Skip to content
← GUIDES

GUIDE · READ ONLINE

Evaluating AI governance in HR software: 10 questions to ask any vendor.

Any vendor can say "governed AI". These ten questions separate architecture from marketing — ask them in the demo, in writing, and in the contract.

THE TEN QUESTIONS

01 Does a human approve every AI action before it executes — and can that gate be disabled?
02 How does the AI authenticate? Does it hold user credentials, or short-lived per-action tokens?
03 Is the AI’s permission scope enforced server-side, or only in the prompt?
04 Can an executed AI action be rolled back? How?
05 Is there a complete audit trail — instruction, plan, approver, actions, timestamps — and is it exportable?
06 Is customer data used to train models? Where is that stated contractually?
07 Where does the data reside, and can residency be guaranteed by region?
08 How is data encrypted in transit and at rest — and is field-level encryption available for sensitive payloads?
09 How are tenants isolated from each other?
10 If we leave, can we export every entity of our data — and is that on every plan?

If the answer is a policy document instead of an architecture, keep asking.

Our answers are public.

All ten, answered in the Trust Center — or asked live in a demo.