Governance
We bring the governance, not just the agents.
Most agent projects don't fail on technology. They fail because nobody knows who may approve what, what it costs, and what to do when it goes wrong. Every pilot leaves with this solved — in documents the client adopts and in rules the platform enforces.
21%
of companies have mature agent governance
Deloitte, State of AI in the Enterprise 2026
> 40%
of agentic projects will be cancelled by 2027 — inadequate risk controls is a named cause
Gartner, June 2025
1 · Policy pack
An adopted governance policy, not a forgotten PDF.
Included in every pilot (S8). Also available standalone for those who already have agents installed elsewhere, without governance.
The client leaves the pilot with an agent governance policy approved by management, answering:
- Who may hire and retire agents — and who approves each hire.
- Approval tiers per action type — automatic, one tap, two admins, prohibited.
- Prohibited actions — for example: issuing or altering fiscal records, evaluating people's performance, emotion recognition.
- Incident procedure — who stops what, how it is communicated, what is logged.
- Worker information — the duty under EU AI Act Art. 26 and Portugal's Lei 13/2023, handled with a ready notice.
Sample governance policy (redacted)
A real policy, names removed, to see the level of detail before talking to us. We send it by email — no form, no marketing sequence.
Request by email →2 · Approval matrix
Designed per client. Enforced by the platform.
During the audit we classify every action of every agent. The matrix doesn't live in a folder: it lives in the Approve / Reject cards the platform sends. A rule people can't forget.
| Action | Tier | Note |
|---|---|---|
| Read tasks, documents and the shared mailbox | auto | Within the charter's scope |
| Remind an internal colleague by DM | auto | Logged; no new content leaves the company |
| Email a client or supplier | one tap | Area manager approves the text |
| Grant a user access to an agent | one tap | The agent's admin |
| Hire or retire an agent | one tap | Chief of Staff proposes; manager approves |
| Alter a posting or fiscal record | prohibited | Never: the certified accountant keeps responsibility |
| Access health or sensitive HR data | two admins | With access notification (Lei 58/2019 Art. 29) |
| Change an agent's model or limits | two admins | IT + area lead |
- To
- geral@clinicasol.pt
- Value
- €4,860 + VAT
- Tier
- one tap — sales manager
3 · Operating rhythm
Governance that runs itself.
A policy is only worth something if someone executes it. The Chief of Staff's daily brief, the monthly review with us and the audit logs form a documented, repeatable oversight process the client can show an auditor.
Daily brief — Wednesday
- Activity: 58 tasks by 4 agents; 3 escalated to humans.
- Costs: €3.60 yesterday; €41 this month; seat 2 at 88%.
- Refused access: 1 (external@… tried to DM Quote Builder).
- Pending decisions: 2 — proposal send (Pedro), HR access (Ana + João).
- Health: backup 03:00 ok; no model being deprecated.
Daily
Chief of Staff's brief in the management channel: activity, costs, refused access, pending decisions, installation health.
Monthly
Review with us: what the agents did, cost per task, seat usage, incidents, what to hire next. Minuted.
Always
Audit and usage logs, retained ≥ 6 months. Auditable by construction.
4 · Compliance records
What we prepare. What your DPO signs.
We don't replace the data protection officer or the certified accountant. We hand them the work done, to review and sign.
| Record | We prepare | The client decides / signs |
|---|---|---|
| Impact assessment (DPIA) | Template filled in during the audit: data, purposes, risks, measures. | The DPO reviews, adjusts and signs. |
| Register of AI systems | Inventory of agents, roles, models, data processed, risk classification. | Management approves the classification. |
| Log-retention statement | Retention ≥ 6 months, minimisation, reconciliation with GDPR. | The DPO validates. |
| Worker information (Lei 13/2023) | Notice template for workers, works council and union delegates. | Management delivers it before go-live. |
| Approval matrix | Classification of every action; configured in the platform. | Area leads approve the tiers. |
| Subprocessor list and DPA | Enlogical's DPA and the model providers' DPAs. | Management signs. |
Already using AI?
A governance review of the AI you already use.
70% of adults use generative AI personally — and many paste company data into free chatbots. A governance review (S8 standalone) maps what is happening, what the law requires and how to bring it in-house.
Book a governance review of your current AI use Back to the Trust Center