Sanctioned AI Gateway

Sanctioned AI Gateway An architecture diagram generated by Archify. Acceptable-use card · tool x data class · Layer 01 Govern-as-Code Acceptable-use card tool x data class Staff · SSO, attested · Architecture component Staff SSO, attested AI gateway · allow / redact / block · Layer 04 Runtime Controls & Observability AI gateway allow / redact / block Approved AI tools · enterprise terms · Layer 04 Runtime Controls & Observability Approved AI tools enterprise terms Assurance store · decision events · Layer 02 and 05 Assurance store decision events Unapproved tool · the bypass · Architecture component Unapproved tool the bypass Shadow-AI discovery · identity, network · Layer 02 and 05 Shadow-AI discovery identity, network sign in allow enforce event bypass finds Layer 01 Govern-as-Code Layer 04 Runtime Controls & Observability Layer 02 and 05 Legend Backend Database Security External

The governed path is the easy path

  • • Approved tools sit behind single sign-on and one gateway
  • • Access depends on a current acceptable-use attestation
  • • A block comes with a reason and a route to the right tool

Policy as code at the gateway

  • • The acceptable-use card maps each tool to the data classes it may receive
  • • The gateway allows, redacts or blocks per call
  • • Every call writes a decision event, with a hash of the input rather than the input

Discovery is the feedback loop

  • • Discovery reads identity, network and expense data for tools outside the gateway
  • • Each find becomes an intake request before it becomes a sanction