Styr
Data Governance for AI

Which data goes to which model — as policy, not folklore

'The fast model for member data, the big model only for anonymised text, frontier models only for trained staff.' Every AI-using organisation has rules like these — living in people's heads. The Model & Data Routing Policy makes them structured, evaluable and exportable.

7 data classes

A fixed vocabulary from public to credentials

3 verdicts

Allow, conditional or deny — deterministic, no AI in the loop

Never silent

No covering rule means 'no policy covers this' — not a quiet yes

From unwritten rules to an evaluable matrix

Most organisations already route AI usage informally: sensitive data stays on the EU-hosted model, the powerful US-hosted model is for public content only, and the experimental frontier model is reserved for people who finished their AI training. None of it is written down where a system — or an auditor — can check it.

The routing policy turns each of those judgements into a rule: a data class (personal data, special category, financials…), a target (a specific registered model, any model within a region, or any model at all), and a verdict — allow, conditional or deny. Conditional rules name their conditions: completed AI literacy training, a signed DPA with the vendor, documented human review, anonymised input only.

Rules can be organisation-wide defaults or per-agent overrides — an agent handling support tickets can run under stricter rules than the internal drafting assistant. The evaluator is pure and deterministic: agent rules beat org defaults, deny beats conditional beats allow, and the most restrictive data class wins.

A built-in 'test a call' preview shows the live traffic light for any model + data-class combination, so you validate the matrix before anything relies on it. And the whole policy exports as a branded PDF — the evidence artifact your DPO, auditor or board actually asks for.

Unwritten rules vs. an evaluable policy

Without the routing policy

  • 'Which model may I use for this?' is answered by asking whoever has been around longest
  • Sensitivity rules drift per team — nobody can say what the actual policy is
  • Conditions like 'only after training' are unenforceable good intentions
  • The auditor asks for the routing policy and gets a shrug or a stale wiki page

With the routing policy

  • One structured matrix: data class × model/region × verdict, org-wide and per-agent
  • A deterministic evaluator answers green, yellow or red — the same answer every time
  • Conditions resolve against real records: literacy training, signed DPAs in the register
  • One click exports the policy as a branded, auditor-ready PDF

What the routing policy gives your governance team

A fixed data-class vocabulary

Seven authored classes from public to credentials — rules speak one language across the whole platform.

Verdicts with teeth

Allow, conditional or deny per combination. Conditional rules name their conditions and resolve green only when every one is met.

Region constraints

'Any model within the EU' is a valid target — evaluated against each model's weakest-link residency from the vendor register, not its marketing page.

Per-agent overrides

Org-wide defaults with agent-specific exceptions — stricter rules for the customer-facing agent, calmer ones for internal drafting.

The traffic-light preview

Test any model + data-class combination and see the verdict your policy gives, with reasons and approved alternatives.

The auditor-ready export

The full matrix — scopes, verdicts, conditions, rationales — as a deterministic branded PDF. No AI wrote it; your policy did.

How the policy comes together

1

Start from the register

Your vendors and models are already documented in the AI Vendor Register — rules reference them directly.

2

Write the rules you already have

Capture the unwritten judgements as allow / conditional / deny rules per data class.

3

Test the matrix

Use the live preview to confirm the policy answers the way you expect — including the gaps it names.

4

Export and share

Hand the PDF to your DPO or auditor, and let agents carry their own override rules on their governance record.

We had routing rules for a year — in three people's heads, slightly different in each. Now the matrix answers, and the answer is the same for everyone.

Available from Pro

The Model & Data Routing Policy is included in every paid plan, alongside the AI Vendor Register.

ProBusinessEnterprise

Write down the rules you already enforce

Start free, document your vendors and models, and turn your routing judgement into an evaluable policy.

Model & Data Routing Policy — structured rules for which data goes to which AI | Fronterio | Fronterio