USE CASES / DATABRICKS
Put a decision in front of your model endpoints.
GovernorAI inventories the AI surfaces in your workspace, then allows or denies individual inference calls at the Model Serving endpoints you choose — with an audit record for every decision. Turning it on changes four environment variables on one served entity. Turning it off puts your original configuration back.
It refuses rather than guesses: if another system's governance markers are already on the endpoint, if it would record an already-governed config as your original, or if it cannot read the change back from Databricks.
THE FIRST QUESTION A PLATFORM TEAM ASKS
Turning it on is reversible, and we prove it worked before saying so.
Before any capability claim, the fear has to go. The change is small, it is verified against Databricks rather than assumed, and it can be put back exactly as it was.
WHAT GETS DECIDED
A policy decision on every inference call you route through us.
Your caller posts to a GovernorAI endpoint URL instead of the Databricks /invocations URL. The endpoint name, provider and the messages or inputs are evaluated against your policy before anything reaches Databricks.
The ceiling, stated here rather than in a footnote. This path carries allow and deny only. There is no approval step on it — an approval or redaction rule pointed at it resolves to a deny, so do not author one. The decision is on the request; the response passes through untouched. The Databricks endpoint URL keeps working, so this is a control you route to, not an interception. You author the policy; no Databricks policy pack ships. With no matching rule the call is allowed unless your deployment is configured to fail closed, and the emergency kill switch does not apply to this path.
PER-ENDPOINT SCOPE
Different rules for different endpoints.
Governance is only useful if it can be narrow. Each governed endpoint carries its own identity plus a namespace you choose when you enable it, so fraud-scorer and support-chat can sit under different policies.
A rule matches on a tool-name pattern plus one condition on the call's arguments, such as which endpoint was invoked. There is no rule axis for a catalog, schema, table, cluster, SQL warehouse, job, model version or user identity — better to know that now than to find it in a proof of concept.
WHAT WE CAN SEE
An inventory of the AI surfaces in your workspace.
One connection per workspace, authenticated with a workspace token. Five API surfaces are read, hourly by default and on demand when you ask. Only Model Serving endpoints are governable — everything else is inventory, and enrolling one of the others is refused with a typed error rather than quietly accepted.
On a very large Unity Catalog the model and function lists can under-report, and a token without catalog read permission returns an empty list rather than an error. That is why there is an on-demand connection check that confirms the token can reach the metastore and names the permissions it is missing.
YOUR WORKSPACE TOKEN
Encrypted at rest, rotatable, and verified before it replaces the old one.
The token is encrypted with AES-256-GCM using a fresh nonce per write, and the connection object the API returns carries no credential fields at all.
Named limits. One long-lived personal access token that you mint — service-principal OAuth is not available today, and GovernorAI cannot verify or narrow the token's permissions, nor track its age or expiry. There is one platform encryption key, so bring-your-own-key and per-tenant keys are not offered, and rotating that platform key for stored workspace tokens is not supported today.
IF YOU INSTRUMENT THE CALL YOURSELF
Your own code can also get approvals and a kill switch.
The endpoint proxy is the no-code-change option, and it has a real ceiling. The SDK path is where the fuller set of outcomes is genuinely enforced — worth saying which is which rather than blurring them together.
It covers only code you change. Approvals fire from an approval rule you author — automatic risk-based escalation is off by default. No lane on any Databricks path redacts, masks or rewrites a payload.
THE BOUNDARY
What this does not cover.
A platform team that finds these limits on its own stops the deal. Here they are first.
THE RECORD
What lands in the audit trail, and what does not.
Each decision records the time, the endpoint-derived action name, the namespace, allow or deny, and the policy and rule that decided it, attributed to your tenant.
It is a decision record, not an inference log: the prompt, the model's response, token counts, cost and latency are not recorded. Requests rejected before policy evaluation — unknown endpoint, bad secret, circuit open — produce no record at all. Control-plane actions, such as who connected a workspace, who enabled governance on which endpoint and who rotated a token, are written to a hash-chained, tamper-evident ledger. Runtime decisions on Databricks endpoints are durable rows: not hash-chained and not signed. There is no SIEM delivery today, and no compliance evidence item is produced for a Databricks decision.
BEFORE THE CLUSTER STARTS
A cluster that cannot start ungoverned is still running an agent nobody assessed.
Pinning governance at cluster-create guarantees the decision path exists. It does not say the agent inside it should have been deployed. Assurance answers that separately, before the release, and blocks the pipeline rather than reporting after the fact.
It ships as a CI/CD gate whose exit codes mean distinct things — pass, blocked, unreachable and unauthorised are four different answers, and unreachable fails closed.