Governance

The rule for everyone else's tools, including mine.

Scope
any tool touching member data
Gate
sanctioned environment or nothing
First subject
my own tools

The problem

A company-wide push to use AI produced a dozen employee-built projects in a few months, several of them touching member data and intended for production. Nobody was coordinating them, and the conversation was being had as a project management problem when it was a compliance one.

The rule

A binary gate. Any project that touches member data runs inside the environment IT already governs (identity-aware proxy, secrets management, audit logging, models called through the company's cloud account) or it does not go to production. No exceptions for how small it is or who built it.

Why I had standing

The proposal engine already met the standard, and it was the most consequential tool anyone had built. It's easier to ask for a rule you're already following.