Use case oversight
Which AI workers exist, what business purpose do they serve, and which are material enough for board visibility?
Enterprise AI Oversight
Translate Passport, Evidence, Human Review, Toll Gate, Runtime Permit, and lifecycle records into board-ready questions about inventory, ownership, risk, exceptions, evidence gaps, lifecycle posture, and value signals.
Use this page when you need the executive oversight answer: what leaders can review across inventory, risk, evidence, exceptions, value signals, lifecycle posture, and owner decisions.
This page is a leadership visibility layer over governed source records. It supports inquiry, readiness planning, and owner review before scale decisions; it does not approve AI workers, accept risk, certify compliance, or authorize production use.
Context / Intent
This page helps boards, executives, and accountable owners understand what should be visible when AI workers move from isolated experiments into governed operating models.
Use it to frame inventory, risk appetite, accountability, evidence, incidents, lifecycle posture, and value discussions before deeper review or implementation planning.
These materials are planning and oversight support only. They do not create legal conclusions, compliance conclusions, audit opinions, security authorization, production approval, risk acceptance, or guaranteed business outcomes.
Board Oversight Dashboard
Board and executive views should summarize which AI workers exist, why they exist, who owns them, what risk they create, what evidence exists, and what requires attention before scale.
These views are reporting and readiness aids. They do not approve deployment, certify compliance, or replace management, legal, audit, security, privacy, or compliance review.
Source-backed read-model contract
The first dashboard slice is backed by Passport, Evidence, Human Review, Toll Gate, Runtime Permit, and lifecycle records. The source contract lives at data/board-executive-oversight-read-model.json and reuses the Passport Studio data dictionary and calculation registry.
| Dashboard signal | Source record | Boundary |
|---|---|---|
| Inventory and Passport coverage | Worker and Passport records | Inventory visibility is not production authorization. |
| Open owner decisions | Human Review items linked to Passport and Worker records | Queue visibility does not approve, deny, or accept risk. |
| Evidence gaps and lifecycle posture | Evidence Records, Stamps, Passport lifecycle state, and Worker state | Readiness signals support review preparation only. |
| Runtime and Toll Gate posture | Runtime Permit and Toll Gate Decision records | Local preview metrics do not imply live runtime enforcement. |
| Third-party and connection posture | Vendor Model Passport and Tool/API/Connector Registry records | Connection visibility does not imply live integration, endorsement, certification, production authorization, compliance approval, or security approval. |
Non-authority disclaimer: This board and executive oversight read model does not approve AI workers and does not create legal, compliance, audit, security, production, or risk-acceptance conclusions. It summarizes source records for human oversight, readiness planning, and owner review.
Board Operating Model
Which AI workers exist, what business purpose do they serve, and which are material enough for board visibility?
What is each worker allowed to do, what is prohibited, and what requires human review before action?
Which workflows intersect with privacy, security, sector, employment, customer, financial, or cross-border obligations?
Where is management comfortable scaling, where must use be conditional, and where should activity be paused or retired?
What value signals, confidence levels, and unresolved evidence gaps support continued investment?
How has the portfolio moved across inventory, ownership, evidence, controls, incidents, renewal, and retirement?
Behavioral Envelope
The Behavioral Envelope should summarize the Passport-backed limits that govern an AI worker before it acts, escalates, uses tools, reaches systems, handles data, or influences consequential decisions.
These limits belong in Passport Studio and Control Plane records. The board view should summarize them; it should not become a separate source of approval authority.
Regulatory Exposure Map
| Exposure theme | Board-ready question | Source record |
|---|---|---|
| Data and privacy | Which workers touch sensitive data, customer data, employee data, regulated records, or cross-border flows? | Passport data classes, Tool/API/Connector Registry, Evidence Records, and review notes |
| Decision consequence | Which workers influence financial, legal, employment, healthcare, customer, safety, or access decisions? | Passport scope, autonomy level, Human Review items, Toll Gate decisions, and workflow events |
| External communication | Which workers communicate externally, draft customer-facing material, or trigger actions outside the organization? | Runtime Permit posture, Action Broker routing, approved destinations, and prohibited actions |
| Lifecycle and incidents | Which workers are pending renewal, under exception, paused, suspended, revoked, retired, or tied to unresolved incidents? | Passport lifecycle state, Stamps, Evidence Records, incident records, and Audit Export Packages |
Boundary: Exposure mapping supports inquiry and readiness planning. It does not create legal conclusions, compliance conclusions, security authorization, audit opinions, risk acceptance, or production approval.
