Guide

Governance baseline.

This is the Govern pillar, turned on from day one. The first week of an AiraFusion deployment is a governance exercise, not a technical one — the controls below apply across your whole AI estate: chat, apps, agents, and reports alike. Here's the checklist we run with every platform owner.

1. Map roles to consoles

AiraFusion separates using AI from building AI from governing AI. Connect your identity provider over OIDC / SAML, enforce MFA, and assign each role only the consoles it needs — most employees get the workspace, a small group gets the build surface, and platform owners get admin.

2. Set model allow-lists per role

Decide which roles may use which models, and let the gateway enforce it on every call, in every surface. Because Nexus is vendor-neutral, the same allow-list spans local open-weight models, in-country cloud endpoints, and commercial APIs. A typical regulated-institution baseline keeps analysts on on-prem models, opens in-country cloud to managers, and denies external APIs by default — allowed only per app.

3 — Platform-floor guardrails

One floor under everything.

Guardrails set at the platform level apply to every surface — chat, apps, agents, reports — so no builder can forget them.

  • PII detection and redaction on the way to any model.
  • Prompt-injection screening on untrusted content — documents, web, email.
  • Blocked-topic policies aligned with your compliance rules.
Guardrails
Platform-floor guardrails configured once and applied to every AI surface

4. Define approval chains

Pick the operations that need a human in the loop — customer-facing outputs, high-value decisions, anything leaving the perimeter — and attach approval policies. Runs hold until a named approver releases them; both the hold and the release land in the audit chain.

5. Cap costs where they're spent

Every app gets a hard per-run ceiling on real measured LLM spend — not estimates — enforced mid-run. Agents get budget trees: a total cap across an entire delegation tree that halts everything on breach. FinOps gets one bill and per-run truth.

6 — Verify the audit chain

Then put it on the calendar.

Run chain verification from the Govern console and export a sample range. The audit log is tamper-evident, hash-chained, and WORM-locked — examiner-grade.

  • Verify the chain — a clean, breaks-free result you can show a regulator.
  • Export a range — a streamed, integrity-checked artifact.
  • Schedule both — weekly verification, monthly export rehearsal.

⚠ verify mandates per jurisdiction

Mission Control
Mission Control showing run history, cost, and audit-chain status across the estate
The principle

Every control above is enforced by the platform, not by policy documents. If a rule lives only in a PDF, it isn't a control — it's a hope.

Next step

Run this with our team

Walk the day-one checklist with an AiraFusion engineer against your own compliance rules.