Mission and owner
One outcome and one accountable human authority.
Citara Governance defines what AI systems may read, recommend, prepare, execute and publish; which evidence they must use; who approves each action; and how every meaningful change is recorded. The purpose is not to remove people from the loop, but to make human authority explicit, repeatable and scalable.
Direct answer
Citara Governance defines what AI systems may read, recommend, prepare, execute and publish; which evidence they must use; who approves each action; and how every meaningful change is recorded. The purpose is not to remove people from the loop, but to make human authority explicit, repeatable and scalable.
Five levels of authority
The public model explains increasing authority without exposing undocumented internal labels.
| Level | AI may… | Human role |
|---|---|---|
| Observe | Read approved sources and monitor signals | Defines access |
| Recommend | Suggest priorities and next actions | Selects direction |
| Prepare | Produce drafts, plans and proposed changes | Reviews and edits |
| Execute | Run approved workflows within boundaries | Authorizes scope |
| Publish | Release content or actions externally | Gives final approval where required |
Governance by design
Every workflow starts with a defined mission, accountable owner, approved sources, permitted and excluded actions, decision thresholds, escalation rules, review cadence and release criteria.
One outcome and one accountable human authority.
Permitted, excluded and escalated actions are explicit.
Evidence, quality and approval conditions are defined before execution.
Evidence and provenance
Traceable fields prevent unsupported wording from becoming durable company truth.
The statement and the evidence supporting it.
Source date, responsible owner and market or language.
Approval status, valid-until date, last use and associated workflow.
Approval workflow
The same visible path applies with different evidence and authority requirements.
Validate source-backed claims, brand fit and publication approval.
Confirm product context, account relevance and commercial authority.
Check offer, policy, evidence and release boundaries before activation.
Data and permissions
Source-specific permissions, restricted knowledge domains, separation of public and internal context, role-based approval, reversible actions where possible and activity logs reduce uncontrolled access.
Each workflow receives only the sources and actions it needs.
Public, internal and restricted domains remain distinct.
Meaningful decisions, approvals and releases remain inspectable.
Governance by product
The product level reflects the number of workflows, teams, permissions and release surfaces—not a claim of universal legal compliance.
| Product | Typical governance depth |
|---|---|
| Starter | Content and workflow approvals |
| Growth | Cross-channel workflows and bounded agents |
| Enterprise | Role-based permissions, Company Intelligence governance and cross-functional release controls |
Frequently asked questions
The rules, evidence, permissions, owners and approval paths that define how an AI agent may access information and act.
Actions involving publication, production systems, external claims, money, customer data or other sensitive consequences require appropriate authority.
Only when an explicitly approved workflow and release authority permit it; important external releases remain human-directed.
Claims are connected to identified sources, dates, ownership and approval status.
Material recommendations, approvals, releases and changes retain an inspectable history.
Yes. Access and approval can be role- and domain-specific.
Through source dates, validity windows, review cycles and explicit supersession.
Recommendations and drafts can be rejected; executed actions are reversible where the connected system technically supports reversal.