Data Academy · Layer 13 · Reason & act

Governance Gate

Safe, compliant and trusted execution before anything happens.

Lesson 15 of 17 · Find it on the platform map

01 What it is

What this layer does

The governance gate is the checkpoint every proposed action passes through before it touches a business system. It checks who is asking, what data is involved, which policies apply and whether a person must approve. In SCIKIQ it brings together identity and access, information classification, privacy controls, policy and compliance rules, segregation of duties, tool-call guardrails, approvals, and audit and lineage.

02 Concepts

Four ideas to hold on to

1

RBAC and ABAC

Role-based access control grants rights by job role; attribute-based access control adds conditions such as region, data classification or purpose. Row-level ABAC applies those conditions to individual records, not just whole tables.

2

Policy precedence: strictest wins

When several policies apply to the same action, each defined by scope, condition and severity, the most restrictive outcome is applied. This avoids a permissive rule quietly overriding a stricter one.

3

Segregation of duties

The control principle that the same person or agent should not both initiate and approve a sensitive action, such as creating and paying a supplier. It is a long-standing requirement in financial controls such as SOX.

4

Tool-call guardrails

Checks applied when an agent calls a tool: the request must match the expected schema, stay within a budget, and have approval where it causes side effects such as changing a record or sending money.

03 In SCIKIQ

What the layer contains

Identity and access (RBAC and ABAC)Information classification: public, internal, confidential, PIIData security and privacy: PII, encryption, maskingPolicy and compliance (SOX, GDPR): scope, condition, severity, strictest winsConfidence and explainabilitySegregation of dutiesAudit and lineageTool-call guardrails: schema, budget, side-effect approvalApprovals: human path for sensitive actions, automatic within policyRow-level ABAC, consent and purpose, single sign-on

04 What good looks like

Signs it is working

  • Every action carries an audit record of who or what requested it, which policies were evaluated and the outcome.
  • Data classified as confidential or PII is masked or blocked for users and agents without the right purpose and consent.
  • Sensitive actions route to a named human approver; actions within policy proceed automatically.
  • No single user or agent can both initiate and approve the same sensitive transaction.

05 Diagnostics

Questions to ask your team

  1. 1

    Which actions do we let run automatically, and who decided where that line sits?

  2. 2

    If two policies conflict, can we show which one was applied and why?

  3. 3

    Can we trace any action an agent took back to the data, policy and approval behind it?

  4. 4

    Do our agents have narrower access than the people they act for, or broader?

06 Keep going

Related reading

— Questions

Frequently asked

Does every action need a human approval?

No. Actions within policy proceed automatically; the human path is reserved for sensitive actions, as defined by policy severity and side-effect rules.

How does the gate handle personal data?

Information is classified as public, internal, confidential or PII, and privacy controls such as masking and encryption apply alongside consent and purpose checks at row level.

Why is confidence part of governance?

A recommendation with low confidence or no explanation is a risk in itself, so the gate considers confidence and explainability before letting an action proceed.