M3 · THE COMPANY BRAIN · P08

The Discoverability & Governance Playbook

Every prompt is a document. Every agent is an identity. Both are now legal evidence.

10 SLIDES · ~10 MIN · PLAYBOOK OVERVIEW
Key Takeaways
  • Every prompt is a document. Every agent is an identity.
  • 96% — of IT leaders have deployed AI agents inside the company.
  • 12% — have any form of centralized agent governance.
  • 84pt — governance gap — the 96/12 spread between agents deployed and agents governed.
  • Email your general counsel today: "AI logs are discoverable. I need an interim AI retention policy within 14 days.".
MODULE 3 · PLAYBOOK 08

The Discoverability & Governance Playbook

Every prompt is a document. Every agent is an identity. Both are now legal evidence.

BuildClub Academy
01 · THE HOOK

You are already losing the governance race.

96%
of IT leaders have deployed AI agents inside the company.
OutSystems/Gartner survey
12%
have any form of centralized agent governance.
OutSystems/Gartner survey
84pt
governance gap — the 96/12 spread between agents deployed and agents governed.
OutSystems/Gartner survey
02 · THE THESIS

Every prompt is a document.
Every agent is an identity.
Both are now legal evidence.

The Thesis
03 · THE PRECEDENT

It is not theoretical. Two courts already ruled.

1
U.S. federal court (SDNY, 2026)
A 2026 ruling held that chatbot transcripts are documents, not privileged conversations, and are therefore discoverable. The transcripts came in as evidence.
2
Delaware Chancery earnout dispute (2025)
In a 2025 earnout dispute, CEO AI chat logs about the deal were admitted as material evidence of intent.
04 · THE PLAYBOOK

The six-step Governance Playbook.

1 Classify tier each doc 2 Restrict least-privilege 3 Watermark mark sensitive 4 Log every query, every user 5 Review quarterly access audit 6 Retain discoverable on demand
05 · THE GAP

The 96/12 gap is a fiduciary problem, not a technical one.

Concentration risk Anthropic 73% % of first-time enterprise AI spend OpenAI 61% % citing as primary GenAI provider Source: Bloomberg (Anthropic enterprise share); Gartner 2026.
Takeaways
  • 1 96% deployed vs 12% governed. The gap is fiduciary exposure.
  • 2 Analyst estimates of unmanaged agent exposure now reach tens to hundreds of billions of dollars across public-company portfolios.
  • 3 Deployment has outrun policy. Boards now own the gap, not IT.
06 · WHAT DISCOVERY NOW INCLUDES

What "discovery" now includes — beyond email.

1
2
3
4
5
6
1
Prompts
Every user input to a chatbot, copilot, or agent. Logged by default by vendor.
2
Tool calls
Each API call an agent makes is a timestamped action log.
3
Agent decisions
Every autonomous action with a rationale trail.
4
System prompts
The fixed instructions your company loaded. These are your policy artifact.
5
Model outputs
Generated text, code, or decision. Potentially discoverable as company statement.
6
Retention schedules
How long each log type is kept. If you do not set it, the vendor’s default applies.
07 · THE IDENTITY PROBLEM

31 unauthorized agents. 6 weeks. One mid-sized agency.

Low agents · Low governance
Manageable. You can still see it.
High agents · High governance
Controlled. The 8% target state.
Low agents · High governance
Over-engineered. Bureaucracy without scale.
High agents · Low governance
The Velocity Digital state. 31 agents discovered. 6 weeks unnoticed.

Count the agents before you govern them.

08 · THE OPERATOR-3 EXTENSION

Per-vertical secrets. Machine identity per agent. Separate accounts per role.

1
No single agent sees the whole vault
Vertical-scoped secret stores (Infisical pattern). Blast radius is limited by design.
2
Machine identity per agent
Every agent provisioned like a service account. Shared service accounts are a single point of failure.
3
Two-account rule
Separate enterprise instances for regulated vs unregulated work. Workshop or client context never shares with personal.
MONDAY-MORNING ACTIONS

Five moves. Two are this week.

Monday Morning
  1. 1
    Email your general counsel today: "AI logs are discoverable. I need an interim AI retention policy within 14 days."
  2. 2
    Count every AI agent your company is running — if you do not know the number, start the audit.
  3. 3
    Name one governance owner with budget authority — not a committee, one person.
  4. 4
    Move any sensitive workflow off consumer-grade AI tools to enterprise instances.
  5. 5
    Pull your top three AI vendor contracts and locate the data retention and model-training clauses.
P08 · Questions CEOs Ask

Frequently Asked Questions

What is the core idea of The Discoverability & Governance Playbook?
Every prompt is a document. Every agent is an identity.
What does the data say a CEO should pay attention to?
96% of IT leaders have deployed AI agents inside the company. 12% have any form of centralized agent governance.
What should a CEO do Monday morning after reading The Discoverability & Governance Playbook?
Start here: Email your general counsel today: "AI logs are discoverable. I need an interim AI retention policy within 14 days."; Count every AI agent your company is running — if you do not know the number, start the audit; Name one governance owner with budget authority — not a committee, one person.
What are the steps in The Discoverability & Governance Playbook?
1) Interim retention policy; 2) Count every agent; 3) Name governance owner; 4) Enterprise instances; 5) Machine identity per agent.
Where do the claims in The Discoverability & Governance Playbook come from?
The playbook cites OutSystems/Gartner survey; U.S. federal court ruling (SDNY, 2026); Delaware Chancery earnout dispute (2025); OutSystems/Gartner.
P08 · Sources

All Sources in This Playbook

00 / 10