Public Preview - Updated June 2026 - Board and executive oversight materials are readiness guidance and planning support, not legal, compliance, audit, or security approval.

Enterprise AI Oversight

Board oversight for governed AI worker portfolios.

Translate Passport, Evidence, Human Review, Toll Gate, Runtime Permit, and lifecycle records into board-ready questions about inventory, ownership, risk, exceptions, evidence gaps, lifecycle posture, and value signals.

Use this page when you need the executive oversight answer: what leaders can review across inventory, risk, evidence, exceptions, value signals, lifecycle posture, and owner decisions.

This page is a leadership visibility layer over governed source records. It supports inquiry, readiness planning, and owner review before scale decisions; it does not approve AI workers, accept risk, certify compliance, or authorize production use.

Context / Intent

Orient leadership around governed AI worker oversight.

This page helps boards, executives, and accountable owners understand what should be visible when AI workers move from isolated experiments into governed operating models.

Use it to frame inventory, risk appetite, accountability, evidence, incidents, lifecycle posture, and value discussions before deeper review or implementation planning.

  • Boards need visibility into AI worker purpose, ownership, risk tier, lifecycle state, review posture, and evidence gaps before scale decisions.
  • Executives need a portfolio view that connects AI worker investment to operating value, unresolved risk, and accountable management actions.
  • Governance teams need reporting that comes from the same Passport, Toll Gate, Human Review, Stamp, and evidence records used in the operating model.

Review boundary

These materials are planning and oversight support only. They do not create legal conclusions, compliance conclusions, audit opinions, security authorization, production approval, risk acceptance, or guaranteed business outcomes.

Board Oversight Dashboard

A portfolio view of governed AI agents.

Board and executive views should summarize which AI workers exist, why they exist, who owns them, what risk they create, what evidence exists, and what requires attention before scale.

These views are reporting and readiness aids. They do not approve deployment, certify compliance, or replace management, legal, audit, security, privacy, or compliance review.

Board-visible indicators

  • Total registered agents and active Passports
  • High-risk or sensitive agents
  • Agents pending review or missing evidence
  • Human approval coverage and open policy exceptions
  • Material incidents and unresolved remediation
  • Regulatory readiness posture and evidence completeness

Source-backed read-model contract

Board and executive views summarize governed records; they do not become a second control plane.

The first dashboard slice is backed by Passport, Evidence, Human Review, Toll Gate, Runtime Permit, and lifecycle records. The source contract lives at data/board-executive-oversight-read-model.json and reuses the Passport Studio data dictionary and calculation registry.

Dashboard signal Source record Boundary
Inventory and Passport coverage Worker and Passport records Inventory visibility is not production authorization.
Open owner decisions Human Review items linked to Passport and Worker records Queue visibility does not approve, deny, or accept risk.
Evidence gaps and lifecycle posture Evidence Records, Stamps, Passport lifecycle state, and Worker state Readiness signals support review preparation only.
Runtime and Toll Gate posture Runtime Permit and Toll Gate Decision records Local preview metrics do not imply live runtime enforcement.
Third-party and connection posture Vendor Model Passport and Tool/API/Connector Registry records Connection visibility does not imply live integration, endorsement, certification, production authorization, compliance approval, or security approval.

Non-authority disclaimer: This board and executive oversight read model does not approve AI workers and does not create legal, compliance, audit, security, production, or risk-acceptance conclusions. It summarizes source records for human oversight, readiness planning, and owner review.

Board Operating Model

Five duties translate AI governance into board-level inquiry.

Use case oversight

Which AI workers exist, what business purpose do they serve, and which are material enough for board visibility?

Behavioral boundaries

What is each worker allowed to do, what is prohibited, and what requires human review before action?

Regulatory exposure

Which workflows intersect with privacy, security, sector, employment, customer, financial, or cross-border obligations?

Risk appetite

Where is management comfortable scaling, where must use be conditional, and where should activity be paused or retired?

Value realization

What value signals, confidence levels, and unresolved evidence gaps support continued investment?

Maturity movement

How has the portfolio moved across inventory, ownership, evidence, controls, incidents, renewal, and retirement?

Behavioral Envelope

Board oversight starts with the approved boundary for agent behavior.

The Behavioral Envelope should summarize the Passport-backed limits that govern an AI worker before it acts, escalates, uses tools, reaches systems, handles data, or influences consequential decisions.

These limits belong in Passport Studio and Control Plane records. The board view should summarize them; it should not become a separate source of approval authority.

Envelope contents

  • Purpose, use case, owner, sponsor, reviewer, and lifecycle state
  • Approved data classes, systems, tools, destinations, and prohibited actions
  • Autonomy level, human approval triggers, escalation path, and pause criteria
  • Jurisdiction, regulatory exposure, customer impact, and decision consequence
  • Monitoring, evidence, renewal, exception, and retirement requirements

Regulatory Exposure Map

Connect the AI worker portfolio to exposure themes without turning readiness into certification.

Exposure theme Board-ready question Source record
Data and privacy Which workers touch sensitive data, customer data, employee data, regulated records, or cross-border flows? Passport data classes, Tool/API/Connector Registry, Evidence Records, and review notes
Decision consequence Which workers influence financial, legal, employment, healthcare, customer, safety, or access decisions? Passport scope, autonomy level, Human Review items, Toll Gate decisions, and workflow events
External communication Which workers communicate externally, draft customer-facing material, or trigger actions outside the organization? Runtime Permit posture, Action Broker routing, approved destinations, and prohibited actions
Lifecycle and incidents Which workers are pending renewal, under exception, paused, suspended, revoked, retired, or tied to unresolved incidents? Passport lifecycle state, Stamps, Evidence Records, incident records, and Audit Export Packages

Boundary: Exposure mapping supports inquiry and readiness planning. It does not create legal conclusions, compliance conclusions, security authorization, audit opinions, risk acceptance, or production approval.

