Skip to main content
EEffata

Deliverables

See what your team receives — not only what the platform does.

Review the governance, engineering, deployment, testing and reporting artifacts Effata produces throughout an AI governance engagement, shown for one sample organisation: Meridian Financial Group.

Illustrative sample data — not a real customerClick any preview to expand it

For CISOs and security leadership

Posture, readiness, and the decisions still waiting on someone.

Leadership Presentation

A leadership-ready summary — posture score, top gaps, and the roadmap — built from the same workflow, no separate deck to assemble.

Primary audience
Leadership
Format
PPTX
ciso-presentation — sampleLive⤢ Expand

Prepared for Meridian Financial Group

GenAI DLP Posture Score

62/95

Level 3 — Defined
Channel Coverage68%
Enforcement45%
Governance73%
Tool Readiness58%

Also produced

  • Executive Governance Report

    PDF

    Where the AI governance programme stands, in language a board paper can quote.

  • AI Risk & Posture Summary

    PDF

    Concentrations of risk across the application estate, and what is driving them.

  • Readiness Assessment

    PDF

    How close the programme is to enforcing its own policy, and what is still missing.

  • Key Decisions & Open Risks

    PDF

    The decisions still waiting on a human, with the risk of leaving each one open.

  • Implementation Progress Report

    PDF

    Deployment and validation status against the plan that was signed off.

For governance and risk teams

The register of what was decided, by whom, and on what basis.

AI Trust Center

A live trust center for evaluated AI applications — trust score, risk rating, DLP activities, and recommended governance classification for each app.

Primary audience
Security & GenAI governance teams
Format
Web app
ai-trust-center — sampleLive⤢ Expand
GenAI ControlsAI Trust Center
Meridian Financial Group

AI Trust Center

Your organization's AI intelligence hub - continuously evaluating applications, measuring trust, recommending governance decisions, and maintaining the trusted foundation for secure AI adoption.

179 applications catalogued · 176 fully evaluated · 3 awaiting evaluation

Search by name, vendor, or category
+ Add Filter
  • Adapta

    Adapta · AI Chatbots

    Discovery Only

    Trust Score

    3/100

    DLP Activities

    0/7

    Classification: Prohibited

  • ChatGPT

    OpenAI · General Purpose AI

    High Risk

    Trust Score

    65/100

    DLP Activities

    6/7

    Classification: Restricted / Unassessed

  • NotebookLM

    Google · AI Productivity

    Medium Risk

    Trust Score

    74/100

    DLP Activities

    6/7

    Classification: Restricted / Unassessed

  • Grok

    xAI · AI Assistant

    Critical Risk

    Trust Score

    22/100

    DLP Activities

    3/7

    Classification: Prohibited

  • Slack AI

    Salesforce · AI Collaboration Assistant

    Medium Risk

    Trust Score

    78/100

    DLP Activities

    7/7

    Classification: Restricted / Unassessed

  • Builder.io

    Builder.io · AI Productivity

    Critical Risk

    Trust Score

    42/100

    DLP Activities

    5/7

    Classification: Prohibited

AI Governance

Your GenAI apps grouped into governance categories, with in-scope status and the rationale behind each classification.

Primary audience
Governance and security
Format
XLSX
app-governance — sampleLive⤢ Expand

Meridian Financial Group — AI Governance

  • Azure AI Foundry

    AI Analytics

    Medium Risk
  • GitHub Copilot

    AI Code Assistant

    Medium Risk
  • Microsoft Copilot (M365)

