The question is already being asked.
MLSs are writing AI terms into their data licenses and asking platforms how AI touches feed data before approving them. Insurance applications are growing AI questions. Whoever asks a brokerage next, the answer depends on one thing: whether the record of what the AI actually did exists.
A record like that either exists for the past year, or it doesn't. It cannot be created retroactively.
Every brokerage running REALM has been building it since the day they turned EVE on, not as a report bolted on afterwards, but as the way the platform works.
One page. Four answers.
The Compliance desk carries a single view of everything the AI did across the brokerage: what happened, what was authorized, what a human decided, and what the record rests on.
The activity ledger
Every action, EVE's and your agents', lands as an append-only entry: who or what acted, for which contact and transaction, on what channel, with what flags. Entries are never edited after the fact; a correction is a new entry.
Authorizations in force
AI use of MLS data is denied by default, per MLS, in code. An MLS appears in an AI feature only after its written authorization is recorded, and the record shows the authorization table itself, each row citing its basis.
Held for review
Anything touching an offer, price, contract, financing, legal, or an unhappy client routes to a human before it goes out, in every mode, with no setting that disables it. The record shows what was held, and how it resolved.
What the record rests on
The record states its own coverage: native capture is always on, and connected mailboxes, the browser extension, and API access are counted, so what it covers is stated, never implied.
Denied by default. Authorized in writing. Enforced in code.
MLS listing data does not reach an AI feature in REALM unless that specific MLS has expressly authorized it in writing and the authorization is recorded, with the document it cites. This is not a policy promise: the control is enforced in code, and it fails closed. An unknown source, an unconfigured source, even a moment when the policy table can't be read: all of them read as no.
Your feed still powers search, listing pages, and every display surface exactly as licensed. The gate governs one thing: whether a listing's data may be placed in front of a model. When an MLS asks how AI touches their data, you answer from the authorization table, not from memory.
Supervision works because the limits are structural.
The escalation ceiling
There is no setting that lets EVE negotiate. Anything touching an offer, a price, contract terms, financing, legal, or an unhappy client routes to your agent, in every autonomy mode, inbound and outbound, with no switch that turns it off. The record shows each held item and the human decision that resolved it. That ceiling is the reason brokers are comfortable turning the rest on.
The content boundary
Supervision needs to know what was done and for whom. It does not need to read every client message. The record and its export carry the supervision grain only. Full message content is sealed per-transaction in the REALM Vault: write-once storage, hash-chained audit, checked on a schedule. The export states this boundary inside the packet itself.
Supervision without surveillance
The record shows what the AI did. It does not show what your agents asked it. Questions an agent types or speaks to EVE are answered statelessly and are not written to the activity record, so the broker sees every action taken under the brokerage and none of the team's working questions. Agents get an assistant they can think out loud with; brokers get the record that matters.
The policy she describes is the policy the platform enforces.
When an agent asks what your office requires, EVE answers from the rules that already run in your brokerage: the documents each transaction requires, the work each stage owes, the compliance rules that hold a file, and the state setup your broker reviewed. She names which of those the answer came from. A written description of a brokerage's rules can drift from the rules themselves, so there is no second copy here to drift: asking EVE what the policy is and watching the platform enforce that policy are one fact read two ways.
For everything that is genuinely prose, the handbook, the onboarding guide, the commission explainer, you upload it and she answers from it, naming the document and the page she took it from. When those documents do not answer the question, she says so instead of filling the gap from general knowledge.
Every document carries an audience: the whole brokerage, one office, one team, or only you. A document outside an agent's scope is not shown to them as restricted. It is not there at all.
And the line that matters most: where an item in your state setup is not backed by a statutory citation, EVE presents it as your brokerage's practice rather than as a legal requirement, and says whether a broker has confirmed it.
Her words are read before they leave.
The review queue decides whether a person should see something before it goes out. This is the separate check on the words themselves, and it runs on what EVE answers and on what she sends.
Fair Housing language
Protected class wording and steering phrasing are flagged on what EVE answers and on what she sends. The check is tuned to stay quiet on ordinary listing copy, because a checker that cries wolf is one your agents learn to click past. It reports what the words contain and leaves the judgment to your broker.
Personal data, masked
A client texts their Social Security number in to get a pre-approval moving. It happens, and every assistant that quotes a thread back is one step from repeating it. Social Security and account shapes are masked on the way out, so a number that came in cannot be quoted back out, whoever approved the message.
Held, never dropped
When an automated message trips the screen, it does not go out and it does not disappear either. It goes back to the agent who owns the relationship, carrying the reason, for them to edit, approve, or drop. Silently swallowing a message loses it and tells nobody.
When someone asks, you hand them a file.
One click exports the record for any period: the activity ledger as a spreadsheet, and a summary carrying the full authorization table with each written basis, the counts, and plain statements of what the packet does and does not contain.
Every export is itself recorded, fingerprinted and logged in its own append-only trail, so a packet produced today can be matched to its export event years later. Built to be handed to an MLS auditor, an E&O underwriter, or whoever asks next.
What the record means for your obligations is between you and your counsel. Our job is that the record exists.
Run AI your MLS can ask about.
AI supervision is not an add-on; it is how REALM BROKER works. Every seat gets the full platform; the brokerage gets the record.