Connect policy to the right objects
Runtime governance starts with a linked AI inventory, not a flat list. Treat Project, AI System, AI Agent, Model, Dataset, and Vendor or Third Party as distinct objects with relationships between them. An AI Agent should have its own record when autonomy, orchestration, or tool use requires independent oversight.
Build that inventory from more than one path, including intake and assessment, existing records, supported platform discovery, model registries, and custom integrations where needed. This connects policy to AI that is already running, not only to projects that entered through a governance request.
Connect runtime signals to policy
Runtime governance evaluates several signal categories: asset and configuration changes such as a new model, agent, model version, tool binding, or guardrail state; evaluation metrics such as faithfulness, correctness, relevance, harmfulness, or task adherence; operational metrics such as usage, invocation count, token consumption, latency, and reliability; sensitive-data signals from prompts, outputs, logs, or application flows; and agent behavior, including tools invoked, model bindings, actions taken, operating instructions, and autonomy.
Policy is the translation layer. It determines what a signal means, whether it crosses an approved threshold, and what should happen next.