    Enterprise AI Assistant

    Medium Risk
  • Articulate

    AI Writing

    Medium Risk
  • Slack AI

    AI Collaboration Assistant

    Medium Risk
  • Synthesia

    AI Video

    Medium Risk
  • Adobe Express

    Image Generator

    High Risk
  • Adobe Firefly

    Image Generator

    Medium Risk
  • Amazon Q

    AI Assistant

    High Risk
  • Arena AI

    AI Assistant

    High Risk
  • Canva AI

    AI Productivity

    High Risk
  • ChatGPT

    General Purpose AI

    High Risk
  • Claude

    General Purpose AI

    High Risk
  • Adapta

    AI Assistant

    Discovery Only
  • AgentGPT

    AI Assistant

    Critical Risk
  • AIApply

    AI Productivity

    Critical Risk
  • Aible

    AI Analytics

    Critical Risk
  • DeepSeek

    AI Assistant

    Critical Risk
  • Devin

    Code Assistant

    Critical Risk
  • ElevenLabs

    AI Communication

    Critical Risk

Also produced

  • Governance Framework

    PDF

    How applications are reviewed, categorised, approved, restricted and re-reviewed.

  • Risk Assessment Records

    XLSX

    The evidence behind each application's risk rating, kept with the decision it informed.

  • Decision Rationale

    XLSX

    Why each application landed in its category — the answer to "who approved this, and on what basis?"

  • Review & Approval History

    XLSX

    Who changed a governance decision, when, and what it was before.

  • Exception Register

    XLSX

    Approved deviations from the standard control model, with owner and expiry.

For security architects

The control model and the design documents that have to survive review.

Control Matrix

Risk families against governance categories — each cell an explicit DLP action your team chose, from Allow to Block.

Primary audience
Governance and security
Format
XLSX/PDF
control-matrix — sampleLive⤢ Expand

Meridian Financial Group — Control Matrix

Risk familyApprovedConditionalRestricted
Credentials & SecretsBlockBlockBlock
Regulated DataCoachCoach + Just.Block
Source CodeCoachBlockBlock
Intellectual PropertyAlertCoachBlock

Policy Blueprints

A vendor-neutral translation of your matrix: policy intent, grouping, source/destination logic, data profiles, activities, and expected actions.

Primary audience
DLP architect / engineer
Format
PDF
policy-blueprint — sampleLive⤢ Expand

Meridian Financial Group — Policy Blueprints

  • Block secrets everywhereBlock

    activities: upload · prompt

  • Protect regulated dataCoach

    activities: upload

  • Coach on customer dataCoach

    activities: prompt

  • Alert on source code uploadsAlert

    activities: upload

HLD / LLD

Design documents your reviewers recognize: a high-level design for stakeholders and a low-level build sheet for the engineer configuring the tenant.

Primary audience
Architect / DLP engineer
Format
PDF
hld-lld-summary — sampleLive⤢ Expand

HLD — Meridian Financial Group

  1. 01Executive Summary
  2. 02Governance Model & App Categories
  3. 03Policy Architecture
  4. 04Coaching & User Experience
  5. 05Risks & Mitigations
  6. 06Rollout Strategy

LLD — Meridian Financial Group

  1. 01Policy Build Sheet
  2. 02Policy Order & Evaluation
  3. 03DLP Profile Mapping
  4. 04Required Objects
  5. 05Deployment Ledger
  6. 06Validation Test Plan

Also produced

  • Platform Boundary Document

    PDF

    What the security platform can and cannot enforce, stated before the design depends on it.

  • Assumptions & Limitations

    PDF

    Every assumption the recommendation rests on, and the known platform limits that constrain it.

  • Required Integration Model

    PDF

    The identity, logging and tenant integrations the design expects to be in place.

For DLP and CASB engineers

Everything needed to build the policies in the console without guessing.

Netskope Policy Pack

The recommended Netskope policy set in evaluation order — access blocks, global secrets protection, per-tier content controls, and a fallback for the unassessed long tail.

Primary audience
DLP engineer
Format
DOCX/PDF
netskope-policy-pack — sampleLive⤢ Expand

Meridian Financial Group — Netskope tenant

  • P100Prohibited GenAI — Access Blockblock
  • P200Secrets & Keys — Global Blockblock
  • P210Scoped — Corp Copilot Tenant (Finance)protect
  • P300Approved & Supported — Content Protectprotect
  • P400Approved w/ Conditions — Content Protectprotect

Deployment Checklist

Every step to stand the pack up correctly — DLP profiles, app objects, notification templates, identity, and validation — tracked to completion.