Incident And Monitoring Lens
These are read-only oversight signals built from Passport, Evidence, Human Review, Toll Gate, Runtime Permit, lifecycle, incident, and monitoring records. They help leaders ask better questions without converting dashboard signals into approval, assurance, legal conclusions, compliance conclusions, security authorization, risk acceptance, or production approval.
Summarize open incidents, containment status, restart-review posture, overdue evidence, and repeated blocked actions so leadership can see whether risk is worsening, stable, or improving.
Weight monitoring attention by risk tier, data class, connector exposure, external visibility, and action consequence instead of treating every AI worker as the same oversight burden.
Track missing owner review, stale data-lineage evidence, prompt or RAG review gaps, missing incident path, overdue renewal, and unresolved Runtime Permit denials.
Boundary: These read-only oversight signals support governance inquiry and management follow-up. They do not approve AI workers, certify compliance, validate security posture, issue audit opinions, accept risk, or authorize production use.
AI Risk Appetite
Boards and executives need a clear view of which agent use cases are acceptable, conditional, restricted, or outside appetite.
Risk appetite should identify actions that always require human approval, including consequential, external, regulated, financial, legal, or customer-impacting activity.
Executives should know when an agent must be paused, reviewed, redesigned, restricted, or retired because scope, evidence, ownership, risk, or incidents changed.
Agent Accountability
| Expectation | Board-ready question | Scaled Agents record |
|---|---|---|
| Business and technical ownership | Who owns the outcome, operation, escalation, and retirement path? | Agent Registry and Passport owner fields |
| Purpose and scope | What is the agent allowed to do, and what is explicitly prohibited? | Passport purpose binding, scope, permissions, and prohibited actions |
| Traceable autonomy | Which actions are drafted, recommended, approved, executed, blocked, or escalated? | Toll Gates, Runtime Permits, Action Broker decisions, Stamps, and Evidence Records |
| Human review | Where is human approval required, and what evidence supports the decision? | Human Review items, approval state, evidence references, and lifecycle events |
Board Questions Library
Which AI workers are active, pending, paused, suspended, revoked, or retired, and which business functions own them?
Which actions require human approval, which are blocked, and which Runtime Permits or Toll Gates changed this quarter?
Where are evidence gaps, stale reviews, missing owners, unresolved exceptions, or incomplete renewal records concentrated?
Which workers create material data, customer, operational, financial, legal, employment, safety, or regulatory exposure?
What was blocked, escalated, paused, remediated, or retired, and what management action remains open?
Which value signals are modeled, estimated, validated by owners, or awaiting finance and business review?
Regulatory Readiness
Scaled Agents can be mapped to selected governance expectations, including NIST AI RMF Govern, Map, Measure, and Manage concepts; ISO/IEC 42001 AI management system concepts; EU AI Act readiness themes; and internal audit or compliance preparation.
Organize ownership, mapping, risk measurement preparation, monitoring expectations, and management review evidence.
Support AI management system readiness through inventory, roles, lifecycle records, controls, review evidence, and improvement loops.
Support preparation for risk awareness, transparency, human oversight, documentation, incident review, and lifecycle governance. August 2, 2026 is a major applicability milestone for many EU AI Act obligations.
Boundary: Scaled Agents supports readiness, evidence organization, and governance preparation. It does not certify compliance, provide legal advice, issue audit opinions, or guarantee regulatory outcomes.
Evidence & Passport Reporting
Passport, Registry, Toll Gate, Human Review, Stamp, incident, exception, and evidence records should support board reporting without creating a second approval system.
A board-ready export should summarize inventory, risk distribution, high-risk agents, open exceptions, pending approvals, incidents, evidence gaps, regulatory exposure, maturity movement, value posture, and recommended management decisions.
Governance Economics
AI governance should connect risk reduction and evidence generation to operational value. Board and executive reporting should use estimated, modeled, or risk-adjusted language unless financial inputs have been validated by the organization.
Track expected hours saved, cost reduced, revenue protected, customer impact, audit effort reduced, and risk reduced.
Show exposure by agent, business unit, data classification, regulatory impact, tool or connector, oversight dependency, and critical workflow dependency.
Classify agents into scale, govern and grow, monitor, redesign, or retire paths based on value, risk, evidence, control coverage, and confidence.