Governance Operations and Decision Rights
Governance Operations is the workspace where your AI governance programme is actually run: who meets, what they decided, what has to happen next, what was excused, what was escalated, and who is allowed to approve each of those things.
Where to find it
Governance Operations has its own entry in the left launcher and its own menu, separate from Compliance. It opens on the Operator Cockpit. It is available to Org Admins and Workflow Admins, and to Rhindon Cyber staff while supporting your tenant.
Operator Cockpit
A single prioritised queue of everything that needs attention, overdue first, then whatever falls due inside the window you choose. Each line explains in plain words why it is ranked where it is, so the order is never a black box. Summary tiles show what is on your plate, what is overdue, what is due soon, and how many escalations are open.
Councils, meetings and decisions
Record your governing bodies and their membership, schedule meetings, build agendas, and capture minutes. Decisions taken are written to a Decision Register that links back to the meeting and to the records the decision concerned, so months later you can show not just the outcome but the forum, the date, and the people in the room.
Actions, exceptions and escalations
- Action Register — every commitment coming out of governance, with an owner, a due date, and visible overdue status.
- Exceptions and waivers — time-boxed permission to depart from a control, with an expiry date, renewal, and an automatic escalation when an exception lapses rather than a silent expiry.
- Escalations — the ladder: what was raised, to whom, by when, and how it was resolved.
- Governance Calendar — meetings, expiries, deadlines and due dates in one view, derived from the live records and exportable to your own calendar.
Authority Matrix — who may approve what
The Authority Matrix is your own definition of decision rights. You declare the authorities that exist in your organization, the rules that decide which authority applies to a given record, and who currently holds each one. Rules are versioned and governed: changes are proposed, reviewed, and published, and before publishing you are shown how many existing records the change would reroute.
How routing behaves on a record
When a use case, AI system, control, or policy version is opened, its approval steps are generated from the matrix rather than hard-coded. The record shows which authority is being asked to approve and why that route applies. The system fails closed: if the route cannot be determined, approval is refused rather than allowed.
- Routed
- The matrix produced an approval sequence and the record follows it.
- Blocked
- The record is prohibited or unclassifiable, and the reason is shown on screen.
- Refused
- The action was attempted by someone without the required authority, over their delegation limit, or where the same person would approve their own work.
Risk acceptance and emergency authority
Accepting residual risk is treated as its own decision right, with a separate matrix by residual level, a register of what was accepted, an expiry, and a reassessment prompt when circumstances change. Emergency authority is available for genuine break-glass situations: it is time-bounded, shows a countdown, must be closed out, and appears in the cockpit and calendar while it is live.
Evidence and the continuity pack
Everything above is exportable as the Governance State and Continuity Pack: a branded briefing document plus registers for councils, decisions, actions, exceptions, escalations, authority, and risk acceptance, a calendar file, and content hashes. Choose the last 90 days, the last 12 months, or all time. It is the handover pack for a new governance lead and the starting bundle for an assessor.
What is recorded
Authority grants, revocations, rule changes, approvals, risk acceptances, emergency use, and refused attempts are all written to your organization's activity log and mirrored to the platform log. Refusals are recorded as governance events, not as system faults — an authority working correctly should leave a trail.
