Skip to main content
Version: 1.0.0-beta

AI Governance

Non-negotiable governance rules for all AI capabilities in AIIA.

Core Principles

PrincipleEnforcement
AI obeys RBACPermission check at AI Gateway before any retrieval or generation
No cross-role leakageRAG filters by user's role and org permissions
Traceable outputsEvery AI response includes citations + confidence scores
Human approval requiredAI = suggestion only; user must "Apply/Approve"
Full audit loggingAIRequest → AIResult → AuditLogEvent chain
Permission-aware retrievaluser_roles passed to RAG pipeline for filtering

AI Gateway Flow

Audit Trail for AI

Every AI interaction creates three records:

RecordContent
AIRequestUser identity, prompt, context data, timestamp
AIResultAI response, citations, confidence, model used
AuditLogEventAction=AI_ACTION, linking request to result

IPPF Prompt Governance

AI prompts are governed assets:

  • Versioned — each prompt has immutable version history
  • Approved — changes require admin signoff
  • Auditable — version changes are logged
  • Methodology-aligned — IPPF overlays ensure professional standards

Permission-Aware Retrieval

The RAG pipeline respects user permissions:

  1. User's roles and org_id extracted from JWT
  2. Vector search filtered by accessible engagements
  3. Results limited to user-authorized data
  4. Citations reference only visible internal objects