Reference map

The Enterprise AI Exposure and Governance OS

In the decision path, not the request path. Find every AI asset, give it an accountable human, decide, compile to the planes you already own, and prove it.

Everything below is one page of the operating model, with the two places it is not finished marked rather than smoothed over.

Built and applied Partial, joining up Awaiting customer data
Governance Control Plane

Decide · Compile · Read back · Prove

Policy Kernel

Usage policies, detectors, MCP tool ACL, egress and agent-to-agent contracts, versioned.

M09 · M10

Identity & NHI

Agent and machine identities ranked by reach, Graph permissions, keys held outside Entra, roles.

M08 · M16

Approvals & Certification

Named reviewers, SLA by tier, decision expiry, Rule-of-Two review, version-bound release certificates.

M04 · M05 · M06

Evidence Ledger

Append-only sealed audit log, hash-chained reports, evidence packs, SIEM export.

M07 · M14

Spend & Risk

Explainable Exposure Score, ISO 42001 risk register, AI spend counted once, budgets.

M07 · M12
The six layers

One record per AI asset, carried all the way through

1

People & Accountability

Who owns it, why it exists

M03 · M07
Owner and sponsortechnical and business, per agent
Signed purposeversioned, drift checked daily
Governance Registera time-boxed decision for every agent
Board reportingAI Exposure Report, three editions
2

Obligations & Classification

What the law and frameworks require

M14 · M07
Risk tieringexposure legs, autonomy, Rule of Two
EU AI Act · ISO 42001 · NIST · OWASP112 controls, 9 frameworks
17-regime legal registrystatus per obligation, never a percentage compliant
Incident clocksper-regime deadlines
3

Lifecycle & Gates

One record, start to retirement

M03 · M04 · M05 · M02
DiscoveredOwned & purposedArchitecture reviewdesign gateRelease certifieddeploy gateOperatingSuspendedRetiredsessions revoked

A change to an agent's configuration fingerprint re-opens its review. The guarded transitions are being joined into a single state machine — the states and the events exist today; one function as the only write path does not yet.

4

Agents, Models & Tools

What runs, with what reach

M02 · M09 · M13
Agent inventoryCopilot Studio, Power Platform, ServiceNow, Box, Hatz
Models and AIBOMmodel per agent, advisories
MCP tools pinnedapproved definitions by hash
Runtime assuranceOpenTelemetry, metadata only

Runtime assurance is built and has had no customer telemetry through it yet. It is marked awaiting customer data rather than shown as working, because a capability with no traffic through it is not the same as a capability in use.

5

Data & Endpoint

Where prompts and data meet

M10 · M11
Data Shielddetectors for sensitive data in prompts
Prompt Guard extensionenforces in Chrome, Edge and Brave
Endpoint governanceforce-install, per-device status
Purview read-backlabels and DLP verified
6

Enforcement Planes

They enforce; Govern360 verifies

M11 · M15
Entra Conditional AccessIntunePurviewSASEAI gatewayGlobal Secure AccessCrowdStrikeSentinelOneTaniumPalo AltoZero Networks
Foundation

You cannot govern what you have not found

NetworkBrowser and endpointSaaS and identityEmail and workflowAgents and API

Discovery sits under all six layers. It is why Discovery carries the largest weight in the Exposure Score, and why a source nobody connected reads not measured rather than clean.

The closed loop

What makes the number a measurement

Detect dailyScore exposureDecide and approveCompile and pushRead back and verifySeal evidence

What this map does not claim. Govern360 does not sit in the request path and does not replace Entra, Purview or Defender. It decides, compiles to planes the customer controls, and verifies by read-back. Where a plane exposes no read path, the control stays compiled and says so rather than being shown as verified. State as of 9 October 2026, modules M01–M18.

Every connected source · Runtime assurance · How the score is built · All answers

Questions

The operating model, answered

What is an AI governance OS?

An operating model rather than a product category: one record per AI asset carried from discovery to retirement, a control plane that decides and compiles, the enforcement planes the organisation already owns doing the enforcing, and a closed loop that reads the applied state back and seals the evidence. Govern360 is in the decision path, never the request path.

Does Govern360 replace Entra, Purview or Defender?

No. It does not sit in the request path and it does not replace any enforcement plane. It decides, compiles governance intent into the planes the customer controls, and verifies by reading the applied state back. Those planes keep their operational owner.

What are the six layers?

People and accountability; obligations and classification; lifecycle and gates; agents, models and tools; data and endpoint; and the enforcement planes. Underneath all six sits discovery, because nothing above it can govern an asset it has not found.

What are the gates in the lifecycle?

Two. Architecture review is the design gate and release certification is the deploy gate. An agent moves discovered, owned and purposed, through both gates, to operating, and then to suspended or retired with its sessions revoked. A change to the configuration fingerprint re-opens the review.

What is the closed loop?

Detect daily, score exposure, decide and approve, compile and push, read back and verify, seal evidence. The loop is what makes the score a measurement rather than a snapshot, because every point traces to a configuration that was read, not asserted.