GOVERNANCE GUIDE
A guide to consent, authority, data relationships, and traceability in AI-assisted work. For the people accountable for what these systems read, change, and put into circulation. Published by Execute Your Intentions, LLC.
This guide is for the person who answers for the outcome when a decision turns out to have rested on something nobody checked.
AI systems now read organizational knowledge, shape decisions, and produce work that other people treat as settled. The exposure is not mainly that a system returns a wrong answer. It is that information acquires authority without anyone deciding that it should.
It assumes no technical background. It assumes the reader carries the consequence.
An AI system given access to a body of work will read everything in it, act anywhere it is permitted to act, and keep no record of why. That is the default behavior, and it is not a malfunction.
The damage is rarely dramatic. Something private surfaces inside something public. A claim gets repeated until it is treated as settled. A good record is quietly replaced by a worse one. Each is small on its own. They compound, and the moment the record stopped being reliable cannot be identified afterward.
Three distinctions do most of the work.
Access is not authorization. Being able to open something says what the permissions allow. It says nothing about what may be done with what is inside.
Retrieval is not approval. That a system found a document proves it could reach it, and nothing more. Whether the content belongs in the thing being produced is a separate decision, and it has to be made separately.
Stating a value is not enforcing one. A principle written down and checked by nobody governs nothing. A rule the system evaluates before it acts governs something.
The third is the one organizations get wrong most often. Most write their values into a document and then never check against them again. A value becomes operational at the moment it changes what happens, not at the moment everyone agrees with it.
A policy document is read once, usually by the person who wrote it. A rule attached to the information itself is checked every time that information is touched.
That is the shift. Governance stops being a document somewhere and becomes a property of the material, carried by it.
Information that can be governed declares four things about itself: what it is for, who is allowed to act on it, what it is connected to, and whether it is allowed to leave. Those declarations have to survive the material moving between tools, formats, and people. When they do not survive the move, meaning gets inferred, and inference is where it goes wrong.
This is also what makes the relationships between pieces of information legible. A system that knows what a document replaces, what it depends on, and what it belongs to can move through a body of work predictably. A system guessing those relationships from resemblance cannot, and it will be confidently wrong in ways that are hard to trace afterward.
A claim separated from its source becomes true by repetition.
This is the failure that matters most in AI-assisted work, because these systems are fluent. Something is asserted as confirmed. The next process trusts the assertion rather than the source. The claim is now load-bearing and nobody has checked it. By the time it is questioned, several decisions are already resting on it.
The correction is narrow and it holds. A claim of verification has to carry the thing that proves it: a source that can be opened, a check that can be re-run. If it cannot be reduced to something checkable, it is reported, not verified. Two words, and the distinction between them is most of the discipline.
Protection works the same way. Restricting who may open something is the easy half. The harder question is what may be derived from it, and where that derivative is allowed to go. Material that must not travel needs that constraint attached to the material, checked by whatever is about to include it, rather than remembered by whoever happens to be supervising.
A governable system does not depend on the person in charge remembering every boundary at the moment it matters. It makes authority, consent, relationships, and evidence visible at the point of action, so the boundary holds when nobody is watching.
That is the difference between a system that can act and a system that can be trusted to act.
None of this requires a particular vendor or tool. It requires that the rules live where the machine reads them, and that the boundary is declared before the access is granted, not after something has gone wrong.
The Implementation Edition carries the complete operating model: the permission structure, the metadata model and its schema, access and execution boundaries, provenance controls, outbound governance, and the order to put them in place. It ships as a formatted manual with a fill-in implementation worksheet and the schema as a usable file.
Published by Execute Your Intentions, LLC. IKINGAI™ is a trademark of Execute Your Intentions, LLC. This guide is provided for informational purposes and does not constitute legal, financial, fiduciary, strategic, or operational advice. © 2026 Execute Your Intentions, LLC.