# The Discoverability & Governance Playbook

> Every prompt is a document. Every agent is an identity. Both are now legal evidence.

*P08 · Module M3 — Company Brain · The CEO AI Playbook by Stephen Forte*

Canonical: https://academy.buildclub.com/m3/p08-discoverability-governance

## Thesis

Every prompt is a document. Every agent is an identity.

## Key Takeaways

- Every prompt is a document. Every agent is an identity.
- 96% — of IT leaders have deployed AI agents inside the company.
- 12% — have any form of centralized agent governance.
- 84pt — governance gap — the 96/12 spread between agents deployed and agents governed.
- Email your general counsel today: "AI logs are discoverable. I need an interim AI retention policy within 14 days.".

## The Playbook

1. **Interim retention policy** — Within 14 days. Tell employees what is logged and how long it is kept.
2. **Count every agent** — Within 14 days. If you cannot count them, you do not own them.
3. **Name governance owner** — Within 60 days. One throat to choke, with hire-and-fire authority.
4. **Enterprise instances** — Move sensitive work off consumer-grade tools. No personal accounts on regulated data.
5. **Machine identity per agent** — Every agent gets its own credential, scoped and rotated like a service account.
6. **Least-privilege audit** — Top 10 agents. Revoke any right the agent has not used in 30 days.
1. **Prompts** — Every user input to a chatbot, copilot, or agent. Logged by default by vendor.
2. **Tool calls** — Each API call an agent makes is a timestamped action log.
3. **Agent decisions** — Every autonomous action with a rationale trail.
4. **System prompts** — The fixed instructions your company loaded. These are your policy artifact.
5. **Model outputs** — Generated text, code, or decision. Potentially discoverable as company statement.
6. **Retention schedules** — How long each log type is kept. If you do not set it, the vendor’s default applies.

## Key Numbers

- **96%** — of IT leaders have deployed AI agents inside the company. (OutSystems/Gartner survey)
- **12%** — have any form of centralized agent governance. (OutSystems/Gartner survey)
- **84pt** — governance gap — the 96/12 spread between agents deployed and agents governed. (OutSystems/Gartner survey)

## What to Do Monday

- Email your general counsel today: "AI logs are discoverable. I need an interim AI retention policy within 14 days."
- Count every AI agent your company is running — if you do not know the number, start the audit.
- Name one governance owner with budget authority — not a committee, one person.
- Move any sensitive workflow off consumer-grade AI tools to enterprise instances.
- Pull your top three AI vendor contracts and locate the data retention and model-training clauses.

## FAQ

**What is the core idea of The Discoverability & Governance Playbook?**

Every prompt is a document. Every agent is an identity.

**What does the data say a CEO should pay attention to?**

96% of IT leaders have deployed AI agents inside the company. 12% have any form of centralized agent governance.

**What should a CEO do Monday morning after reading The Discoverability & Governance Playbook?**

Start here: Email your general counsel today: "AI logs are discoverable. I need an interim AI retention policy within 14 days."; Count every AI agent your company is running — if you do not know the number, start the audit; Name one governance owner with budget authority — not a committee, one person.

**What are the steps in The Discoverability & Governance Playbook?**

1) Interim retention policy; 2) Count every agent; 3) Name governance owner; 4) Enterprise instances; 5) Machine identity per agent.

**Where do the claims in The Discoverability & Governance Playbook come from?**

The playbook cites OutSystems/Gartner survey; U.S. federal court ruling (SDNY, 2026); Delaware Chancery earnout dispute (2025); OutSystems/Gartner.

## Sources

- [OutSystems/Gartner survey](https://www.outsystems.com/)
- U.S. federal court ruling (SDNY, 2026)
- Delaware Chancery earnout dispute (2025)
- [OutSystems/Gartner](https://www.outsystems.com/)
- [Gartner / Forrester — enterprise agent governance forecasts (2026)](https://www.gartner.com/)
- YPO Technology Network AI Daily Brief case file
- OWASP Agentic Security
- Infisical (public)
- OP3 Security Stack Playbook

---

Work with BuildClub: https://buildclub.com/company-brain
