Skip to main content

AI Governance

OASIS treats AI as a governed capability: administrators can constrain its use, outputs remain advisory until reviewed, and released work keeps its model and evidence context.

Reviewed September 15, 2026

Control details

Customer choice

  • Generative AI is feature-gated and can be disabled by tenant, organization, role, data class, or workflow policy.

No default shared training

  • The model registry defaults customer-data use for shared vendor training to false.
  • Any exception requires explicit contractual authorization.

Model inventory

  • Governed entries record provider, version, purpose, owner, inputs, outputs, evaluation results, limitations, approval state, and retention policy.

Human review

  • AI material cannot become an official report or public communication through the governance path without a named reviewer and an approve/reject decision.

Traceability

  • AI audit evidence records the prompt, retrieved evidence, model and version, output, user action, approvals, labeling, and retention context.

Risk testing

  • Deployment evaluation covers hallucination, unsupported citations, prompt injection, data leakage, harmful bias, and unsafe recommendations.
  • Change control includes an approved rollback version.

High-impact use

  • Autonomous high-impact decisions about individuals are prohibited.
  • AI output for an individual-affecting workflow must remain advisory to a human decision-maker.

Current provider

  • OpenRouter is the configured gateway for optional AI-assisted features.
  • The selected model is configuration-controlled and may change through the governed model lifecycle.

Important: AI availability depends on customer configuration, entitlement, approved data-use policy, and the specific workflow.