Incident And Monitoring Lens

Board and executive views should show posture, incident trajectory, and exposure-adjusted monitoring.

These are read-only oversight signals built from Passport, Evidence, Human Review, Toll Gate, Runtime Permit, lifecycle, incident, and monitoring records. They help leaders ask better questions without converting dashboard signals into approval, assurance, legal conclusions, compliance conclusions, security authorization, risk acceptance, or production approval.

Incident trajectory

Summarize open incidents, containment status, restart-review posture, overdue evidence, and repeated blocked actions so leadership can see whether risk is worsening, stable, or improving.

Exposure-adjusted monitoring

Weight monitoring attention by risk tier, data class, connector exposure, external visibility, and action consequence instead of treating every AI worker as the same oversight burden.

Unresolved evidence gaps

Track missing owner review, stale data-lineage evidence, prompt or RAG review gaps, missing incident path, overdue renewal, and unresolved Runtime Permit denials.

Boundary: These read-only oversight signals support governance inquiry and management follow-up. They do not approve AI workers, certify compliance, validate security posture, issue audit opinions, accept risk, or authorize production use.

AI Risk Appetite

Define what agents may do before authority expands.

Acceptable use cases

Boards and executives need a clear view of which agent use cases are acceptable, conditional, restricted, or outside appetite.

Human-owned decisions

Risk appetite should identify actions that always require human approval, including consequential, external, regulated, financial, legal, or customer-impacting activity.

Pause and retirement triggers

Executives should know when an agent must be paused, reviewed, redesigned, restricted, or retired because scope, evidence, ownership, risk, or incidents changed.

Agent Accountability

Every durable AI worker needs named accountability.

Expectation Board-ready question Scaled Agents record
Business and technical ownership Who owns the outcome, operation, escalation, and retirement path? Agent Registry and Passport owner fields
Purpose and scope What is the agent allowed to do, and what is explicitly prohibited? Passport purpose binding, scope, permissions, and prohibited actions
Traceable autonomy Which actions are drafted, recommended, approved, executed, blocked, or escalated? Toll Gates, Runtime Permits, Action Broker decisions, Stamps, and Evidence Records
Human review Where is human approval required, and what evidence supports the decision? Human Review items, approval state, evidence references, and lifecycle events

Board Questions Library

Use repeatable questions to keep oversight tied to governed records.

Portfolio

Which AI workers are active, pending, paused, suspended, revoked, or retired, and which business functions own them?

Authority

Which actions require human approval, which are blocked, and which Runtime Permits or Toll Gates changed this quarter?

Evidence

Where are evidence gaps, stale reviews, missing owners, unresolved exceptions, or incomplete renewal records concentrated?

Exposure

Which workers create material data, customer, operational, financial, legal, employment, safety, or regulatory exposure?

Incidents

What was blocked, escalated, paused, remediated, or retired, and what management action remains open?

Value

Which value signals are modeled, estimated, validated by owners, or awaiting finance and business review?

Regulatory Readiness

Framework-aware evidence without certification claims.

Scaled Agents can be mapped to selected governance expectations, including NIST AI RMF Govern, Map, Measure, and Manage concepts; ISO/IEC 42001 AI management system concepts; EU AI Act readiness themes; and internal audit or compliance preparation.

NIST AI RMF

Organize ownership, mapping, risk measurement preparation, monitoring expectations, and management review evidence.

ISO/IEC 42001

Support AI management system readiness through inventory, roles, lifecycle records, controls, review evidence, and improvement loops.

EU AI Act readiness

Support preparation for risk awareness, transparency, human oversight, documentation, incident review, and lifecycle governance. August 2, 2026 is a major applicability milestone for many EU AI Act obligations.

Boundary: Scaled Agents supports readiness, evidence organization, and governance preparation. It does not certify compliance, provide legal advice, issue audit opinions, or guarantee regulatory outcomes.

Evidence & Passport Reporting

Quarterly board reporting should come from the same governed record.

Passport, Registry, Toll Gate, Human Review, Stamp, incident, exception, and evidence records should support board reporting without creating a second approval system.

A board-ready export should summarize inventory, risk distribution, high-risk agents, open exceptions, pending approvals, incidents, evidence gaps, regulatory exposure, maturity movement, value posture, and recommended management decisions.

Report pack contents

  • AI agent inventory and Passport coverage
  • Top risks, high-exposure agents, and sensitive-data workflows
  • Open findings, policy exceptions, and material incidents
  • Evidence completeness and renewal status
  • Regulatory exposure map and maturity movement
  • Recommended scale, govern, monitor, redesign, or retire decisions

Governance Economics

Measure the business value of governing AI agents.

AI governance should connect risk reduction and evidence generation to operational value. Board and executive reporting should use estimated, modeled, or risk-adjusted language unless financial inputs have been validated by the organization.

Value realization

Track expected hours saved, cost reduced, revenue protected, customer impact, audit effort reduced, and risk reduced.

Risk exposure

Show exposure by agent, business unit, data classification, regulatory impact, tool or connector, oversight dependency, and critical workflow dependency.

Investment portfolio

Classify agents into scale, govern and grow, monitor, redesign, or retire paths based on value, risk, evidence, control coverage, and confidence.