Engineering decisions, product thinking, and compliance insights.
Enterprises won't adopt a compliance platform that means another password or hand-copying data into the HRIS. So we ship both sides: single sign-on per organisation over standard OIDC, and a read-only API that lets HR and governance systems pull their own compliance data on their own schedule.
Most platforms bolt MFA onto admin accounts and leave the read-only viewer — usually the largest role — as the soft way in. We enforce multi-factor across every role, and an adversarial penetration test drove eighteen fixes we walk through here.
A compliance platform that looks like someone else's software is one staff quietly distrust. Here's how we recolour the entire product per organisation at runtime, with no rebuild — and why we let an organisation rename its own vocabulary.
Multi-tenancy is easy to claim and hard to prove. Most platforms enforce it in application code — one forgotten filter from a breach. We pushed isolation into the database itself and prove it with hundreds of tests that run without privilege.
Every LMS vendor claims AVETMISS compliance. Almost none admit NCVER's Compliant Software Register is explicitly not an endorsement or a quality warranty. We're now listed on it as Lattice Learn. Here's what that actually means, and where the regulator boundary really sits.
When a learner wants to see or correct their data, that should be a button, not an email to an inbox someone checks on Fridays. How Lattice Learn handles access and correction as self-service, by design.
A look at the economics of the Australian contractor-compliance market: who carries the cost, how it flows back into the rates organisations pay, and why a $0-to-contractor model is structurally cheaper.
An LMS is a records system whether you treat it like one or not. Retention schedules, append-only signed disposal with a cooling-off window, and a log of every automated decision. Why training records have to be defensible, not just stored.
Compliance gating usually means more forms. Done right, a geofenced check-in is a single tap. The design choices behind check-in that blocks off-site but lets anyone check out anywhere.
A peak body authors a mandatory training rule once; it cascades to every member council and auto-enrols the right people by position. How master distribution and mandatory rules scale training without a coordinator chasing a list.
Contractor compliance records are immutable and Merkle-sealed — tamper-evident by construction. What that means, how the sealing works, and the honest limits of the claim.
A PDF is easy to forge; a certificate that writes to an append-only ledger and verifies by public QR is not. How Lattice Learn issues tamper-resistant certificates, and labels accredited vs non-accredited honestly.
Linear modules test recall. Branching scenarios test judgement: the learner makes a call, the path responds, and every decision is logged. How adaptive learning paths work in Lattice Learn.
Most systems treat contractors as a document store. We assess them against your own position-to-competency matrix — the same one your employees run on. Here is why that distinction changes contractor compliance.
If finishing a course moves a compliance score, blocks an uncertified operator, and cascades down from a peak body, the LMS isn't an add-on you can skip. It's base tier.
A completion tracker counts who finished. An RTO-grade platform holds the USI in the records layer and keeps it off the certificate, exports a NAT file, and answers a data-subject-rights request, because the records law is part of the design.
Every contractor sign-in runs six independent checks and returns PASS, BLOCK or WARN — with a reason. A walk through the gate, the cascade, and why every decision is explainable.
Most platforms wire learning to operations with SCORM exports and manual reconciliation. Ours doesn't bolt the LMS on: it lives inside the compliance schema, so finishing a course changes what a worker is allowed to do.
Our contractor licence is $150 per contractor per year, billed on active profiles only — and contractors themselves pay nothing. Here is exactly what that bundles and why the $0-to-contractors model matters.
Recording a completion is easy. Proving one to a regulator, after the fact, when intent doesn't matter, is a different problem. So we built for the audit, not the tick.
Most platforms rent their SCORM runtime from a US cloud and charge per launch. We author and serve courses inside our own schema, on Melbourne metal, with no per-play toll.
A PCBU's WHS duty for on-site contractors is non-delegable — and a folder of certificates collected at procurement doesn't discharge it. Why contractor compliance has to be verified at the gate, on the day.
Most platforms connect learning to operations through SCORM export and manual reconciliation. We grew the LMS inside the compliance schema: same system, not connected to it.
Most multi-module SaaS is a federation of products that share a login. We sell something else: a single nervous system where empty seats at the table are designed in, and the upsell isn't a banner. It's missing data, shown specifically.
Twelve modules shipping independently is a feature. Twelve modules that share data across three interoperability tiers is a platform. Here's how we built the connective tissue.
When an incident occurs, the first question is always: 'Was the worker qualified?' Lattice Look answers it instantly with competency snapshots.
Equipment tracking is easy. Blocking an uncertified operator from starting a shift is hard. Pre-start certification gates close the gap between 'we track it' and 'we enforce it.'
Most inspection tools are glorified checklists. Ours cross-references operator certification status at the time of every inspection — because a checklist without context is just paperwork.
Reactive compliance finds gaps after incidents. The Compliance Horizon graph shows you gaps forming months before they become problems.
Why we run Australian-only, two-state infrastructure, how we enforce data residency at every layer, and what it means for government procurement.
Training budgets are finite. The What-If Simulator lets compliance officers model gap closure scenarios and see the projected impact before committing a dollar.
Victoria's Occupational Health and Safety Amendment (Psychosocial Health) Regulations 2025 changed the game. Here's how we built a module to meet them.
Building an interactive scatter plot that shows every Victorian council's compliance position in real time — and why anonymisation was the hardest problem.
How we turned the abstract concept of 'document health' into something visceral, immediate, and impossible to ignore.
Every compliance platform starts with a spreadsheet replacement. We started with the question nobody was asking: what if the training matrix was the foundation, not the feature?