Deliverables
See what your team receives — not only what the platform does.
Review the governance, engineering, deployment, testing and reporting artifacts Effata produces throughout an AI governance engagement, shown for one sample organisation: Meridian Financial Group.
For CISOs and security leadership
Posture, readiness, and the decisions still waiting on someone.
Leadership Presentation
A leadership-ready summary — posture score, top gaps, and the roadmap — built from the same workflow, no separate deck to assemble.
- Primary audience
- Leadership
- Format
- PPTX
Prepared for Meridian Financial Group
GenAI DLP Posture Score
62/95
Also produced
Executive Governance Report
PDFWhere the AI governance programme stands, in language a board paper can quote.
AI Risk & Posture Summary
PDFConcentrations of risk across the application estate, and what is driving them.
Readiness Assessment
PDFHow close the programme is to enforcing its own policy, and what is still missing.
Key Decisions & Open Risks
PDFThe decisions still waiting on a human, with the risk of leaving each one open.
Implementation Progress Report
PDFDeployment and validation status against the plan that was signed off.
For governance and risk teams
The register of what was decided, by whom, and on what basis.
AI Trust Center
A live trust center for evaluated AI applications — trust score, risk rating, DLP activities, and recommended governance classification for each app.
- Primary audience
- Security & GenAI governance teams
- Format
- Web app
AI Trust Center
Your organization's AI intelligence hub - continuously evaluating applications, measuring trust, recommending governance decisions, and maintaining the trusted foundation for secure AI adoption.
179 applications catalogued · 176 fully evaluated · 3 awaiting evaluation
- Discovery Only
Adapta
Adapta · AI Chatbots
Trust Score
3/100
DLP Activities
0/7
Classification: Prohibited
- High Risk
ChatGPT
OpenAI · General Purpose AI
Trust Score
65/100
DLP Activities
6/7
Classification: Restricted / Unassessed
- Medium Risk
NotebookLM
Google · AI Productivity
Trust Score
74/100
DLP Activities
6/7
Classification: Restricted / Unassessed
- Critical Risk
Grok
xAI · AI Assistant
Trust Score
22/100
DLP Activities
3/7
Classification: Prohibited
- Medium Risk
Slack AI
Salesforce · AI Collaboration Assistant
Trust Score
78/100
DLP Activities
7/7
Classification: Restricted / Unassessed
- Critical Risk
Builder.io
Builder.io · AI Productivity
Trust Score
42/100
DLP Activities
5/7
Classification: Prohibited
AI Governance
Your GenAI apps grouped into governance categories, with in-scope status and the rationale behind each classification.
- Primary audience
- Governance and security
- Format
- XLSX
Meridian Financial Group — AI Governance
- Medium Risk
Azure AI Foundry
AI Analytics
- Medium Risk
GitHub Copilot
AI Code Assistant
- Medium Risk
Microsoft Copilot (M365)
Enterprise AI Assistant
- Medium Risk
Articulate
AI Writing
- Medium Risk
Slack AI
AI Collaboration Assistant
- Medium Risk
Synthesia
AI Video
- High Risk
Adobe Express
Image Generator
- Medium Risk
Adobe Firefly
Image Generator
- High Risk
Amazon Q
AI Assistant
- High Risk
Arena AI
AI Assistant
- High Risk
Canva AI
AI Productivity
- High Risk
ChatGPT
General Purpose AI
- High Risk
Claude
General Purpose AI
- Discovery Only
Adapta
AI Assistant
- Critical Risk
AgentGPT
AI Assistant
- Critical Risk
AIApply
AI Productivity
- Critical Risk
Aible
AI Analytics
- Critical Risk
DeepSeek
AI Assistant
- Critical Risk
Devin
Code Assistant
- Critical Risk
ElevenLabs
AI Communication
Also produced
Governance Framework
PDFHow applications are reviewed, categorised, approved, restricted and re-reviewed.
Risk Assessment Records
XLSXThe evidence behind each application's risk rating, kept with the decision it informed.
Decision Rationale
XLSXWhy each application landed in its category — the answer to "who approved this, and on what basis?"
Review & Approval History
XLSXWho changed a governance decision, when, and what it was before.
Exception Register
XLSXApproved deviations from the standard control model, with owner and expiry.
For security architects
The control model and the design documents that have to survive review.
Control Matrix
Risk families against governance categories — each cell an explicit DLP action your team chose, from Allow to Block.
- Primary audience
- Governance and security
- Format
- XLSX/PDF
Meridian Financial Group — Control Matrix
| Risk family | Approved | Conditional | Restricted |
|---|---|---|---|
| Credentials & Secrets | Block | Block | Block |
| Regulated Data | Coach | Coach + Just. | Block |
| Source Code | Coach | Block | Block |
| Intellectual Property | Alert | Coach | Block |
Policy Blueprints
A vendor-neutral translation of your matrix: policy intent, grouping, source/destination logic, data profiles, activities, and expected actions.
- Primary audience
- DLP architect / engineer
- Format
Meridian Financial Group — Policy Blueprints
- Block secrets everywhereBlock
activities: upload · prompt
- Protect regulated dataCoach
activities: upload
- Coach on customer dataCoach
activities: prompt
- Alert on source code uploadsAlert
activities: upload
HLD / LLD
Design documents your reviewers recognize: a high-level design for stakeholders and a low-level build sheet for the engineer configuring the tenant.
