Skip to main content
EEffata

How it works

A guided engagement — from first assessment to operational governance.

You are not dropped into an empty dashboard. Effata works through the engagement in the order an experienced security consultant would structure it, while every decision and approval stays with your team.

  1. 01Assess
  2. 02Govern
  3. 03Design
  4. 04Engineer
  5. 05Deploy
  6. 06Validate
  7. 07Operate

Seven steps, one continuous loop — step 07 feeds back into step 01 as new applications appear. For the modules that deliver each step, see the Platform overview.

Step 01 — Assess

Understand the applications entering your organisation

Review AI applications against security, privacy, vendor and governance considerations in the AI Trust Center — before anyone has to decide whether they are allowed.

Outcome

A consistent foundation for application decisions.

ai-trust-center — sampleLive
GenAI ControlsAI Trust Center
Meridian Financial Group

AI Trust Center

Your organization's AI intelligence hub - continuously evaluating applications, measuring trust, recommending governance decisions, and maintaining the trusted foundation for secure AI adoption.

179 applications catalogued · 176 fully evaluated · 3 awaiting evaluation

Search by name, vendor, or category
+ Add Filter
  • Adapta

    Adapta · AI Chatbots

    Discovery Only

    Trust Score

    3/100

    DLP Activities

    0/7

    Classification: Prohibited

  • ChatGPT

    OpenAI · General Purpose AI

    High Risk

    Trust Score

    65/100

    DLP Activities

    6/7

    Classification: Restricted / Unassessed

  • NotebookLM

    Google · AI Productivity

    Medium Risk

    Trust Score

    74/100

    DLP Activities

    6/7

    Classification: Restricted / Unassessed

  • Grok

    xAI · AI Assistant

    Critical Risk

    Trust Score

    22/100

    DLP Activities

    3/7

    Classification: Prohibited

  • Slack AI

    Salesforce · AI Collaboration Assistant

    Medium Risk

    Trust Score

    78/100

    DLP Activities

    7/7

    Classification: Restricted / Unassessed

  • Builder.io

    Builder.io · AI Productivity

    Critical Risk

    Trust Score

    42/100

    DLP Activities

    5/7

    Classification: Prohibited

Step 02 — Govern

Decide how each AI application should be used

Classify every application as Approved & Supported, Approved with Conditions, Restricted / Unassessed, or Prohibited — and define the organisational scope, using business units, groups and application instances where the decision needs to differ across the company.

Outcome

An approved AI application governance register.

Delivered by

Step 03 — Design

Define the controls that apply to each risk

Use the Control Matrix to determine how sensitive information should be handled across every governance category — allow, monitor, alert, coach and acknowledge, coach and require justification, or block.

Outcome

A defensible, risk-based control model.

Delivered by

Step 04 — Engineer

Convert governance into vendor-ready policy architecture

Effata recommends the policy topology, policy order, source and destination criteria, DLP profiles, required objects, coaching messages and implementation dependencies your platform needs.

Outcome

A deployment-ready vendor policy pack.

netskope-policy-pack — sampleLive

Meridian Financial Group — Netskope tenant

  • P100Prohibited GenAI — Access Blockblock
  • P200Secrets & Keys — Global Blockblock
  • P210Scoped — Corp Copilot Tenant (Finance)protect
  • P300Approved & Supported — Content Protectprotect
  • P400Approved w/ Conditions — Content Protectprotect

Step 05 — Deploy

Give engineers a structured implementation plan

Generate the required objects, configuration sequence, deployment checklist, assumptions, dependencies and known limitations — so implementation is a checklist rather than an interpretation exercise.

Outcome

A practical implementation guide for the security engineering team.

Step 06 — Validate

Prove that the controls work as intended

Create test scenarios, expected results, validation criteria and evidence requirements for every relevant governance and risk condition, then record what actually happened.

Outcome

Structured test results and implementation evidence.

testing-evidence — sampleLive

Meridian Financial Group — Testing Plan

35/35must-pass
8/11recommended

Sample records

  • DLP-001Navigate to a prohibited GenAI app from a test account○ Pending
  • DLP-002Upload a file containing Credentials, Keys & Secrets to any GenAI app✓ Passed
  • DLP-003Paste an API key into an approved AI chat prompt✓ Passed
  • DLP-004Upload a file containing Source Code to Generative AI✓ Passed
  • DLP-005Upload a .pem file to a Restricted GenAI app✓ Passed

Step 07 — Operate

Maintain governance as AI usage changes

Review new applications, adjust governance decisions, update controls, and regenerate the implementation artifacts those changes affect — without restarting the engagement.

Outcome

Continuous AI governance rather than a one-time project.

Who decides

Effata structures the work. Your team owns the decisions.

Every recommendation carries the reasoning behind it, the assumptions it relies on, the alternatives that were available, and the platform limitations that apply — so your architects can review and challenge it rather than accept it. Effata does not make changes in your security tenant, and nothing is applied on your behalf.

See the engagement end to end.

Explore a completed sample workspace in read-only mode and follow the same seven steps against real generated output.