Knowledge

How should an enterprise govern employees using unapproved AI tools with corporate credentials?

The control question is which effects AI systems may produce on behalf of this employee: identity, delegated authority, resource boundary, permitted actions, and evidence. Banning every tool will not close the gap.

Public educational material.

Evidence baseline

Hood's analysis distinguishes identity from current authorization. A governed action should establish the actor, the exact requested effect, the affected resource, the policy in force, and the evidence retained after execution.

These sources establish surrounding security context; Hood's effect-authority model is Hood's analysis. No endorsement or partnership is implied. Reviewed September 2, 2026.