- Primary audience
- Architect / DLP engineer
- Format
HLD — Meridian Financial Group
- 01Executive Summary
- 02Governance Model & App Categories
- 03Policy Architecture
- 04Coaching & User Experience
- 05Risks & Mitigations
- 06Rollout Strategy
LLD — Meridian Financial Group
- 01Policy Build Sheet
- 02Policy Order & Evaluation
- 03DLP Profile Mapping
- 04Required Objects
- 05Deployment Ledger
- 06Validation Test Plan
Also produced
Platform Boundary Document
PDFWhat the security platform can and cannot enforce, stated before the design depends on it.
Assumptions & Limitations
PDFEvery assumption the recommendation rests on, and the known platform limits that constrain it.
Required Integration Model
PDFThe identity, logging and tenant integrations the design expects to be in place.
For DLP and CASB engineers
Everything needed to build the policies in the console without guessing.
Netskope Policy Pack
The recommended Netskope policy set in evaluation order — access blocks, global secrets protection, per-tier content controls, and a fallback for the unassessed long tail.
- Primary audience
- DLP engineer
- Format
- DOCX/PDF
Meridian Financial Group — Netskope tenant
- P100Prohibited GenAI — Access Blockblock
- P200Secrets & Keys — Global Blockblock
- P210Scoped — Corp Copilot Tenant (Finance)protect
- P300Approved & Supported — Content Protectprotect
- P400Approved w/ Conditions — Content Protectprotect
Deployment Checklist
Every step to stand the pack up correctly — DLP profiles, app objects, notification templates, identity, and validation — tracked to completion.
- Primary audience
- DLP engineer
- Format
- XLSX/PDF
Meridian Financial Group — deployment tracker
- Create DLP Profiles43/43
- Confirm App Objects5/5
- Verify User Identity3/3
- Notification Templates8/12
- Validation Checks2/4
Also produced
DLP Profile Requirements
XLSXWhich DLP profile backs each content rule, and the detection it has to perform.
Policy Order
XLSXEvaluation sequence and continue/stop behaviour per policy — the part that silently breaks enforcement when it's wrong.
Required Object List
XLSXApp tags, instances, groups, URL lists and templates that must exist before a policy will save.
Notification Templates
DOCXThe coaching, justification and block messages end users actually see.
For testing and operations
Proof that the controls behave as designed, and a clean handover.
Testing Plan
Test scenarios mapped to each policy, split into must-pass and good-to-verify, with expected outcomes ready to record against.
- Primary audience
- Tester / project team
- Format
- XLSX
Meridian Financial Group — Testing Plan
Sample records
- DLP-001Navigate to a prohibited GenAI app from a test account○ Pending
- DLP-002Upload a file containing Credentials, Keys & Secrets to any GenAI app✓ Passed
- DLP-003Paste an API key into an approved AI chat prompt✓ Passed
- DLP-004Upload a file containing Source Code to Generative AI✓ Passed
- DLP-005Upload a .pem file to a Restricted GenAI app✓ Passed
Evidence Report
Captured results per test — expected vs actual, pass/fail, tester, and date — the proof security leaders and auditors ask for.
- Primary audience
- Auditor / security leader
- Format
Meridian Financial Group — GenAI DLP Evidence Report
- DLP-001Prohibited GenAI app accessPassed
- DLP-002Credentials upload blockedPassed
- DLP-003Source code upload blockedPassed
- DLP-004Regulated data upload blockedPassed
Also produced
Test Data Requirements
XLSXWhat each scenario needs to exercise a control honestly, without production data.
Expected Outcomes
XLSXThe result each test must produce for the control to count as working.
Evidence Checklist
XLSXWhat has to be captured per test for the result to stand up in an audit.
Operational Handover
PDFWhat the run team inherits: exceptions, review cadence, and the things to watch.
Metadata
Every preview, at a glance.
| Output | Audience | Primary reader | Format |
|---|---|---|---|
| AI Trust Center | Governance & risk | Security & GenAI governance teams | Web app |
| AI Governance | Governance & risk | Governance and security | XLSX |
| Control Matrix | Architects | Governance and security | XLSX/PDF |
| Policy Blueprints | Architects | DLP architect / engineer | |
| Netskope Policy Pack | Engineers | DLP engineer | DOCX/PDF |
| Deployment Checklist | Engineers | DLP engineer | XLSX/PDF |
| Testing Plan | Testing & ops | Tester / project team | XLSX |
| Evidence Report | Testing & ops | Auditor / security leader | |
| HLD / LLD | Architects | Architect / DLP engineer | |
| Leadership Presentation | Leadership | Leadership | PPTX |
Take it with you
Sample Policy Pack
The Control Matrix, Netskope Policy Pack, Testing Plan, Evidence Report, and Leadership Presentation for Meridian Financial Group, bundled into one document — illustrative sample data, structured exactly like what Effata generates for your own environment.
Next sample
Sample Governance Pack
A second downloadable sample covering the governance side of an engagement — the application register, governance framework, decision rationale and exception register — in the same format as the policy pack above.
Want these generated for your environment?
Customers receive every artifact above, built from their own governance decisions.