Approve discovered AI assets
Review models, services, MCP servers, connectors and system principals before they become approved product resources.
Platform · Governance Control Plane
AI Warden connects AI inventory, business products, standards-mapped controls, policy bindings, approval workflows, review periods and runtime request logs. Governance teams can review what exists, who owns it, which controls apply, whether evidence is passing and who approved changes.
AI inventory
The control plane brings together discovered cloud AI assets and AI Warden runtime objects: LLM aliases, MCP servers, hosted agents, system principals, policies and request-log activity.
Products, labels and ownership
Products are the governance anchor. A product can represent an internal copilot, hosted agent, customer-facing chatbot, AI-enabled workflow, reporting service or application. Labels and ownership turn raw inventory into control scope.
gdpr=true, tier=production, region=eu or data=personal.product: customer-insights-agent owner_group: retail-digital labels: gdpr: true tier: production region: eu data: personal resources: - llm_model_alias:gpt-4o-eu - mcp_server:customer-profile-readonly - hosted_agent:customer-insights matched_controls: - approved_models_only - icap_request_response_required - mcp_servers_approved_and_scanned
Controls, standards and policy bindings
A control is not just a document. It has scope, owner, framework references, required policies, optional machine predicates, review cadence and evidence state.
Map controls to external obligations and internal frameworks so one operating control can support multiple assurance needs.
Bind governance controls to actual enforcement objects in the LLM Gateway, MCP Gateway, ICAP integration and FinOps policy layer.
A GDPR-scoped AI processing control can apply to production products tagged gdpr=true, require EU-approved model routes and ICAP request/response policy, then show whether the required policies and predicates are operating.
| Field | Example |
|---|---|
| Framework refs | GDPR Art. 5 · ISO 42001 8.4 · NIST GV-1 |
| Scope labels | gdpr=true · tier=production |
| Required policies | llm_content_policy · icap_policy · mcp_firewall_policy |
| Predicate | llm_only_approved · required_policies_present |
| Cadence | quarterly review with evidence snapshot |
Approval workflows
AI Warden separates inventory/catalog approvals, product ownership reviews and four-eyes policy approvals so operational changes remain auditable.
Review models, services, MCP servers, connectors and system principals before they become approved product resources.
Require a submitter and separate approver for firewall, content, ICAP, budget, LLM and MCP policy changes.
Control owners can review current machine evidence, add notes and freeze a snapshot at attestation time.
Runtime evidence
Governance evidence is strongest when it connects declared controls to real traffic. AI Warden links controls to policies and policies to LLM/MCP request logs, including AI Warden scanner outcomes, ICAP decisions, budget outcomes and local blocks.
evidence_chain:
obligation: GDPR Art. 32
product: customer-insights-agent
control: icap_request_response_required
policy: llm_icap_policy:global
approval: policy-change-1842
runtime_log: llm_request_log:9f3c...
review_snapshot: 2026-Q3-control-review
state: passingOperating model
Controls, labels, approvals and reviews are not disconnected compliance records. They live alongside the enforcement paths used by employees, developers, agents and MCP tools.
Governance component
AI Warden Governance Control Plane connects the governance story to the enforcement layer, so assurance reflects how AI is actually used.