- GOVERN — RBAC (admin / compliance / user), dual-approval purge, documented policy versions.
- MAP — Per-tenant inventory of AI systems, registered models, and the policy packs applied to each.
- MEASURE — Live metrics (
/metrics) for enforcement actions, PII / injection rates, and chain-write latency. - MANAGE — Alerts page incident workflow with assignment, SLA timers, and post-incident notes recorded in the audit chain.
Compliance
NIST AI RMF
Govern · Map · Measure · Manage.
The NIST AI Risk Management Framework pack maps to all four functions: