Privacy-first Safe AI Enablement + Shadow AI Governance

PrivAI Guard

Put a Gate Between AI and Risk

Enable AI without losing control. PrivAI Guard converts an AI-use event into an actionable governance workflow—so risk can be reviewed, owned, remediated, preserved as evidence, and made visible to management.

SHADOWInvisible AI use GATEGovernance workflow SIGNALActionable evidence

Enable AI. Control risk. Preserve evidence.

SHADOW

Unapproved tools.
Unclear data.
No accountable trail.

SIGNAL

Risk identified.
Owner assigned.
Evidence visible.

QR code opening https://bit.ly/spsram26
Explore the live capstone MVP bit.ly/spsram26

The business problem

AI Productivity Is Visible. AI Governance Often Is Not.

The problem is not AI adoption. The problem is AI adoption without an operational governance process.

Employees use generative AI because it creates real productivity value. The blind spot appears when the organization cannot consistently see what tool is being used, what information may be submitted, who is affected, who owns the decision, what remediation is required, or what evidence remains afterward.

01

Privacy & confidentiality

Potentially sensitive personal, client, employee, applicant, vendor, or business-confidential information can enter an unapproved workflow.

02

Cybersecurity exposure

External tools can create unmanaged data exposure and reduce control over where information is processed, retained, or accessed.

03

Operational inconsistency

Email, spreadsheets, and ad hoc judgment make governance difficult to repeat, measure, assign, or defend.

04

Weak evidence

Leadership and auditors need a durable record of what happened, who reviewed it, what action was assigned, and whether it was resolved.

Policy defines expectations.PrivAI Guard demonstrates the operating process that follows.

The PrivAI Guard solution

From AI Use to Accountable Governance

One structured path turns an informal AI-use event into a governed record with human decision points.

01

CHECK

Sensitive-data indicators

02

ASSESS

Risk + potential data-subject impact

03

REDIRECT

Recommend a safer approved internal AI pathway where appropriate

04

ACT

Create accountable remediation

05

PROVE

Preserve governance evidence

06

SEE

Provide management visibility

AI UseDetectionRiskSafer PathAccountabilityEvidenceVisibility
Important MVP boundary: internal-AI routing is advisory. PrivAI Guard records a recommendation for human governance review; it does not automatically transmit prompt content to another AI service.

What management gets

Enable. Own. See.

Business value before technology: help people use AI more safely, convert risk into accountable work, and give management a clearer operating picture.

01

ENABLE

Safer AI Adoption

Give employees guidance and safer alternatives instead of relying only on blanket prohibitions.

02

OWN

Operational Accountability

Translate identified risk into responsible owners, priorities, due dates, status, and remediation.

03

SEE

Audit & Executive Visibility

Provide structured evidence, remediation status, governance activity, and dashboard-level visibility.

INFORMAL RISKMANAGED PROCESS

Why SMEs should care

Enterprise AI Governance Thinking—Without Enterprise-Scale Complexity

Small and medium enterprises can face the same AI-governance questions as larger organizations while operating with smaller privacy, security, compliance, and engineering teams.

PrivAI Guard demonstrates a focused cloud-based governance layer: visibility, accountable ownership, safer AI-use guidance, evidence, and management insight—without requiring an enormous governance program as the starting point.

Strategic product direction: SME commercialization is a future direction, not a claim that the Capstone MVP is already a commercial multi-tenant SaaS product.

VisibilityKnow what risk event entered governance.
AccountabilityKnow who owns the response.
EvidenceKnow what was reviewed and what changed.
Safer pathwaysSupport adoption rather than defaulting to prohibition.

Responsible AI resource & token efficiency

Governance First. Optimization Next.

Cost-conscious AI routing can become part of responsible governance, but the frozen MVP does not establish measured token savings.

CURRENT MVP

Risk-aware governance + advisory safer-AI routing

The implemented product evaluates risk and can recommend an approved internal AI pathway where appropriate. The recommendation is reviewed by a human and does not automatically transmit data.

FUTURE PRODUCT OPPORTUNITY

Cost- and context-aware model selection

A production version could extend routing intelligence to consider model suitability, task complexity, context minimization, token usage, approved-model cost, privacy requirements, data residency, performance needs, and business criticality.

Use the safest appropriate model—not automatically the largest or most expensive model.

Signature capstone section

FROM CURRICULUM TO CAPSTONE

PrivAI Guard is not one class applied to one application. It is the integration point for the MSIS learning journey.

The project brings security, privacy, architecture, resilience, delivery, and transformation thinking together around one operational business problem.

Security StrategyPrivacy by DesignCybersecurityDatabase ArchitectureBC/DRDevSecOps + AgileDigital Transformation
PrivAI GuardOperational Shadow AI governance
Safer adoptionAccountabilityResponsible data useAudit evidenceResilienceScalable governance
Information Security StrategyGovernance as a business enabler

PrivAI Guard application: Shadow AI governance, risk-based controls, innovation-versus-risk decisions, and security positioned as an enabler.

Business lesson: Governance should enable responsible innovation—not simply prohibit it.

