Governance Gate
Safe, compliant and trusted execution before anything happens.
Lesson 15 of 17 · Find it on the platform map
01 What it is
What this layer does
The governance gate is the checkpoint every proposed action passes through before it touches a business system. It checks who is asking, what data is involved, which policies apply and whether a person must approve. In SCIKIQ it brings together identity and access, information classification, privacy controls, policy and compliance rules, segregation of duties, tool-call guardrails, approvals, and audit and lineage.
02 Concepts
Four ideas to hold on to
RBAC and ABAC
Role-based access control grants rights by job role; attribute-based access control adds conditions such as region, data classification or purpose. Row-level ABAC applies those conditions to individual records, not just whole tables.
Policy precedence: strictest wins
When several policies apply to the same action, each defined by scope, condition and severity, the most restrictive outcome is applied. This avoids a permissive rule quietly overriding a stricter one.
Segregation of duties
The control principle that the same person or agent should not both initiate and approve a sensitive action, such as creating and paying a supplier. It is a long-standing requirement in financial controls such as SOX.
Tool-call guardrails
Checks applied when an agent calls a tool: the request must match the expected schema, stay within a budget, and have approval where it causes side effects such as changing a record or sending money.
03 In SCIKIQ
What the layer contains
04 What good looks like
Signs it is working
- Every action carries an audit record of who or what requested it, which policies were evaluated and the outcome.
- Data classified as confidential or PII is masked or blocked for users and agents without the right purpose and consent.
- Sensitive actions route to a named human approver; actions within policy proceed automatically.
- No single user or agent can both initiate and approve the same sensitive transaction.
05 Diagnostics
Questions to ask your team
- 1
Which actions do we let run automatically, and who decided where that line sits?
- 2
If two policies conflict, can we show which one was applied and why?
- 3
Can we trace any action an agent took back to the data, policy and approval behind it?
- 4
Do our agents have narrower access than the people they act for, or broader?
06 Keep going
Related reading
— Questions
Frequently asked
Does every action need a human approval?
No. Actions within policy proceed automatically; the human path is reserved for sensitive actions, as defined by policy severity and side-effect rules.
How does the gate handle personal data?
Information is classified as public, internal, confidential or PII, and privacy controls such as masking and encryption apply alongside consent and purpose checks at row level.
Why is confidence part of governance?
A recommendation with low confidence or no explanation is a risk in itself, so the gate considers confidence and explainability before letting an action proceed.