AI Evidence Plane — Architecture Brief
Central authority. Local enforcement. Local evidence.
AI Evidence Plane operationalises Governed AI Execution and the Connected Evidence Graph approach for enterprise agentic AI applications.
The operating principle
Cloud Control distributes approved governance state. Local runtime assurance enforces and proves locally.
Cloud Control is the central authority: identity and tenancy, RBAC, the agent and workflow registry, approvals, bindings, approved execution configuration, configuration packages, fleet posture, health and evidence references. It distributes approved governance state — it is never the evidence vault.
Local runtime assurance runs inside the customer boundary and is the local execution evidence store: Governed AI Execution, local policy enforcement, execution events, governance traces, Connected Evidence Graph relationships, judge and evaluation results, approved-versus-executed assurance and governed remediation.
Hybrid overview
Customer AI Application
Agents, workflows and business logic run inside the customer boundary.
Runtime SDK (in-process)
Resolves approved execution profiles and emits metadata-only execution events.
Optional SecureAI
Inspects AI traffic locally; findings flow into the local evidence store.
Local Runtime Assurance
Governed AI Execution and local execution evidence:
- Approved Execution Profile Resolution
- Local Policy Enforcement
- Execution Events
- Governance Traces
- Connected Evidence Graph Relationships
- Judge Results
- Approved vs Executed Assurance
- Governed Remediation
- Local Execution Evidence
Models · MCP & Tools · Memory & Enterprise Data
Everything the application depends on stays inside the boundary.
Cloud Control (AI Evidence Plane cloud)
Identity, RBAC, registry, approvals, bindings, approved execution configuration and fleet posture. Approved state syncs down; only health, posture and references flow up.
Governed AI Execution
Governed AI Execution manages how approved prompts, models, model configurations, tools, policies, memory, judges, workflow routes and human approval boundaries are applied while an AI application operates.
AI models remain probabilistic, but the operating boundaries around them can be approved, scoped, evaluated and enforced.
The in-process runtime SDK resolves the application, workflow, node and agent scope, resolves or reuses the approved execution profile, applies approved prompt, model, policy, MCP, tool and memory bindings, and emits metadata-only execution events — keys, hashes, IDs and references, never raw prompts or customer payloads.
The Connected Evidence Graph approach
The Connected Evidence Graph approach links governance intent, AI assets, controls, evaluations, approvals, operational decisions, supporting evidence, remediation and business outcomes into a traceable evidence chain.
The Connected Evidence Graph approach can strengthen traceability, accountability and operational assurance. It does not itself guarantee that an AI system is safe, compliant or trustworthy.
Optional SecureAI
Optional SecureAI sits inside the customer boundary, inspects AI traffic locally and sends sensitive-data, policy and anomalous-behaviour findings into the local evidence store. It remains optional: without it, local runtime assurance still governs the application and records local execution evidence.
Evidence custody
Execution evidence stays inside your control. Execution evidence is retained locally inside the customer boundary. Cloud Control shows health, posture and evidence references only.
AI Evidence Plane is a Value Creation Teams product. Canonical product page: https://aep.valuecreationteams.com