Skip to main content

Concepts

Concepts

Explanations of how AIControls works. Read these to understand the model before changing configuration — for step-by-step instructions, see Tasks.

🔌
Upstreams
How AIControls routes requests to Anthropic, OpenAI, Azure OpenAI, and Amazon Bedrock.
Read more →
👤
Identity & Activity
Identity types, risk scores, behavioral baselines, sessions, adoption analytics, and the audit log.
Read more →
💰
Cost Governance
Budgets, rules, limits, alerts, and context optimization — including compression and lossless retrieval.
Read more →
🛡
Security & Compliance
Security posture, detections, Shadow AI discovery, and compliance coverage against frameworks like NIST AI RMF.
Read more →
📜
Policies
Policy anatomy, enforcement modes, matching rules, and the built-in policy library.
Read more →
🎚
Autonomy Tiers
The CSA NIST T1–T4 autonomy model, the default tier, and how the built-in policies scale enforcement to it.
Read more →
Approval Workflow
The request → approve → grant → expire/revoke lifecycle, and single- vs multi-approver co-sign.
Read more →
🧩
MCP Governance
How MCP tool-call proxying, logging, and authorization work.
Read more →
🗝️
Team Access
Map IdP teams to MCP servers with Access Bindings, enforced at token issuance and per tool call.
Read more →
🌐
Network Egress Filtering
How raw outbound HTTP(S) calls from agent processes are intercepted, governed, and audited.
Read more →
🧑‍💻
Builder Portal
What developers see in their own portal — budgets, scores, tokens, and sessions.
Read more →
📈
Productivity
AI delivery attribution — linking merged pull requests back to the AI sessions that produced them.
Read more →
⚙️
Configuration Model
Deployment settings (Helm/config.yaml) vs. app settings (Settings UI) — seeding, upgrades, and drift notifications.
Read more →