CITARA OS · HUMAN-DIRECTED GOVERNANCE

Human authority at every important AI decision.

Citara Governance defines what AI systems may read, recommend, prepare, execute and publish; which evidence they must use; who approves each action; and how every meaningful change is recorded. The purpose is not to remove people from the loop, but to make human authority explicit, repeatable and scalable.

Direct answer

Citara Governance defines what AI systems may read, recommend, prepare, execute and publish; which evidence they must use; who approves each action; and how every meaningful change is recorded. The purpose is not to remove people from the loop, but to make human authority explicit, repeatable and scalable.

Five levels of authority

Clear authority is easier to scale than vague supervision.

The public model explains increasing authority without exposing undocumented internal labels.

LevelAI may…Human role
ObserveRead approved sources and monitor signalsDefines access
RecommendSuggest priorities and next actionsSelects direction
PrepareProduce drafts, plans and proposed changesReviews and edits
ExecuteRun approved workflows within boundariesAuthorizes scope
PublishRelease content or actions externallyGives final approval where required

Governance by design

Governance begins before an agent starts working.

Every workflow starts with a defined mission, accountable owner, approved sources, permitted and excluded actions, decision thresholds, escalation rules, review cadence and release criteria.

01

Mission and owner

One outcome and one accountable human authority.

02

Action boundaries

Permitted, excluded and escalated actions are explicit.

03

Release criteria

Evidence, quality and approval conditions are defined before execution.

Evidence and provenance

Every important claim has a source, owner and status.

Traceable fields prevent unsupported wording from becoming durable company truth.

01

Claim and source

The statement and the evidence supporting it.

02

Date and owner

Source date, responsible owner and market or language.

03

Status and validity

Approval status, valid-until date, last use and associated workflow.

Approval workflow

Draft → Validate → Review → Approve → Release → Monitor

The same visible path applies with different evidence and authority requirements.

01

AI Visibility page update

Validate source-backed claims, brand fit and publication approval.

02

Sales-agent recommendation

Confirm product context, account relevance and commercial authority.

03

Buying-agent product information

Check offer, policy, evidence and release boundaries before activation.

Data and permissions

Least privilege, explicit separation and traceable action.

Source-specific permissions, restricted knowledge domains, separation of public and internal context, role-based approval, reversible actions where possible and activity logs reduce uncontrolled access.

01

Least privilege

Each workflow receives only the sources and actions it needs.

02

Context separation

Public, internal and restricted domains remain distinct.

03

Traceability

Meaningful decisions, approvals and releases remain inspectable.

Governance by product

Governance depth grows with operating complexity.

The product level reflects the number of workflows, teams, permissions and release surfaces—not a claim of universal legal compliance.

ProductTypical governance depth
StarterContent and workflow approvals
GrowthCross-channel workflows and bounded agents
EnterpriseRole-based permissions, Company Intelligence governance and cross-functional release controls

Frequently asked questions

Direct answers before the next step.

What is AI agent governance?+

The rules, evidence, permissions, owners and approval paths that define how an AI agent may access information and act.

Which AI actions require human approval?+

Actions involving publication, production systems, external claims, money, customer data or other sensitive consequences require appropriate authority.

Can Citara agents publish without permission?+

Only when an explicitly approved workflow and release authority permit it; important external releases remain human-directed.

How are sources verified?+

Claims are connected to identified sources, dates, ownership and approval status.

How are decisions recorded?+

Material recommendations, approvals, releases and changes retain an inspectable history.

Can access differ by department?+

Yes. Access and approval can be role- and domain-specific.

How is outdated information handled?+

Through source dates, validity windows, review cycles and explicit supersession.

Can an AI action be rejected or reversed?+

Recommendations and drafts can be rejected; executed actions are reversible where the connected system technically supports reversal.