) + per-canonical-audit-trail-SOC2-Type-II-export + per-canonical-audit-trail-HIPAA-OCR-investigation-format-export + per-canonical-audit-trail-FINRA-Rule-3110-supervisory-review-export + per-canonical-audit-trail-FDA-Form-2253-promotional-material-export + per-canonical-audit-trail-CCPA-DSAR-export + per-canonical-audit-trail-GDPR-DPIA-export + per-canonical-audit-trail-immutable-WORM-storage. Per-governance-router-agent-canonical-bundle integrates the nested-autonomy-profile-inheritance skill with sibling skills on the same agent: per-canonical-rbac-software (sibling, parent commercial pillar at /rbac-software) + per-canonical-borderline-routing (sibling, build-pillar shipped at /how-to-build-borderline-routing-for-ai-outputs) + per-canonical-multi-stakeholder-approval-routing (sibling, complementary multi-stakeholder routing) + per-canonical-multi-dimensional-threshold-routing (sibling, complementary threshold routing) + per-canonical-ai-agent-guardrails (sibling, complementary AI agent guardrails) + per-canonical-ai-agent-governance (sibling, complementary AI agent governance) + per-canonical-ai-routing-decision-audit-trail (sibling, complementary AI routing audit trail) + per-canonical-tiered-content-filtering (sibling, complementary tiered content filtering).

Engage the governance-router agent

Per-portfolio per-corporate per-brand per-location per-franchisee per-role per-canonical-hierarchical-policy-inheritance-spec + per-policy-as-code-spec + per-per-brand-override + per-per-location-override + per-per-franchisee-override + per-per-role-RBAC-ABAC-PBAC-overlay + per-emergency-override-spec + per-cross-brand-acquisition-policy-merge + per-autonomy-tier-spec + per-policy-evaluation-engine + per-policy-version-control + per-policy-effective-date-staging + per-policy-audit-trail + per-portfolio audit-trail shipped as the orchestration layer above your existing per-IAM-vendor + per-policy-engine-vendor + per-secrets-management-vendor + per-policy-version-control-platform primitive.