How it fits together

Nexus and Mechanic are not two separate tools — the link between them is structural. A Gap in Nexus is resolved by a mechanism in Mechanic, and that progression is tracked in both places.

The most important thing to understand about Balcony is that Nexus and Mechanic are not two separate tools that happen to live in the same product. The connection between them is the point.

[Screenshot needed] PLACEHOLDER IMAGE: A diagram showing the full analytical chain — Artefact → Expectation → Control → Mechanism — with Nexus labelled on the left half (Artefact through Control) and Mechanic on the right half (Control through Mechanism), with arrows showing how the control is the shared handoff point and how coverage state flows back to Nexus

The handoff point

The control is where Nexus and Mechanic meet.

In Nexus, a control is the target of mapping: when you map an expectation node from a regulatory document, you connect it to a control in the unified framework. This is how regulatory obligations become visible against a common structure.

In Mechanic, a control is what a mechanism is for: when you set a mechanism's objective, you link it to one or more controls. This is how operational processes become connected to governance requirements.

The same control appears in both tools. The crosswalk in Nexus shows what regulatory obligations map to it. The mechanism in Mechanic shows what operational process is behind it. The coverage state — Gap, Covered, or Implemented — is the bridge between the two.

How coverage state changes

Gap is the default: a control has expectations mapped to it in Nexus, but no mechanism linked to it in Mechanic.

Covered appears when a mechanism is created in Mechanic and its objective is linked to the control. The link has been established; the mechanism has not yet been confirmed as fully operational.

Implemented appears when the mechanism is assessed and its key components are confirmed as present and adequate.

This progression is visible in the Crosswalk view in Nexus. Every mapped expectation can be traced to a coverage state, and every coverage state can be traced to the mechanism — or absence of mechanism — behind it.

The bidirectional relationship

The analytical flow is not one-directional. Work in one tool regularly sends you back to the other.

Nexus informs Mechanic: A new regulatory obligation mapped in Nexus creates or extends a Gap, which points to a mechanism that needs to be built or updated in Mechanic. The specific expectations in the crosswalk tell you what the mechanism must satisfy — and if multiple frameworks map to the same control, the mechanism must satisfy the most demanding of them.

Mechanic informs Nexus: A mechanism assessment in Mechanic reveals that a control's mechanism is partial or absent, which sends you back to Nexus to understand what expectations are at risk — and whether there are converging obligations from other frameworks that make the gap more urgent.

This back-and-forth is not a failure of workflow; it is the workflow. Governance understanding deepens iteratively. The crosswalk and the mechanism portfolio grow together, each one making the other more precise.

A concrete example

  1. You load the EU AI Act into Nexus and map Article 9 (Risk Management) to controls in the RM domain.
  2. The RM controls now show as Gap — regulatory obligations are documented, but nothing operational is behind them.
  3. In Mechanic, you create a "Risk Classification" mechanism and link it to the RM controls via its objective.
  4. The RM controls move from Gap to Covered in the Nexus crosswalk.
  5. You work through the mechanism's components. You find that Ownership is absent — no one is named as accountable for the risk classification process.
  6. You address this by assigning an owner, at which point the Ownership component moves to Functioning.
  7. Once all components are confirmed, the mechanism status becomes Functioning and the RM controls move from Covered to Implemented.
  8. You return to Nexus and find that ISO 42001 also maps to the same RM controls. The mechanism you just confirmed as Implemented satisfies obligations from two frameworks simultaneously.

This is the efficiency that the unified control framework makes possible. One mechanism, assessed once, can close Gaps against multiple regulatory sources — because the crosswalk has already done the work of mapping them to a common control structure.