Policy Kernel
Usage policies, detectors, MCP tool ACL, egress and agent-to-agent contracts, versioned.
M09 · M10Reference map
In the decision path, not the request path. Find every AI asset, give it an accountable human, decide, compile to the planes you already own, and prove it.
Everything below is one page of the operating model, with the two places it is not finished marked rather than smoothed over.
Usage policies, detectors, MCP tool ACL, egress and agent-to-agent contracts, versioned.
M09 · M10Agent and machine identities ranked by reach, Graph permissions, keys held outside Entra, roles.
M08 · M16Named reviewers, SLA by tier, decision expiry, Rule-of-Two review, version-bound release certificates.
M04 · M05 · M06Append-only sealed audit log, hash-chained reports, evidence packs, SIEM export.
M07 · M14Explainable Exposure Score, ISO 42001 risk register, AI spend counted once, budgets.
M07 · M12Who owns it, why it exists
What the law and frameworks require
One record, start to retirement
A change to an agent's configuration fingerprint re-opens its review. The guarded transitions are being joined into a single state machine — the states and the events exist today; one function as the only write path does not yet.
What runs, with what reach
Runtime assurance is built and has had no customer telemetry through it yet. It is marked awaiting customer data rather than shown as working, because a capability with no traffic through it is not the same as a capability in use.
Where prompts and data meet
They enforce; Govern360 verifies
Discovery sits under all six layers. It is why Discovery carries the largest weight in the Exposure Score, and why a source nobody connected reads not measured rather than clean.
What this map does not claim. Govern360 does not sit in the request path and does not replace Entra, Purview or Defender. It decides, compiles to planes the customer controls, and verifies by read-back. Where a plane exposes no read path, the control stays compiled and says so rather than being shown as verified. State as of 9 October 2026, modules M01–M18.
Every connected source · Runtime assurance · How the score is built · All answers
An operating model rather than a product category: one record per AI asset carried from discovery to retirement, a control plane that decides and compiles, the enforcement planes the organisation already owns doing the enforcing, and a closed loop that reads the applied state back and seals the evidence. Govern360 is in the decision path, never the request path.
No. It does not sit in the request path and it does not replace any enforcement plane. It decides, compiles governance intent into the planes the customer controls, and verifies by reading the applied state back. Those planes keep their operational owner.
People and accountability; obligations and classification; lifecycle and gates; agents, models and tools; data and endpoint; and the enforcement planes. Underneath all six sits discovery, because nothing above it can govern an asset it has not found.
Two. Architecture review is the design gate and release certification is the deploy gate. An agent moves discovered, owned and purposed, through both gates, to operating, and then to suspended or retired with its sessions revoked. A change to the configuration fingerprint re-opens the review.
Detect daily, score exposure, decide and approve, compile and push, read back and verify, seal evidence. The loop is what makes the score a measurement rather than a snapshot, because every point traces to a configuration that was read, not asserted.