AI governance and release gate
For the team that has been asked to say yes to AI across a company. The stages, the agent’s mandate, the approval step, the register fields, the measure a pilot uses and the exit terms.
A register of every AI workflow, and a gate on every change.
Who it is for
The team that has been asked to say yes to AI across a company and has nowhere to write down what it already said yes to. The first deliverable is usually the inventory, and it is usually longer than anyone expected.
The trigger
A new AI use, or a change to a model, a prompt, a retrieval source or a connector in one that is already live.
The stages
Register
The workflow gets one entry, with its purpose and its owner named.
Record the mandate
What the software may read, keep and do is written down, with its sources listed by name.
Name the reviewer
The person who signs the workflow’s outputs is named, by role and by name.
Attach the evaluation set
The golden set for that workflow is attached to the entry and carries a version number.
Gate the change
The set is re-run. A change whose set has not passed does not reach live use.
Record the release
A named person approves, and the decision joins the entry with its evidence.
Review on a cycle
Each entry is revisited on a fixed cycle, and a stale entry is treated as a finding.
Stage 05 in one picture. Every item is checked before a change reaches live use, and a failing item stops the change.
- Evaluation set re-run
- Citation check pass rate
- Mandate unchanged or re-approved
- Reviewer named
- Incident plan current
- Rollback tested
What the agent may read, keep and do
- Mandate
- MANDATEMATTER 2026-117v3
- The register and its entries
- granted
- The evaluation results
- granted
- The change request
- granted
- The matter content a registered workflow handles
- not granted
- Versions and dates
- granted
- Evaluation results against a version
- granted
- Run the evaluation set and report the result
- granted
- Block a release whose set has not passed
- granted
- Approve a release
- not granted
- Change an entry without a named author
- not granted
May read
May keep
May do
These are the fields of a mandate, not a real matter. No client work appears on this site.
Where a person signs
Stage 06, by the person whose approval a change has to have. If that name is uncertain today, finding it is the first deliverable of the engagement. The agent may block a release and may never approve one.
What the record contains
The register carries one entry per live workflow, and the entry is the artefact a board or a regulator asks for.
These are the fields, not a real matter. No client work appears on this site.
| Field | What goes in it |
|---|---|
| Purpose | What the workflow is for, in a sentence a non-specialist can read |
| Owner | The person accountable for it |
| Mandate | The mandate version in force, and its sources by name |
| Reviewer | The person who signs its outputs |
| Evaluation | The evaluation set version and the date it last passed |
| Change | The last change, its author and its approval |
| Incidents | What went wrong, what was preserved, and what was added to the set |
Entries are written as the run happens and are append-only. A correction is a new entry naming the one it corrects. Section 5 of the operating standard says what that means in practice.
The measure a pilot uses
One measure, chosen by you. The one I would usually propose is the share of live AI workflows with a current entry and a passing evaluation. The baseline is whatever the true number turns out to be on day one. That first number is uncomfortable and it is the point of taking it.
The systems it usually sits on
Wherever your policies live now. This is a register before it is software, and a register in a spreadsheet that is kept beats a platform that is not. LEXSAS resells none of these and claims no certified connector to any of them.
The first week
- Day one
- The scope call: who has been saying yes, to what, and who has to approve a change.
- Days two and three
- The inventory of what is already running, which is usually longer than expected.
- Day four
- The register format is written down, and you correct it.
- Day five
- The gate and the first evaluation set are agreed, and the pilot dates are fixed.
Exit terms
The register is the asset, and it is the artefact a board, an auditor or a regulator asks for. It is yours, in an exportable format, from the first day.
Three questions
It is the normal starting position, and the inventory is the first deliverable. It is more useful than any policy written before it.
No. It runs the evaluation set, reports the result and blocks a release whose set has not passed. Approval belongs to a named person, every time.
It is a register before it is software. It can start wherever your policies live now, and the format matters more than the tool.
The controls behind this page are in the LEXSAS operating standard, sections 6 and 8. The reasoning is in AI governance for in-house legal teams: five minimum controls and Evaluating a live AI workflow: the release gate. Get in touch