GUIDE · GLOSSARY
Governed work glossary
Plain definitions of the terms behind governed work and enterprise AI governance. Each is short on purpose.
- Governed work
- Work produced inside a permission-aware, evidence-grounded, auditable environment, where every output traces to its source and AI is one governed capability alongside automation and business rules.
- Ungoverned work
- Work that cannot be traced, checked or stood behind: shadow AI in personal accounts, documents with no defensible source, processes living in spreadsheets and inboxes, decisions nobody can later explain.
- AI governance
- The operating-level control over how AI is accessed, sourced, approved, metered and audited across an organisation. A component of governed work, not a policy document.
- Shadow AI
- Staff using AI tools such as ChatGPT, Claude or Copilot in personal or unsanctioned accounts for work, outside the organisation’s governance, evidence and permissions.
- Evidence grounding
- Deriving an output from retrievable evidence and keeping it connected to that evidence, so any claim can be traced back to a source rather than merely sounding plausible.
- Provenance
- The recorded origin of an output: which sources it rests on, who produced and approved it, and when. Provenance is what makes work defensible.
- Permission-aware
- Access bound to entitlement and inherited from the systems that already hold your permissions, so no person and no output ever draws on evidence they are not entitled to see.
- Permission inheritance
- Taking access rules from an existing identity and permission system (principally Microsoft 365) rather than reinventing them, so governance strengthens the estate instead of bypassing it.
- Policy gate
- The permanent control layer every AI request passes through: approved providers, for approved tasks, at a known cost, metered and logged. The gate is fixed; the model behind it is replaceable.
- Model-agnostic
- Using the most suitable AI model for each task and keeping governance constant as models change, rather than committing the organisation to one provider.
- The confidence premium
- The idea that as intelligence is commoditised, the advantage moves to organisations that can reliably turn it into trusted, defensible work. Intelligence you can rent; confidence you have to build.
- Organisational memory
- The judgement, decisions and reasoning an organisation retains over time, rather than losing them when a browser session closes or an experienced person leaves.
- Automation first, AI where it adds value
- The principle that deterministic work (forms, approvals, calculations, ledgers) runs on automation and business rules, and AI is introduced only where reasoning genuinely adds value.
- Append-only record
- A record that only ever grows: nothing above the line is rewritten, and corrections are new entries that say so. It underpins auditability and reconciliation.
- Evidence perimeter
- The set of external sources a workspace is permitted to use. It defines what governed AI and generation may draw on, and is re-evaluated when work is shared.
- Intersection-of-access
- When work is shared, tightening the evidence it can use to what every member is entitled to see, so a shared output never depends on sources some members cannot access.
- Approval
- A deliberate human decision that stands between a draft and a decision, or between work and its release. In governed work, approval applies to a specific version and is recorded.
- Auditability
- The property that what happened, who approved it, and what it was based on are preserved after the fact and cannot be quietly rewritten.
- Retrieval-augmented generation (RAG)
- A technique where an AI model is given retrieved documents to ground its answer. Useful, but retrieval alone is not governance: it adds no approval, permission-tightening or immutable record.
- Microsoft Copilot
- Microsoft’s AI assistant inside Microsoft 365. It answers over content the signed-in user can already access, inheriting Microsoft 365 permissions. A capability that can operate inside a governed environment.
- Oversharing
- Pre-existing over-broad permissions in a Microsoft 365 estate. AI assistants surface it faster because they answer over everything a user can reach, so governing AI starts with getting permissions right.
- Defensibility
- The ability to answer “where did this come from?” about a piece of work: to show its evidence, its permissions and its approval, on request, without a scramble.
- Operating Maturity Model
- Five stages, from Shadow to Confident, describing the operating conditions AI runs under in an organisation. Higher stages mean more control, not more usage.
- AI operating system
- Shorthand for an environment that governs AI, evidence, automation and knowledge as one operating model, rather than a single AI tool bolted onto existing systems.
Start with the idea these terms describe.
Read: what is governed work? →