Governance framework & guidance

Roles and responsibilities

Everyday contributors should be able to disclose AI activity using ordinary business language. Governance Managers oversee assessments, decisions, actions, changes and reporting. Specialist reviewers provide privacy, security, legal, technical or supplier input where required. Executives and directors consume concise governance and strategy information rather than operating the system day to day.

Administration is not governance authority

The ability to invite a user, maintain organisation settings or manage access does not automatically give someone authority to approve an AI Use, accept a Risk or make another governance decision. Swell keeps system permissions and accountable governance decisions distinct.

Support occasional, non-specialist users

Contributors should not need to research model architecture or legal terminology before using Swell. Use I don't know, Needs confirmation, drafts, delegation and specialist routing where information belongs with another person.

Security and auditability

Access, tenant separation, permissions, versioning and audit history are part of the governance design. Use named user access rather than shared accounts and assign privileged roles deliberately. Governance decisions should retain who acted, what they decided, when they decided it and the context that supported the decision.

Using Swell AI

Recommended first steps

  1. Confirm your organisation details and primary governance owner.
  2. Set up the business areas used to describe where AI activity occurs.
  3. Invite the small group of users who will administer governance.
  4. Assign roles according to actual responsibility.
  5. Begin AI discovery or add known AI Uses.
  6. Reuse known supplier and product information rather than asking contributors repeatedly.

Inviting users

Invite people who have a genuine role in the process. Avoid creating broad privileged access merely for convenience. If a contributor only needs to disclose an AI Use or answer assigned questions, give them the minimum access required.

What should we do next?

Once the organisation structure and governance owners are in place, start with visibility. Run a discovery campaign or enter the known AI Uses, then work through Register → Assess → Control → Approve → Monitor → Review.