Governance Overview
This section contains policy starters for engineering teams adopting AI coding tools.
Who This Section Is For
- engineering managers
- platform and security reviewers
- team leads creating internal standards
What Readers Can Accomplish
- define approval and rollout rules
- set least-privilege expectations
- classify tools by approval status
- standardize prompt and MCP reviews
- adapt this public repo into an internal policy handbook
Best First Pages
| Page | Best for | Maturity |
|---|---|---|
| Security and Permissions | baseline controls | Most mature |
| MCP Approval Policy | privileged integration approval | Most mature |
| Approved Tools Policy | tool classification | Strong |
| Team Rollout Guide | staged adoption | Strong |
Current Limitations
- these pages are policy starters, not legal advice
- each organization must add owners, systems, and evidence paths
- paid-plan, enterprise, and compliance controls vary by company
Recommended Reading Order
- Security and Permissions
- Approved Tools Policy
- Prompt Review Policy
- MCP Approval Policy
- Team Rollout Guide
Contribution Opportunities
- add company-fork examples
- add evidence templates for audits and approvals
- contribute more stack-specific rollout checklists
Verification Note
Governance pages are Documentation verified policy starters. They require team-specific customization before adoption.