The NAVI AI Enablement Journey · Guide 05
AI Governance, Permissions, and Responsible Use
A practical starting model for deciding who may use AI, what information it may reach, what it may do, where people must review the work, and how the organization verifies results and corrects outputs, data, or workflows when needed.
Roles and responsibilitiesResponsible-use boundariesAccess and authorityHuman accountability
Core idea
Governance should make useful work easier to do responsibly. Set a small number of visible boundaries, assign the people who can decide exceptions, and apply the rules to real capabilities.
Where this guide fits: Guides 03 and 04 establish dependable organizational knowledge. Guide 05 defines who may use AI, what information and actions are permitted, and where human authority remains required before connections and workflows are implemented.
Eight governance
decisions
Together, these decisions create a workable boundary. Connection design, workflow testing, and adoption plans are covered in their own guides.
1Who owns AI direction?Name the person accountable for priorities, boundaries, and unresolved decisions.Output: accountable AI owner
2Which uses are allowed?Separate approved, restricted, and prohibited uses, such as research, drafting, decision support, or automation.Output: use classification
3What information may be used?Define public, approved internal, restricted, and excluded information.Output: information rules
4Who may access what?Use role-based access control (RBAC) to match knowledge, working files, sources, and tools to each role and business need.Output: access map
5What must AI not do?Start with clear prohibitions, then define permitted levels for retrieval, analysis, drafting, release, system changes, and unattended work.Output: action authority
6When must a person review?Use clear triggers tied to consequence, uncertainty, and sensitivity.Output: review rule
7Who approves a new AI-enabled process?Name the required business, information, technical, and specialist decisions.Output: approval path
8How are accuracy or workflow issues handled?Pause affected work, verify inputs and outputs, correct the source or workflow, communicate, and resume deliberately.Output: issue response
Approval scope: approving a business process does not automatically approve its data access, technical connection, or use in work that could materially affect customers, money, commitments, operations, compliance, or reputation.
Roles and
responsibilities
Make each necessary decision and responsibility visible. In a small organization, one or two people may hold every role; larger teams can separate them when useful.
AI ownerDirection
Owns the organization’s AI direction. Sets the starting boundary and resolves cross-functional questions.
Business ownerPurpose and result
Owns the business purpose and result. Defines the intended outcome, users, and acceptable impact and risk.
Information or system ownerSource and access
Owns source and access boundaries. Approves information use, access scope, authoritative sources, and technical boundaries.
Reviewer or approverJudgment and release
Owns the human decision. Checks the required evidence or professional judgment and accepts or rejects the result for a stated use.
AdministratorImplementation
Implements approved controls. Configures users, permissions, sources, connections, and settings but does not grant business authority.
UserResponsible use
Owns responsible use of the result. Uses approved capabilities, protects information, performs required checks, and reports concerns.
Responsible-use boundaries
Define what is approved, restricted, or prohibited by classifying the intended use and information together.
Approved
Routine uses within the intended program and manageable consequence.
- Research approved sources
- Summarize, compare, or organize information
- Experiment with private drafts and low-impact personal automations
Default: proceed within normal verification and access rules.
Restricted
Potentially valuable uses requiring named approval or stronger controls.
- External communication or publication
- Restricted information or specialized judgment
- Autonomous agents or unattended actions that can publish, send externally, or change a system
Default: pause until the responsible owner approves the boundary.
Prohibited
Uses that conflict with law, policy, contract, rights, security, or the approved purpose.
- Unauthorized access, surveillance, or deception
- Bypassing required human approval
- Using AI as the sole basis for a high-impact decision
Default: do not proceed. These are baseline examples; add organization- or industry-specific prohibitions as needed.
Public or approved externalUsable for the approved purpose, subject to source, copyright, and contractual limits.
Approved internalOrdinary internal information available through appropriate users and destinations.
RestrictedNeed-to-know information requiring an explicit owner, limited audience, and approved handling.
ExcludedInformation that remains outside AI use unless the responsible owner changes the boundary.
KnowledgeWhich approved organizational context does the role need?
Working materialWho may see or change drafts before approval?
Source systemsWhich records or folders may the connection retrieve?
Tools and actionsWhich exact actions may the user, workflow, or agent perform?
