How it works
A guided engagement — from first assessment to operational governance.
You are not dropped into an empty dashboard. Effata works through the engagement in the order an experienced security consultant would structure it, while every decision and approval stays with your team.
Seven steps, one continuous loop — step 07 feeds back into step 01 as new applications appear. For the modules that deliver each step, see the Platform overview.
Step 01 — Assess
Understand the applications entering your organisation
Review AI applications against security, privacy, vendor and governance considerations in the AI Trust Center — before anyone has to decide whether they are allowed.
Outcome
A consistent foundation for application decisions.
Delivered by
AI Trust Center
Your organization's AI intelligence hub - continuously evaluating applications, measuring trust, recommending governance decisions, and maintaining the trusted foundation for secure AI adoption.
179 applications catalogued · 176 fully evaluated · 3 awaiting evaluation
- Discovery Only
Adapta
Adapta · AI Chatbots
Trust Score
3/100
DLP Activities
0/7
Classification: Prohibited
- High Risk
ChatGPT
OpenAI · General Purpose AI
Trust Score
65/100
DLP Activities
6/7
Classification: Restricted / Unassessed
- Medium Risk
NotebookLM
Google · AI Productivity
Trust Score
74/100
DLP Activities
6/7
Classification: Restricted / Unassessed
- Critical Risk
Grok
xAI · AI Assistant
Trust Score
22/100
DLP Activities
3/7
Classification: Prohibited
- Medium Risk
Slack AI
Salesforce · AI Collaboration Assistant
Trust Score
78/100
DLP Activities
7/7
Classification: Restricted / Unassessed
- Critical Risk
Builder.io
Builder.io · AI Productivity
Trust Score
42/100
DLP Activities
5/7
Classification: Prohibited
Step 02 — Govern
Decide how each AI application should be used
Classify every application as Approved & Supported, Approved with Conditions, Restricted / Unassessed, or Prohibited — and define the organisational scope, using business units, groups and application instances where the decision needs to differ across the company.
Outcome
An approved AI application governance register.
Delivered by
Step 03 — Design
Define the controls that apply to each risk
Use the Control Matrix to determine how sensitive information should be handled across every governance category — allow, monitor, alert, coach and acknowledge, coach and require justification, or block.
Outcome
A defensible, risk-based control model.
Delivered by
Step 04 — Engineer
Convert governance into vendor-ready policy architecture
Effata recommends the policy topology, policy order, source and destination criteria, DLP profiles, required objects, coaching messages and implementation dependencies your platform needs.
Outcome
A deployment-ready vendor policy pack.
Delivered by
Meridian Financial Group — Netskope tenant
- P100Prohibited GenAI — Access Blockblock
- P200Secrets & Keys — Global Blockblock
- P210Scoped — Corp Copilot Tenant (Finance)protect
- P300Approved & Supported — Content Protectprotect
- P400Approved w/ Conditions — Content Protectprotect
Step 05 — Deploy
Give engineers a structured implementation plan
Generate the required objects, configuration sequence, deployment checklist, assumptions, dependencies and known limitations — so implementation is a checklist rather than an interpretation exercise.
Outcome
A practical implementation guide for the security engineering team.
Delivered by
Step 06 — Validate
Prove that the controls work as intended
Create test scenarios, expected results, validation criteria and evidence requirements for every relevant governance and risk condition, then record what actually happened.
Outcome
Structured test results and implementation evidence.
Delivered by
Meridian Financial Group — Testing Plan
Sample records
- DLP-001Navigate to a prohibited GenAI app from a test account○ Pending
- DLP-002Upload a file containing Credentials, Keys & Secrets to any GenAI app✓ Passed
- DLP-003Paste an API key into an approved AI chat prompt✓ Passed
- DLP-004Upload a file containing Source Code to Generative AI✓ Passed
- DLP-005Upload a .pem file to a Restricted GenAI app✓ Passed
Step 07 — Operate
Maintain governance as AI usage changes
Review new applications, adjust governance decisions, update controls, and regenerate the implementation artifacts those changes affect — without restarting the engagement.
Outcome
Continuous AI governance rather than a one-time project.
Delivered by
Who decides
Effata structures the work. Your team owns the decisions.
Every recommendation carries the reasoning behind it, the assumptions it relies on, the alternatives that were available, and the platform limitations that apply — so your architects can review and challenge it rather than accept it. Effata does not make changes in your security tenant, and nothing is applied on your behalf.
See the engagement end to end.
Explore a completed sample workspace in read-only mode and follow the same seven steps against real generated output.