Square One
GUIDE · GLOSSARY

Governed work glossary

Plain definitions of the terms behind governed work and enterprise AI governance. Each is short on purpose.

Governed work
Work produced inside a permission-aware, evidence-grounded, auditable environment, where every output traces to its source and AI is one governed capability alongside automation and business rules.
Ungoverned work
Work that cannot be traced, checked or stood behind: shadow AI in personal accounts, documents with no defensible source, processes living in spreadsheets and inboxes, decisions nobody can later explain.
AI governance
The operating-level control over how AI is accessed, sourced, approved, metered and audited across an organisation. A component of governed work, not a policy document.
Shadow AI
Staff using AI tools such as ChatGPT, Claude or Copilot in personal or unsanctioned accounts for work, outside the organisation’s governance, evidence and permissions.
Evidence grounding
Deriving an output from retrievable evidence and keeping it connected to that evidence, so any claim can be traced back to a source rather than merely sounding plausible.
Provenance
The recorded origin of an output: which sources it rests on, who produced and approved it, and when. Provenance is what makes work defensible.
Permission-aware
Access bound to entitlement and inherited from the systems that already hold your permissions, so no person and no output ever draws on evidence they are not entitled to see.
Permission inheritance
Taking access rules from an existing identity and permission system (principally Microsoft 365) rather than reinventing them, so governance strengthens the estate instead of bypassing it.
Policy gate
The permanent control layer every AI request passes through: approved providers, for approved tasks, at a known cost, metered and logged. The gate is fixed; the model behind it is replaceable.
Model-agnostic
Using the most suitable AI model for each task and keeping governance constant as models change, rather than committing the organisation to one provider.
The confidence premium
The idea that as intelligence is commoditised, the advantage moves to organisations that can reliably turn it into trusted, defensible work. Intelligence you can rent; confidence you have to build.
Organisational memory
The judgement, decisions and reasoning an organisation retains over time, rather than losing them when a browser session closes or an experienced person leaves.
Automation first, AI where it adds value
The principle that deterministic work (forms, approvals, calculations, ledgers) runs on automation and business rules, and AI is introduced only where reasoning genuinely adds value.
Append-only record
A record that only ever grows: nothing above the line is rewritten, and corrections are new entries that say so. It underpins auditability and reconciliation.
Evidence perimeter
The set of external sources a workspace is permitted to use. It defines what governed AI and generation may draw on, and is re-evaluated when work is shared.
Intersection-of-access
When work is shared, tightening the evidence it can use to what every member is entitled to see, so a shared output never depends on sources some members cannot access.
Approval
A deliberate human decision that stands between a draft and a decision, or between work and its release. In governed work, approval applies to a specific version and is recorded.
Auditability
The property that what happened, who approved it, and what it was based on are preserved after the fact and cannot be quietly rewritten.
Retrieval-augmented generation (RAG)
A technique where an AI model is given retrieved documents to ground its answer. Useful, but retrieval alone is not governance: it adds no approval, permission-tightening or immutable record.
Microsoft Copilot
Microsoft’s AI assistant inside Microsoft 365. It answers over content the signed-in user can already access, inheriting Microsoft 365 permissions. A capability that can operate inside a governed environment.
Oversharing
Pre-existing over-broad permissions in a Microsoft 365 estate. AI assistants surface it faster because they answer over everything a user can reach, so governing AI starts with getting permissions right.
Defensibility
The ability to answer “where did this come from?” about a piece of work: to show its evidence, its permissions and its approval, on request, without a scramble.
Operating Maturity Model
Five stages, from Shadow to Confident, describing the operating conditions AI runs under in an organisation. Higher stages mean more control, not more usage.
AI operating system
Shorthand for an environment that governs AI, evidence, automation and knowledge as one operating model, rather than a single AI tool bolted onto existing systems.

Start with the idea these terms describe.

Read: what is governed work? →
SQUARE ONE IS A PRODUCT OF INHOUSE CX© 2026 INHOUSE CX