Skip to content

Govern · Docs

Risk tiering, policy as code, runtime guardrails, red team evals, and the audit evidence behind every decision.

Sample governance data. This control plane page renders a curated demo dataset.Govern the live initiative

Reference

Architecture Guide

Follow a case from risk inputs to controls, review and evidence. Start with a sample, then use the reference sections below.

First task: run a sample governance check

Product Overview

The Enterprise AI Governance Control Plane shows how enterprise GenAI and agentic systems can be registered, risk tiered, governed with policy as code, tested through red team evals, monitored at runtime, escalated to human reviewers, and exported as audit ready evidence.

The sample registry and browser models let executives inspect risk posture and engineers inspect controls. Use the Executive / Technical lens to switch density. Current-program release gates remain separate from the broader sample registry.

Architecture

Frontend: Next.js 14 + TypeScript + Tailwind + Recharts (static export friendly). Backend: FastAPI + Python + SQLAlchemy + SQLite, provider agnostic model gateway (AI_PROVIDER=mock by default).

Policies live as code in policies/*.yaml; red team suites in evals/*.json; control to framework mappings in app/core/frameworks.py. This deployment runs fully client side in static demo mode, the same governance engine is ported to TypeScript so every decision is reproducible with no backend.

Governance Pipeline

Every AI request flows through: 1. Risk scoring, prompt and use case risk assessed deterministically 2. Input guardrails, injection, PII, toxicity, bias, financial, tool action checks 3. Model gateway, mock or live response generated 4. Output guardrails, unsupported claim and citation checks on the response 5. Decision engine, highest precedence action selected (BLOCK > ESCALATE > REQUIRE_CONFIRMATION > REDACT > REWRITE > ALLOW_WITH_DISCLAIMER > LOG_ONLY > ALLOW) 6. Audit, event written to a tamper evident, hash chained log 7. Human review, escalated items queued with SLAs

Guardrails (8)

1. Prompt Injection, blocks directive overrides, jailbreaks, token injection 2. Sensitive Data / PII, redacts SSN, card, email, phone, passport, DOB 3. Unsupported Claims, disclaims overconfident or unsourced assertions 4. Regulated Financial Recommendation, escalates credit and investment decisions 5. Tool Action Risk, escalates / confirms destructive or high impact actions 6. Toxicity / Professional Conduct, blocks abusive content 7. Bias / Protected Class, blocks decisions based on protected attributes 8. Citation Required, flags RAG answers lacking sources

This hosted browser model uses deterministic rules. Its confidence values summarize modeled signals; they are not statistical calibration or a guarantee of safety. Backend-only options are separate from the browser implementation.

Governance Decisions

ALLOW, passed all checks ALLOW_WITH_DISCLAIMER, passed with an advisory note REDACT, PII or sensitive content removed REWRITE, response rewritten for compliance REQUIRE_CONFIRMATION, user must confirm before proceeding ESCALATE, sent to a human reviewer BLOCK, request rejected outright LOG_ONLY, allowed but flagged for audit

Assurance & Evidence

Audit integrity, the static deployment exposes an embedded sample verification record. New browser-session events are inspectable but are not part of that sample hash chain. A connected backend may supply a fresh verification result. Red team evals, available suites exercise the rule pipeline. Inspect the run's cases and results; the browser sample does not retain evaluation run history for evidence reports. Framework mapping, every policy maps to NIST AI RMF 1.0, the EU AI Act, and ISO/IEC 42001. RBAC, Analyst / Reviewer / Auditor / Admin personas demonstrate separation of duties in the browser. They are not authentication or a server authorization boundary. Evidence, drafts contain current case and policy snapshots plus event/review records in the requested period. Section coverage counts available records, not controls passed or compliance certification.

Interactive Lab

See it Live, the same risky prompt with and without governance, side by side. Red Team Arcade, try to break the AI; the control plane scores every contained attack. Business Case, an interactive ROI model (cost avoided, hours saved, time to launch). Maturity Index, a 6 question self assessment placing you on a crawl/walk/run/fly curve. Regulatory Readiness, control coverage mapped to EU AI Act / NIST / ISO. Board Brief, generate a screenshot ready one pager for the board.

Demo Script

1. See it Live, run "Ignore all previous instructions" (BLOCK), an SSN (REDACT), a credit decision (ESCALATE). 2. Red Team Arcade, fire a few attacks; watch containment hold. 3. Executive Cockpit, portfolio posture and the value strip. 4. Policy Workbench, open a policy; see the YAML and its framework mapping. 5. Human Review Queue, switch role to Reviewer and action an item. 6. Eval Lab, run a suite, then Compare runs. 7. Audit Log Explorer, inspect the available verification record and its scope. 8. Board Brief, generate the one pager.

Setup

The hosted sample needs no API key. Start with a sample prompt in the Runtime Playground.

For an optional real model response, open Model & connection, choose an OpenAI-compatible endpoint and enter your own model and key. The key remains in this browser's local storage and is sent to that endpoint. A failed call can fall back to a mock response; check the mode on the actual result.

Repository setup and the optional governance service are documented separately in the project's README and operating instructions.

Return to the Runtime Playground