Skip to content
BlueprintPage 30
30GOVERNANCE

Model & Provider Governance

The customer should be able to change models without rewriting its governance architecture.

Priority
P1
Phase
Phase 2
Primary owner
AI Platform / Risk
Status
Blueprint

Objective

Enterprises will use multiple models and providers. Agent Trust Cloud should normalize policy across them while giving customers control over which models may process which data and perform which types of work.

What to build

  • Provider/model inventory with owner, region, contract status and approved use cases.
  • Policy by model capability, hosting mode, data residency, retention terms and risk classification.
  • Route sensitive tasks to approved providers or customer-hosted models.
  • Track model/version changes and material capability drift.
  • Record model usage/cost by agent and business purpose.

Implementation decisions

  • Do not assume model vendor identity equals agent identity.
  • Support model allow/deny lists and fallback chains with policy checks.
  • Require review when an agent switches to a materially different provider/model for protected workflows.
  • Capture only the prompt/response content required by customer policy; support metadata-only modes.

Definition of done

  • Unapproved models cannot receive restricted data through protected gateways.
  • Provider changes are visible and auditable.
  • Routing rules can optimize cost without violating security constraints.

Success metrics

  • Approved-model coverage
  • Policy-routed requests
  • Unauthorized provider attempts
  • Cost per agent/task

VENDOR NEUTRALITY

The customer should be able to change models without rewriting its governance architecture.