WFGY/ProblemMap/GlobalFixMap/Governance
2026-02-26 17:06:21 +08:00
..
checklists Create .gitkeep 2025-09-01 18:35:07 +08:00
eval Create .gitkeep 2025-09-01 18:35:15 +08:00
mvp_demo Create .gitkeep 2025-09-01 18:35:23 +08:00
ops Create .gitkeep 2025-09-01 18:35:30 +08:00
patterns Create .gitkeep 2025-09-01 18:35:38 +08:00
playbooks Create .gitkeep 2025-09-01 18:35:45 +08:00
tools Create .gitkeep 2025-09-01 18:35:52 +08:00
audit_and_logging.md Update audit_and_logging.md 2025-09-05 10:53:14 +08:00
audit_logs_and_traceability.md Update audit_logs_and_traceability.md 2025-09-05 10:53:21 +08:00
data_lineage_and_provenance.md Update data_lineage_and_provenance.md 2025-09-05 10:53:26 +08:00
escalation_and_governance.md Update escalation_and_governance.md 2025-09-05 10:53:31 +08:00
ethics_and_bias_mitigation.md Update ethics_and_bias_mitigation.md 2025-09-05 10:53:37 +08:00
eval_governance_gates_and_signoff.md Update eval_governance_gates_and_signoff.md 2026-02-26 17:06:21 +08:00
incident_response_and_postmortems.md Update incident_response_and_postmortems.md 2025-09-05 10:53:48 +08:00
license_and_dataset_rights.md Update license_and_dataset_rights.md 2025-09-05 10:53:53 +08:00
model_governance_model_cards_and_releases.md Update model_governance_model_cards_and_releases.md 2025-09-05 10:53:58 +08:00
pii_handling_and_minimization.md Update pii_handling_and_minimization.md 2025-09-05 10:54:05 +08:00
policy_baseline.md Update policy_baseline.md 2025-09-05 10:54:11 +08:00
prompt_policy_and_change_control.md Update prompt_policy_and_change_control.md 2025-09-05 10:54:25 +08:00
README.md Update README.md 2026-02-10 16:48:15 +08:00
regulatory_alignment.md Update regulatory_alignment.md 2025-09-05 10:54:30 +08:00
risk_register_and_waivers.md Update risk_register_and_waivers.md 2025-09-05 10:54:36 +08:00
roles_and_access_rbac_abac.md Update roles_and_access_rbac_abac.md 2025-09-05 10:54:41 +08:00
transparency_and_explainability.md Update transparency_and_explainability.md 2025-09-05 10:54:46 +08:00

Governance — Global Fix Map

🏥 Quick Return to Emergency Room

You are in a specialist desk.
For full triage and doctors on duty, return here:

Think of this page as a sub-room.
If you want full consultation and prescriptions, go back to the Emergency Room lobby.

A hub for governance controls around AI pipelines.
Use this folder when failures are not infra or retrieval bugs, but breakdowns in policy, approvals, lineage, or compliance.
Every page links to a structural WFGY fix and carries measurable acceptance targets so you can verify governance gates quickly.


When to use this folder

  • Policies exist but are unclear, obsolete, or unenforced
  • Prompts or models change without sign-off and audit trail
  • Data provenance is lost between documents, chunks, embeddings, and answers
  • PII handling, minimization, or redaction cannot be proven
  • License or usage rights are ambiguous for datasets or generated outputs
  • Incident response or postmortems are missing or not actionable

Acceptance targets

  • Policy coverage ≥ 0.95 across datasets, prompts, models, eval
  • ΔS(question, retrieved) ≤ 0.45 for governed outputs
  • Coverage of the target section ≥ 0.70 with cite-then-explain
  • λ remains convergent across 3 paraphrases and 2 seeds
  • Every waiver has owner, expiry, and review link
  • Immutable audit logs are joinable to lineage and approvals

Quick index — per governance page

Area Page
Policy baseline policy_baseline.md
Roles and access (RBAC and ABAC) roles_and_access_rbac_abac.md
Data lineage and provenance data_lineage_and_provenance.md
PII handling and minimization pii_handling_and_minimization.md
License and dataset rights license_and_dataset_rights.md
Prompt policy and change control prompt_policy_and_change_control.md
Model governance, model cards, releases model_governance_model_cards_and_releases.md
Eval governance, gates and sign-off eval_governance_gates_and_signoff.md
Audit and logging audit_and_logging.md
Audit logs and traceability audit_logs_and_traceability.md
Escalation and governance escalation_and_governance.md
Ethics and bias mitigation ethics_and_bias_mitigation.md
Regulatory alignment regulatory_alignment.md
Transparency and explainability transparency_and_explainability.md
Incident response and postmortems incident_response_and_postmortems.md
Risk register and waivers risk_register_and_waivers.md

