Govern (GV) · Approval gating
Approval gating at the server side layer
external · Outside the agent entirely
Who is allowed to put this agent into the world, under what authority, accountable to what policy, with what retirement criteria?
What this cell does
AI Governance Council approves new agent classes, ratifies risk-tier policy. Member roles named (CISO, Chief AI Officer, GC, Privacy, Domain Leads). Quorum and voting rules defined.
Cell notes
Charter, Approval gating / Organizational
Structural question. Does the org have a named AI Governance Council with member roles, quorum, voting rules, and recorded minutes?
Owner. AI Governance Council itself; minutes ratified by the chair.
Template fragment
§4.1 (AI Governance Council) of ../../templates/organizational-policy.md.
Audit prompts
- - Who are the Council members by role? Are the named individuals current?
- - When did the Council last meet? Were minutes recorded? Where are they stored?
- - What decisions has the Council made in the last 12 months? Voting record?
Common failure mode
Council named but never meets. Minutes never recorded. ISO/IEC 42001 conformity assessment fails on §A.4.
Citation
NIST CSF 2.0 GV.RR-01, GV.RR-02, GV.RR-03 (organizational leadership, roles, adequate resources). NIST AI RMF GOVERN 2.1, GOVERN 2.2 (accountability). ISO/IEC 42001 §A.4 (leadership), §A.5 (planning). EU AI Act Art. 17(1)(b), Art. 26.
Crosswalk
| NIST CSF 2 0 | GV.RR-01, GV.RR-02, GV.RR-03 |
|---|---|
| NIST AI RMF | GOVERN 2.1, GOVERN 2.2 |
| ISO IEC 42001 | §A.4, §A.5 |
| EU AI ACT | Art. 17(1)(b), Art. 26 |
Cite this cell:
https://agenticcovenants.com/govern/approval-gating/server-side/