Primary audience
DLP engineer
Format
XLSX/PDF
deployment-checklist — sampleLive⤢ Expand

Meridian Financial Group — deployment tracker

  • Create DLP Profiles43/43
  • Confirm App Objects5/5
  • Verify User Identity3/3
  • Notification Templates8/12
  • Validation Checks2/4

Also produced

  • DLP Profile Requirements

    XLSX

    Which DLP profile backs each content rule, and the detection it has to perform.

  • Policy Order

    XLSX

    Evaluation sequence and continue/stop behaviour per policy — the part that silently breaks enforcement when it's wrong.

  • Required Object List

    XLSX

    App tags, instances, groups, URL lists and templates that must exist before a policy will save.

  • Notification Templates

    DOCX

    The coaching, justification and block messages end users actually see.

For testing and operations

Proof that the controls behave as designed, and a clean handover.

Testing Plan

Test scenarios mapped to each policy, split into must-pass and good-to-verify, with expected outcomes ready to record against.

Primary audience
Tester / project team
Format
XLSX
testing-plan — sampleLive⤢ Expand

Meridian Financial Group — Testing Plan

35/35must-pass
8/11recommended

Sample records

  • DLP-001Navigate to a prohibited GenAI app from a test account○ Pending
  • DLP-002Upload a file containing Credentials, Keys & Secrets to any GenAI app✓ Passed
  • DLP-003Paste an API key into an approved AI chat prompt✓ Passed
  • DLP-004Upload a file containing Source Code to Generative AI✓ Passed
  • DLP-005Upload a .pem file to a Restricted GenAI app✓ Passed

Evidence Report

Captured results per test — expected vs actual, pass/fail, tester, and date — the proof security leaders and auditors ask for.

Primary audience
Auditor / security leader
Format
PDF
evidence-report — sampleLive⤢ Expand

Meridian Financial Group — GenAI DLP Evidence Report

35/35must-pass
8/11recommended
  • DLP-001Prohibited GenAI app accessPassed
  • DLP-002Credentials upload blockedPassed
  • DLP-003Source code upload blockedPassed
  • DLP-004Regulated data upload blockedPassed

Also produced

  • Test Data Requirements

    XLSX

    What each scenario needs to exercise a control honestly, without production data.

  • Expected Outcomes

    XLSX

    The result each test must produce for the control to count as working.

  • Evidence Checklist

    XLSX

    What has to be captured per test for the result to stand up in an audit.

  • Operational Handover

    PDF

    What the run team inherits: exceptions, review cadence, and the things to watch.

Metadata

Every preview, at a glance.

OutputAudiencePrimary readerFormat
AI Trust CenterGovernance & riskSecurity & GenAI governance teamsWeb app
AI GovernanceGovernance & riskGovernance and securityXLSX
Control MatrixArchitectsGovernance and securityXLSX/PDF
Policy BlueprintsArchitectsDLP architect / engineerPDF
Netskope Policy PackEngineersDLP engineerDOCX/PDF
Deployment ChecklistEngineersDLP engineerXLSX/PDF
Testing PlanTesting & opsTester / project teamXLSX
Evidence ReportTesting & opsAuditor / security leaderPDF
HLD / LLDArchitectsArchitect / DLP engineerPDF
Leadership PresentationLeadershipLeadershipPPTX

Take it with you

Sample Policy Pack

The Control Matrix, Netskope Policy Pack, Testing Plan, Evidence Report, and Leadership Presentation for Meridian Financial Group, bundled into one document — illustrative sample data, structured exactly like what Effata generates for your own environment.

Next sample

Sample Governance Pack

A second downloadable sample covering the governance side of an engagement — the application register, governance framework, decision rationale and exception register — in the same format as the policy pack above.

In preparation

Want these generated for your environment?

Customers receive every artifact above, built from their own governance decisions.