Security and Governance
Enterprise AI security covers more than authentication and content filtering. It also defines which data an agent can retrieve, which tools it can execute, when a person must approve an action, which model and region process a request, and what evidence remains after an incident.
Use this section to design those controls before production launch and to review them as the deployment changes.
Start Here
| If you need to | Read |
|---|---|
| Identify AI-specific attack paths | AI Threat Model |
| Protect agents from malicious instructions | Prompt Injection |
| Control external actions | Tool Governance and Human Approval |
| Restrict company knowledge | Data Access and RAG |
| Prepare evidence and response procedures | Auditability and Incident Response |
| Select approved models and processing locations | Model Governance and Model Deployment and Data Residency |
| Review an EU deployment | EU AI Act Readiness |
| Approve a production launch | AI Go-Live Checklist |
Product Controls and Operating Controls
Siesta AI provides product controls such as roles, teams, sharing policies, connection governance, function confirmation, Prompt Shield, content safety, token limits, Tool Executions, and Audit Log. Those controls still need an operating model: named owners, data classification, approval rules, incident procedures, review cadence, and evidence retention.
For product configuration, also use: