Operations / Governance & Compliance
Governance & Compliance
Accountability, audit, policy enforcement and the regulatory landscape — making agent decisions defensible.
- Audit Trails & ProvenanceWhat to capture to reconstruct any decision, hash-chained tamper-evidence, retention vs erasure, and the four-strand provenance of model, prompt, tools and data.
- Policy Enforcement & ControlsPolicy-as-code outside the model, enforcing pre/in/post loop, allowlist-by-default, and separation of duties so a compromised agent cannot close the loop alone.
- The Regulatory LandscapeA qualitative map (not legal advice): risk-tiered regulation, documentation and human-oversight duties, the provider/deployer split, and how NIST AI RMF and ISO/IEC 42001 operationalize it.
- Accountability & OwnershipAccountability never transfers to the agent: the named operator role, RACI on the autonomous action, sign-off that means something, and an accountability ladder set in advance.
- Data Governance for AgentsAn agent is a data-flow machine: lineage through the loop, purpose/consent enforced at point of use, boundary minimization for PII, governed training data, and invisible cross-border flow.
- Governance Without GridlockMake governance an enabler: risk-proportionate tiers, the safe default as the easy path, automated evidence with humans on judgment, and counting gridlock as a real cost.