Skip to main content

Governance

Governance controls what is allowed to go live on the platform. You write policies that describe what must be true before something ships (facts to record, statements to acknowledge, metrics to hit, documents to upload, reviewers who must approve). You apply those policies to a solution: a named group of the workloads you want to govern. From then on, every time one of those workloads goes live (a deploy, a start, a launch, a create that runs something), the platform checks the solution's requirements and blocks the action until they are complete.

Governance Solutions

How it fits together​

ConceptWhat it is
PolicyA reusable set of ordered stages. Each stage can collect form fields, can require one gate (acknowledgment, approval, threshold, evidence, input, or guardrail), and can gate resource types, meaning it blocks them from going live. See Policies.
SolutionA group of workloads (specific resources, or every resource of a type) plus the policies applied to them. See Compliance.
RequirementEvery required field and every gate of every applied policy becomes a requirement on the solution, with a status: pending, satisfied, failed, or waived.
EnforcementAt go-live, the platform finds the solutions containing the workload and blocks it while any requirement that gates its type is pending or failed. See Enforcement.
ReviewApproval gates are decided by the reviewers you name (users, roles, or organization groups) on the Reviews page. See Stages & Reviews.
Audit trailEvery policy, solution, and requirement action is recorded for administrators. See Compliance.

A policy on its own does nothing. It takes effect when it is published (Active and not a draft) and applied to a solution that contains the workloads you want to govern.

Where to find it​

Governance is in the sidebar under Governance:

PageWhat you do there
SolutionsCreate solutions, add workloads and policies, complete requirements, upload evidence. This is also the Governance landing page.
PoliciesBrowse, create, edit, and delete policies in the Policy Builder.
ReviewsApprove or deny the approval gates you are a reviewer for.
Audit LogThe governance audit trail. Administrators only.

When a go-live is blocked anywhere in the platform (for example Deploy on an app, Start on a workspace, Create on an avatar), a Governance requirements window opens right there so the requirements can be completed and the action retried. See Enforcement.

Resource types you can govern​

A solution can include any of these workload types, and a policy stage can gate any of them. For types marked type level only, you add "All type resources" to a solution instead of picking individual resources, because the resource does not exist until the action that governance checks.

TypeKeyChecked whenHow you add it to a solution
AppappThe app is deployedPick apps, or all apps
WorkflowworkflowThe workflow is deployed (including deploying a version, or promoting a workflow to an agent)Pick workflows, or all workflows
AddonaddonThe add-on is created (creating it deploys it) or deployedPick add-ons, or all add-ons
WorkspaceworkspaceThe workspace is deployed, started for the first time or after an error, or launched from its project (resuming a stopped workspace is not checked again)Pick workspaces, or all workspaces
VolumevolumeThe volume is createdPick volumes, or all volumes
ProjectprojectA workspace of the project is deployed, started for the first time or after an error, or launched from the projectPick projects, or all projects
ML ModelmlModelA model is published or deployed from the model registry, AutoML, fine-tuning, or self-hosted serving; requests to a self-hosted model through the AI GatewayPick models, or all models
Fine-tuning JobfineTuningJobThe fine-tuning job is createdPick jobs, or all jobs
AutoML JobautomlJobThe AutoML job is createdPick jobs, or all jobs
Data SourcedataSourceThe data source is createdType level only
AgentagentThe agent is startedType level only
AvataravatarThe avatar is createdType level only
JobjobA job run is triggered (manually or by its schedule)Type level only
Code SessioncodeSessionThe code session is deployedType level only
A/B TestabTestThe A/B test is deployed or an experiment is startedType level only
Marketplace AppmarketplaceAppA marketplace app is deployedType level only
AI Gateway ModelaiGatewayModelEvery request to a model through the AI GatewayType level only
Workflow ToolworkflowToolThe workflow tool is deployedType level only
Data Forge ProjectdataForgeData generation is startedType level only

"All type resources" governs every resource of that type, including ones created later, for everyone the solution applies to. Use it deliberately: a type-level workload in a solution with open requirements blocks that type for your whole organization (or the whole platform in a single-organization installation).

Getting started​

1. Create a policy​

Go to Governance > Policies and click Create Policy. Name it, pick a category and severity, tick the Applicable Resource Types, and add stages. In each stage add the form fields to collect, optionally turn on a gate, and tick the Gated Resource Types the stage should block. Turn Active on and switch Draft to Published, then click Save Policy. See Policies.

2. Create a solution​

Go to Governance > Solutions and click Create Solution. Name it, add workloads (specific resources, or "All type resources"), select the policies to apply, and click Create Solution. See Compliance.

3. Complete the requirements​

Open the solution. The Gate Requirements section lists every requirement grouped by policy, each with its own form: enter values, tick acknowledgments, submit metrics, upload evidence, verify guardrails, and request approvals. The solution's status moves to Compliant when every requirement is satisfied or waived.

4. Review and approve​

Reviewers are notified when an approval is requested. They approve or deny it on Governance > Reviews (a denial needs a comment). See Stages & Reviews.

5. Go live​

Deploy, start, or create the workload as usual. If requirements are still open, the Governance requirements window lists exactly what blocks it, lets you complete it in place, and enables Retry once everything is done. See Enforcement.

Who can do what​

ActionWho
Create a policy or a solutionAny user with access to Governance
See a policyIts creator and administrators. Published policies are visible to everyone in your organization (or everyone, in a single-organization installation) so they can be applied.
Edit or delete a policyIts creator or an administrator. A policy applied to any solution cannot be deleted.
See and change a solution (name, workloads, policies, delete)Its owner and administrators
See and complete a solution's requirementsEveryone the solution can govern: users in the same organization (every user in a single-organization installation), plus the owner and administrators. This is what lets a developer whose go-live is blocked by someone else's solution finish the requirements.
Decide an approval gateThe reviewers named on the gate. Administrators can decide any approval gate at any time, and their decision settles it.
Waive a requirementAdministrators only, with a written reason
View the audit logAdministrators only

Administrators see every policy and solution across all organizations.

Regulatory frameworks​

Policies are a general mechanism: model each obligation of a framework as a stage requirement, gate the resource types that must not ship until it is met, and the platform tracks completion and keeps the evidence and decisions. Tag policies with the framework (for example soc2, hipaa, gdpr, iso-27001) to find them later. See Regulatory compliance and the EU AI Act guide.

Automating governance​

Everything on these pages is also available through the REST API (authenticate with an X-API-Key that has the governance:read / governance:write scopes) and the Python SDK.

Best practice

Introduce blocking gradually. Start with stages that gate nothing, so teams see and complete the requirements without being stopped, then tick Gated Resource Types on the stages that matter once the process is working.