AIndex
Download free

Governance · For: lead

CTOs and CISOs need to know which agent requested which context and whether sensitive paths were protected.

Governed Context applies repo/team permissions, path exclusions, redaction and audit logging before context reaches an agent.

$ aindex governance audit --agent Codex --team security --json && aindex governance export --limit 500 --output governance-audit-export.json --json

subject
policy_id
allowed_items
denied_items
redacted_items
hash_chain_valid
raw_payloads_included
no_cloud_source

Command

Governed Context

RBAC, redaction, audit logs and policy filters for agent context.

CLI

aindex governance audit --agent Codex --team security --json && aindex governance export --limit 500 --output governance-audit-export.json --json

MCP

status detail=governance

Example output
  • subject
  • policy_id
  • allowed_items
  • denied_items
  • redacted_items
  • hash_chain_valid
  • raw_payloads_included
  • no_cloud_source

What the Brain does automatically

The Brain fires this workflow for you.

Security can prove which agent asked for which context and which paths were denied or redacted.

On demand

Run when you need it

This workflow is not auto-triggered by the Brain yet; run it explicitly with the command above or its MCP action.

Not measuredProof
Not measuredNo public benchmark covers this workflow yet — the proof is the live command output above, not a positioning claim.
Source
AvailableRuntime feature status · 0 evidence item(s). Metadata-only; no raw source included.

Required tier

Where this becomes commercially available.

Gives CISOs an audit trail of which agent requested which context and whether sensitive paths were redacted.

Enterprise · Custom

Foundation

Visible as a product workflow and pilot proof target; do not treat as fully shipped enterprise automation yet.

Buyer grade

Foundation

Names the parity workflow and proof path without claiming full Sourcegraph-class depth.

Visible in
  • Governance audit
  • Dashboard audit
  • Enterprise policy
  • Monitors
  • Pilot report

This workflow stays discoverable across setup, CLI, MCP status, docs, dashboard and pricing — never a hidden command.

Feature visibility checklist

Buyer-visible names covered by Governed Context.

This keeps grouped product names discoverable without claiming a separate maturity level from the underlying workflow.

Governed ContextFoundation

Governed Context

RBAC, redaction, denied paths and audit exports stay visible.

Surface
Governance audit, Enterprise policy, monitors, pilot report
Buyer-safe status
Foundation · Foundation
Runtime
preview only

Governance

Enterprise context controls without a hosted source index.

No-cloud source default

Request Enterprise demoSee pilot proof