Know what it may use
Approved collections, currency, ownership and access are designed before the interface.
AI assistants / Governance
Human review and AI governance define what an assistant may do, which information it may use, who approves outputs, how quality is evaluated and how problems are escalated. GA Applications turns those decisions into interface controls, permissions, logs, review queues and operating procedures suited to the particular use case rather than a generic policy document alone.
The assistant has prepared a response, but it is not an approved decision.
AI assistance belongs inside a designed operating process. It does not replace accountable people, authoritative records or competent professional judgement.
Approved collections, currency, ownership and access are designed before the interface.
Citations, source context and uncertainty travel with the draft.
Permissions, review, escalation, logging and shutdown routes match consequence.
The record states audience, purpose, sources, output, decision consequence, model or provider, data categories and clear exclusions.
Explain the user problem and why AI is considered.
Identify harm from wrong, missing, biased or exposed information.
A human gate must provide enough source context, time and authority to make a real decision rather than becoming a ceremonial click.
Name the competent role and alternatives when unavailable.
Show output, evidence, uncertainty, destination and effect together.
The assistant needs visible routes for out-of-scope requests, source conflict, sensitive data, unsafe content and system failure.
Send the user to an appropriate person or established process.
Allow authorised suspension without waiting for a code release.
Test sets, red-team scenarios, permission checks, feedback review and meaningful change control monitor whether the system remains within its approved purpose.
Set acceptance criteria for support, citation, refusal and leakage.
Re-evaluate model, prompt, source, permission and action changes.
Documentation covers source owners, provider settings, access review, logs, retention, incidents, user guidance, monitoring and retirement.
Assign routine review and issue-response responsibilities.
Tell users when AI is involved and how to challenge an outcome.
Questions worth answering
Govern before scaling
We can assess a proposed assistant and turn governance decisions into a testable product specification.