Enterprise Generative Search — Azure and Open Source  ·  View 40 of 41  ·  Assurance

Governance and Audit

From a written policy to evidence an auditor accepts, without a single interpretive step.

Editable source SVG draw.io All views
Policy Source policy who may index what Model policy which models, which data Tool policy per query class Retention policy traces, answers, feedback Expressed as OPA rules in git reviewed, versioned Index schema fields classification, tenant Gateway configuration model routing, budgets Enforced at Index-side filter before scoring Model Gateway model and region choice Tool Broker call-by-call Verifier what may be shown Recorded as Audit log append-only, 7 years Answer provenance claims and evidence ids Decision log every policy evaluation Evaluation history every gate, every release Reviewed by Source onboarding review before a source is indexed Quarterly architecture board policy and drift Red team twice a year Evidence produced Replay any answer from its evidence ids Prove entitlement at the time fingerprint plus ACL history Show the quality record gates at that release findings change policy Governance and Audit — From a Written Policy to Evidence an Auditor Accepts Security / platform Application we own Data store failure / alternate Explainability here means naming the evidence that produced an answer, not interpreting the model. That is answerable; the other is not. v 1.0 · owner Data and AI Global Practice

The decision

  • Explainability here means naming the evidence that produced an answer, not interpreting the model. The first is answerable and auditable; the second is not, and promising it is how these programmes lose credibility.
  • Every policy is expressed as something a machine enforces — an OPA rule, an index field, a gateway configuration — rather than as a document people are asked to remember.
  • Three questions must be answerable for any answer ever given: what evidence produced it, was the caller entitled to that evidence at that moment, and what quality gates the release had passed.

Numbers

  • Audit log append-only for 7 years; provenance for 7 years; policy decision log for 2 years; traces 90 days.
  • A source onboarding review precedes indexing for every new source, with a named data owner and a documented permission mapping.
  • Quarterly architecture board review and a twice-yearly red team, whose findings change policy rather than producing a report.

Risks

  • Policy expressed in two places — a document and a rule — drifts. The document references the rule rather than restating it.
  • Seven-year provenance grows steadily. It stores references, not content, which is what keeps it affordable.