Platform · Governance Control Plane

Turn AI governance from spreadsheet evidence into operating controls.

AI Warden connects AI inventory, business products, standards-mapped controls, policy bindings, approval workflows, review periods and runtime request logs. Governance teams can review what exists, who owns it, which controls apply, whether evidence is passing and who approved changes.

AI inventory

Know which AI assets exist before you try to govern them.

The control plane brings together discovered cloud AI assets and AI Warden runtime objects: LLM aliases, MCP servers, hosted agents, system principals, policies and request-log activity.

CloudDiscoveryCloud AI services, AI entitlements and approved cloud resources.
RuntimeGatewaysLLM routes, MCP servers, hosted agents, tools and service principals.
StatusApprovalNew models, services and connectors can enter review before product use.
AuditActivityRequest logs show actual use, not just declared inventory.

Products, labels and ownership

Map technical AI assets to business accountability.

Products are the governance anchor. A product can represent an internal copilot, hosted agent, customer-facing chatbot, AI-enabled workflow, reporting service or application. Labels and ownership turn raw inventory into control scope.

  • Assign product owners and platform owner groups.
  • Attach resources such as LLM aliases, MCP servers, cloud resources and agents.
  • Use labels such as gdpr=true, tier=production, region=eu or data=personal.
  • Apply controls to products whose labels match.
product: customer-insights-agent
owner_group: retail-digital
labels:
  gdpr: true
  tier: production
  region: eu
  data: personal
resources:
  - llm_model_alias:gpt-4o-eu
  - mcp_server:customer-profile-readonly
  - hosted_agent:customer-insights
matched_controls:
  - approved_models_only
  - icap_request_response_required
  - mcp_servers_approved_and_scanned

Controls, standards and policy bindings

Controls point to the policies and evidence that make them true.

A control is not just a document. It has scope, owner, framework references, required policies, optional machine predicates, review cadence and evidence state.

Standards and regulators

Map controls to external obligations and internal frameworks so one operating control can support multiple assurance needs.

  • EU AI Act, NIST AI RMF and ISO/IEC 42001.
  • GDPR, DORA, SOC 2, FCA/SYSC and internal risk standards.
  • Customer-defined controls for sector-specific obligations.

Live policy bindings

Bind governance controls to actual enforcement objects in the LLM Gateway, MCP Gateway, ICAP integration and FinOps policy layer.

  • Required LLM, MCP, ICAP, content and budget policies.
  • Predicates such as approved models only or MCP scanned and approved.
  • Evidence pass, fail, unknown, pending and overdue states.

Example control anatomy.

A GDPR-scoped AI processing control can apply to production products tagged gdpr=true, require EU-approved model routes and ICAP request/response policy, then show whether the required policies and predicates are operating.

FieldExample
Framework refsGDPR Art. 5 · ISO 42001 8.4 · NIST GV-1
Scope labelsgdpr=true · tier=production
Required policiesllm_content_policy · icap_policy · mcp_firewall_policy
Predicatellm_only_approved · required_policies_present
Cadencequarterly review with evidence snapshot

Approval workflows

Material AI changes should not go live without review.

AI Warden separates inventory/catalog approvals, product ownership reviews and four-eyes policy approvals so operational changes remain auditable.

Catalog

Approve discovered AI assets

Review models, services, MCP servers, connectors and system principals before they become approved product resources.

Policy

Four-eyes enforcement changes

Require a submitter and separate approver for firewall, content, ICAP, budget, LLM and MCP policy changes.

Review

Attest operating controls

Control owners can review current machine evidence, add notes and freeze a snapshot at attestation time.

Runtime evidence

Support enforcement review with request logs, approvals and review snapshots.

Governance evidence is strongest when it connects declared controls to real traffic. AI Warden links controls to policies and policies to LLM/MCP request logs, including AI Warden scanner outcomes, ICAP decisions, budget outcomes and local blocks.

  • Request-log evidence for LLM prompts, responses and MCP tool calls.
  • ICAP request/response decisions attached to the transaction.
  • Approval diffs and policy history for material changes.
  • Review snapshots showing evidence state at sign-off time.
evidence_chain:
  obligation: GDPR Art. 32
  product: customer-insights-agent
  control: icap_request_response_required
  policy: llm_icap_policy:global
  approval: policy-change-1842
  runtime_log: llm_request_log:9f3c...
  review_snapshot: 2026-Q3-control-review
  state: passing

Operating model

Governance stays useful because it sits next to the gateway.

Controls, labels, approvals and reviews are not disconnected compliance records. They live alongside the enforcement paths used by employees, developers, agents and MCP tools.

Governance and risk teams

  • Define controls, framework mappings, review cadence and evidence requirements.
  • Track failing, pending and overdue controls by product and owner.
  • Export evidence for auditors, internal risk teams and customer due diligence.

Platform and security teams

  • Operate LLM, MCP, ICAP and budget policies that satisfy controls.
  • Use approval workflows for high-impact changes.
  • Investigate runtime evidence through request logs and SOC workflows.

Governance component

Show the control, the scope, the policy and the evidence.

AI Warden Governance Control Plane connects the governance story to the enforcement layer, so assurance reflects how AI is actually used.