Do not provide an entire repository, dataset, or customer history when a smaller approved subset is sufficient.
Action authority
Increase authority one level at a time. For more information on connection and workflow controls, see Guides 06 and 08.
RetrieveFind approved knowledge or records.
Starting defaultWithin permitted sources and purpose.
Required safeguardVerify access and source authority.
Analyze or recommendCompare, calculate, classify, or suggest.
Decision supportA person owns material decisions.
Required safeguardDefine evidence and acceptance.
Create a draftProduce working files or proposed records.
Private working draftMay be created in an approved private workspace; review applies before release or system use.
Required safeguardName the reviewer and permitted destination.
Publish, share, or sendRelease a result to an audience.
Human confirmationReview content, recipient, and version.
Required safeguardApprove the destination and release rule.
Create or change a recordCause an effect in a business system.
Controlled write-backLimit fields, targets, and actions.
Required safeguardTest failure, duplication, and recovery.
Run automaticallyBegin on a schedule or event.
Separate approvalInteractive use does not authorize unattended use.
Required safeguardBound data, actions, recipients, and pause authority.
Technical control principle: enforce permissions, confirmation, approval, and write limits in NAVI, an external connection, or its tool configuration whenever practical. Use operating practices for judgment and for gaps that cannot be reliably enforced through technical controls.
Human review
triggers
Protect consequential work by tying review to clear conditions rather than applying a vague requirement to everything.
Business or operational impactMoney, commitments, customers, contracts, operations, or reputation may be affected.
Specialized judgmentLegal, financial, employment, safety, compliance, or other qualified review is required.
Release or record changeThe work will be published, sent, filed, or used to change a record.
Sensitive informationThe workflow could expose restricted information beyond the intended audience.
Weak or conflicting evidenceA source is missing, stale, incomplete, or contradicted.
New, changed, or unusual caseThe capability or request falls outside its tested and approved boundary.
Approval path
Use this four-step path when a workflow, prompt, agent, or tool-enabled process meets one or more human review triggers above. Routine private experimentation that does not meet those triggers can proceed within normal access and verification rules.
01Define the purposeOutcome, owner, users, audience, and exclusions.
02Approve context and accessInformation, sources, permissions, tools, and connections.
03Set action and reviewPermitted actions, human decisions, and escalation.
04Record the boundaryApproved version, limits, responsible people, and next review trigger.
Issue response
Respond consistently when results or workflows need correction by containing the immediate risk and correcting the underlying cause.
1PauseStop affected output or action when continued use could cause harm.
2ContainPrevent further sharing, changes, or automated runs.
3VerifyCompare with authoritative evidence and determine scope.
4CorrectFix the underlying source, access, instruction, or process.
5CommunicateNotify affected owners or recipients when needed.
6Resume deliberatelyRetest and restart only after the responsible owner accepts the boundary.
Minimum governance package
Keep essential governance rules visible and usable without creating a second operating system.
Five practical outputs
Use these as the organization’s starting record.
Responsible-use boundaryApproved, restricted, and prohibited uses; information categories; user responsibilities.
Access and authority mapRoles, sources, working areas, tools, and action levels.
Review and escalation ruleReview triggers, qualified reviewers, pause authority, and issue contacts.
Capability registerRecord important workflows, prompts, agents, or tool-enabled processes with owners, versions, boundaries, and status. Use the example at right as a starting format.
Governance refresh triggersMaterial change, issue, post-pilot decision, or periodic review for important capabilities.
Example: Capability Record
Record important capabilities that could materially affect customers, money, commitments, operations, compliance, or reputation.
Capability titleCustomer follow-up workflow
DescriptionPrepares account follow-up drafts using approved CRM context and templates.
Owner and authoritySales Operations owns the workflow. It may create drafts but may not send messages or change CRM records.
Human reviewThe account owner reviews recipients and content before use; Sales Operations handles issues and pauses.
Approved versionCurrent tested version, effective scope, known limits, and next review trigger.
This guide is a practical implementation framework, not legal, regulatory, privacy, security, employment, or industry-specific professional advice. The organization remains responsible for its policies, information classification, access decisions, contractual duties, regulated activities, and final business decisions.