Map symptoms to structural fixes

Symptom Likely cause Open this
Prompts or models change silently No change control, missing approvals prompt_policy_and_change_control.md · eval_governance_gates_and_signoff.md
PII appears in answers or logs Weak minimization, missing redaction gates pii_handling_and_minimization.md · audit_and_logging.md
Cannot show why a citation was selected Missing trace schema or lineage joins audit_logs_and_traceability.md · data_lineage_and_provenance.md
Disputes about dataset or output rights Missing license registry or usage constraints license_and_dataset_rights.md
Bias complaints or ethical risk No bias probes, weak mitigation playbooks ethics_and_bias_mitigation.md
Regulatory questions block a release No mapping from policy to artifacts regulatory_alignment.md · policy_baseline.md
Incidents repeat with no learning Postmortems not tied to gates incident_response_and_postmortems.md · eval_governance_gates_and_signoff.md
Access is too broad or untracked RBAC or ABAC not enforced or logged roles_and_access_rbac_abac.md
Waivers never expire Risk register lacks owner or timer risk_register_and_waivers.md
Users say answers are opaque No public card, weak rationale trail model_governance_model_cards_and_releases.md · transparency_and_explainability.md

Governance in 60 seconds

  1. Gate before ship
    Require cite-then-explain, ΔS ≤ 0.45, coverage ≥ 0.70 on 3 paraphrases and 2 seeds.
  2. Lock the policy surface
    For each change, capture who, what, why, and link to risk entry. Block if approvals missing.
  3. Prove lineage
    Emit a joinable record for question, snippets, ΔS, λ state, policy checks, model rev.
  4. Escalate with a plan
    If any gate fails, open the page from the table above and attach a time-boxed fix.

Copy-paste governance gate

governance_gate:
  approvals: required
  citations: cite_then_explain
  eval_window:
    seeds: 2
    paraphrases: 3
  targets:
    deltaS: <=0.45
    coverage: >=0.70
    lambda: convergent
  artifacts:
    lineage_log: required
    change_request: required
    model_card: required
  waivers:
    owner: required
    expiry_days: 30
    reason: required
block_on_failure: true

FAQ

Q1. We already have security reviews. Why add governance here as well Security reviews focus on systems and data access. Governance closes the policy loop for prompts, models, eval, and end user impact. It gives repeatable gates for ΔS, coverage, and approvals so releases are auditable.

Q2. What is the fastest path to “good enough” governance for a small team Start with three items. Change control for prompts and models. Eval gate with cite-then-explain and ΔS and coverage targets. A minimal lineage log that joins questions, snippets, and approvals.

Q3. How do I prove PII minimization without slowing teams down Tag sensitivity at ingest, redact at export, and enforce a schema that carries policy flags with each snippet. Keep a joinable audit log. See PII handling and the audit pages.

Q4. Our legal team asks who owns the generated outputs. What should we track Record the base model license, any fine-tune datasets with rights, and the allowed uses. Store the link to the release note and model card for each production rev.

Q5. We passed eval but a week later users saw regressions Your gate is not attached to change control. Hook the same eval and targets to the approval workflow and block deploys if the gate fails.

Q6. What is a practical rule for waivers Every waiver must have an owner, an expiry, a review link, and a rollback. Put it in a risk register and report open waivers weekly.

Q7. People ask for explainability but do not read long reports Provide a short model card and keep the citation trail visible. For complex cases include one visual lineage join to show where an answer came from.

Q8. Which metrics should appear on an executive dashboard Policy coverage, count of approved changes, open waivers by age, ΔS and coverage medians, incident count and mean time to resolution, and percentage of runs with cite-then-explain.

Q9. How do we align with new regulations without rewriting everything Keep your policy baseline and evidence mapping separate from code. Store proofs in an immutable sink and link them to releases. Update the mappings as new rules arrive.

Q10. What triggers an escalation Any failed gate, waiver beyond expiry, missing lineage, or production PII event. Follow the escalation page and attach a dated recovery plan.


🔗 Quick-Start Downloads (60 sec)

Tool Link 3-Step Setup
WFGY 1.0 PDF Engine Paper 1 Download · 2 Upload to your LLM · 3 Ask “Answer using WFGY + ”
TXT OS (plain-text OS) TXTOS.txt 1 Download · 2 Paste into any LLM chat · 3 Type “hello world” — OS boots instantly

🧭 Explore More

Module Description Link
WFGY Core WFGY 2.0 engine is live: full symbolic reasoning architecture and math stack View →
Problem Map 1.0 Initial 16-mode diagnostic and symbolic fix framework View →
Problem Map 2.0 RAG-focused failure tree, modular fixes, and pipelines View →
Semantic Clinic Index Expanded failure catalog: prompt injection, memory bugs, logic drift View →
Semantic Blueprint Layer-based symbolic reasoning & semantic modulations View →
Benchmark vs GPT-5 Stress test GPT-5 with full WFGY reasoning suite View →
🧙‍♂️ Starter Village 🏡 New here? Lost in symbols? Click here and let the wizard guide you through Start →

👑 Early Stargazers: See the Hall of Fame
Engineers, hackers, and open source builders who supported WFGY from day one.

GitHub stars WFGY Engine 2.0 is already unlocked. Star the repo to help others discover it and unlock more on the Unlock Board.

WFGY Main   TXT OS   Blah   Blot   Bloc   Blur   Blow