The AI governance model

Governance exceptions with dollars attached, the team-first privacy model, correlational-not-causal reporting and the audit trail.

Updated 12 July 2026

Governance in EngLedger means governing the spend, not the people. The model has four parts: ranked exceptions that turn spend patterns into management decisions, a privacy stance that starts at org and team level, a reporting posture that labels findings for what they are, and an audit trail underneath it all. This page explains each, including what the numbers deliberately don't claim.

Governance exceptions

Rather than walls of charts, the governance overview ranks a short list of exceptions (issues worth management attention this period, each with its size stated and a next action linked):

ExceptionWhat it detectsStated as
Model mixHigh-cost models carrying work cheaper ones couldEstimated monthly headroom in your currency
Reliability dragSpend burned on failed requests and retriesThe error rate behind the burn
Shallow cache reuseRepeated work that isn't being cachedThe cache hit rate and what better reuse is worth
Spend not tied to deliveryThe unattributed and unticketed remainderThe amount not linked to tickets

Each exception links to the report that explains it (model breakdown, API health, cache ROI, or the ticket attribution view) and a next best action strip states the estimated monthly headroom if high-cost requests shift to more efficient models.

The headroom figures are estimates and presented as such: model-mix headroom assumes most high-cost spend could shift to cheaper equivalents, which is a starting point for a review, not a guaranteed saving.

The privacy model

The stance is team-level by design:

  • Org and team views come first. The governance report suite is an admin surface: spend, adoption, model mix and exceptions at organisation and team level.
  • Individual detail is opt-in and coaching-framed. Per-person value estimates sit behind an explicit control and carry their own label: an estimate from an org-wide assumption, not a productivity or performance measure.
  • People can see their own usage. Each person has access to their own AI usage detail, the same detail the org holds about them, not a redacted version.

The posture fits works-council and privacy-regime obligations rather than fighting them, and it's why the notifications EngLedger sends your people are action-focused and neutral. The full stance is on the AI Governance overview and the security page.

Honest, correlational reporting

Governance findings are labelled for what they are, and the labels are in the reports themselves, not just the marketing:

  • Measured leads. Observed comparisons on your own data (AI-touched work against the rest of your delivery) front the value story.
  • Correlation is named. Where AI-touched tickets close faster, the report says exactly that: an observed correlation for this period, not a measured speed-up. People self-select when to reach for AI, and the reporting refuses to launder that into causation.
  • Modelled stays behind a toggle. Assumption-based estimates exist but are demoted, labelled as modelled, and never headline a report.
  • Uncertainty is surfaced. When session-intent classification is uncertain, the report says the value mix should be read with care rather than presenting it at full confidence.

A number you can defend beats a bigger one you can't, the same principle the effort model applies to hours and cost.

The audit trail

Governance rests on an append-only activity log: entries record who did what, when, from where, and (for sensitive actions) a required reason. Report exports are logged, spend-control override actions are append-only with the reason preserved, and related change histories (rates, classification, period locks) carry the same who/when/why discipline. EngLedger ingests no source code and connects to your tools read-only, so the trail covers everything the product can actually do.

Where to go next