GOVERN 1.4
The risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities.
Evidence from: Gateway ledger (not yet generally available)
- What the evidence supports
- Gateway policies are written rules: allow, deny, or hold for approval. Every decision entry names the rule that produced it and whether the policy was enforcing or only observing, so a reviewer can see which declared control applied to each recorded tool call the gateway decided.
- What it does not establish
- That the rules reflect your organization’s risk priorities, or that the process is transparent to anyone beyond the people who read the log. Calls are recorded only while the ledger file reads cleanly; if it is damaged, the gateway still decides calls and forwards the ones it allows but writes no entry. Calls refused by the kill switch, or because a tool’s definition changed, leave no entry.
- Not covered
- Your risk management process and its outcomes outside agent tool calls.
Ledger entries: policy.decision