Guide / AIGIS resources

What evidence helps when AI touches data inside a SOC 2 scope.

When AI reads customer data, access-control evidence matters for a SOC 2 readiness effort. AIGIS produces permission-provenance evidence that supports those control conversations. SOC 2 is a readiness workstream for Governed; this content does not claim an active audit or certification.

Executive read

The short version, before the deep dive.

Map where AI reads in-scope data and what access checks gate it.

Capture per-interaction evidence of permission checks and stripped fields.

Keep the access record auditor-readable and repeatable.

Start on Salesforce; disclose ServiceNow and SAP as co-development scope.

Analysis

What matters

What an access reviewer wants to see

Logical access controls are a common SOC 2 focus. When AI is the consumer, the reviewer wants evidence that the access boundary held before the model saw data.

AIGIS records that check. It does not assert SOC 2 conformance, and no AIGIS material should claim certification.

A practical starting scope

Pick one Salesforce workflow with role-dependent visibility. Show object, field, and live record access checks before prompt construction, then the evidence trail.

Next step

Bring that workflow to a scoped review at `/demo`.

Resource packet

Turn this into a review worksheet.

Evidence packet

Permission-Provenance Evidence Packet

Capture user context, system of record, enforcement tier, stripped fields, model route, response, hash marker, and fallback notes.

Salesforce is the production proof path. ServiceNow and SAP are design-partner co-development paths with asymmetric enforcement that must be disclosed in diligence.

Get the packet