Cybersecurity Attacks & CountermeasuresDefense in depth

PrivAI Guard application: role-aware security, server-side authorization, Row Level Security, input validation, controlled data boundaries, and fail-closed behavior where implemented.

Business lesson: A governance system must itself be trustworthy.

Privacy by Design & CompliancePrivacy built into the workflow

PrivAI Guard application: data minimization, synthetic data, sensitive-data identification, data-subject impact review, human review, redacted excerpts, and audit evidence.

Business lesson: Privacy is designed into the workflow rather than added afterward.

Disaster Recovery & Business Continuity (BC/DR)Resilience awareness

PrivAI Guard application: limited read-only BC/DR checkpoint visibility, RTO/RPO awareness, backup-status records, ownership, and readiness information.

Business lesson: Governance matters only if the supporting service can remain recoverable and accountable.

Database Systems & ArchitectureSystem-of-record thinking

PrivAI Guard application: Supabase PostgreSQL, structured relational records, persistence, integrity constraints, relationships, controlled RPC boundaries, and authoritative governance evidence.

Business lesson: Accountability requires reliable information, relationships, and system-of-record thinking.

DevSecOps / Agile Project ManagementBuild quality + controlled delivery

PrivAI Guard application: spec-driven development, iterative implementation, automated quality gates, local RLS/E2E validation, hosted UAT, GitHub source control, Vercel Preview hosting, scope control, and release gates.

Business lesson: How the solution is built matters as much as what is built.

GitHub Actions validates the repository; final documentation does not claim that GitHub Actions itself performs Vercel deployment.

Digital Transformation StrategyOperating-model change

PrivAI Guard application: converts informal Shadow AI behavior into a governed operating process and balances adoption, risk, agility, accountability, and cloud-enabled delivery.

Business lesson: Digital transformation requires operating-model change, not merely new technology.

Cross-cutting professional disciplines

Project Management — scope, dependencies, milestones, UAT, release control, stakeholder priorities. Enterprise Agility — iteration, adaptation, feedback, focused delivery. Business Analysis — translating a governance problem into users, requirements, workflows, risks, and acceptance criteria. UI / Application Design — turning complex privacy and security decisions into understandable employee and management workflows.

These are presented as broader professional disciplines unless separately identified as formal course titles in the project source material.

Technology — supporting, not leading

Simple Architecture. Practical Control.

The frozen MVP uses a deliberately compact stack so the architecture serves the governance workflow rather than becoming the story.

01

EXPERIENCE

Next.js / React / TypeScript

Browser-based role-aware interface for employee and governance workflows.

02

GOVERNANCE LOGIC

Risk + workflow rules

Deterministic risk scoring, authorization, human review, routing recommendations, remediation, and aggregation.

03

TRUSTED DATA

Supabase Auth + PostgreSQL

Authentication, persistence, Row Level Security, controlled database functions, and governance audit records.

04

CLOUD DELIVERY

Vercel + GitHub

Vercel hosts the non-production Preview. GitHub provides source control and a repository quality gate.

Boundary: final documentation treats GitHub Actions quality validation and Vercel hosting as separate facts; it does not claim a proven GitHub Actions-to-Vercel deployment mechanism.

Safety by design

Governance Built Into the Workflow

The capstone does not treat privacy and security as a disclaimer added at the end. They shape the data boundary, authorization model, decision process, and evidence trail.

Synthetic dataCapstone operation is synthetic-data-only.
Data minimizationFull raw prompts are not the normal durable record; verified redacted excerpts may be retained where needed.
Role-aware accessProtected routes, server authorization, capability checks, and PostgreSQL RLS operate as separate layers.
Human reviewRisk scores and routing recommendations are decision support, not autonomous legal decisions.
Controlled failureInvalid actors, payloads, or conflicting updates are rejected rather than silently accepted where implemented.
Audit evidenceGovernance-relevant actions are preserved through trusted workflow operations.
Demo environment. Synthetic data only. Human review required. Not a legal breach determination.

Inside the frozen MVP

One Incident. Multiple Roles. One Evidence Trail.

Selected screenshots from the final capstone documentation show the employee check, governance review, remediation, audit evidence, and management dashboard.

PrivAI Guard employee Safe Prompt Check screen
Employee Safe Prompt Check
PrivAI Guard governance review detail screen
Governance review
PrivAI Guard remediation task screen
Accountable remediation
PrivAI Guard audit evidence screen
Governance evidence
PrivAI Guard governance dashboard showing management visibility
Management dashboard visibility

The MVP boundary

What Exists Now. What Belongs to the Product Vision.

Transparency is part of the product story. The capstone demonstrates a real working governance workflow, but it is not enterprise-production software.

CAPSTONE MVP — NOW
  • Employee Safe Prompt Check
  • AI Tool Registry
  • Deterministic sensitive-data detection and risk scoring
  • Governance review and data-subject impact review
  • Advisory approved-internal AI routing recommendation
  • Remediation ownership and status tracking
  • Governance audit evidence
  • Dashboard-level management visibility
  • Limited read-only BC/DR checkpoint visibility
  • Role-aware admin governance
PRODUCTION VISION — NEXT
  • Enterprise SSO and stronger identity controls
  • Richer workflow, vendor, SIEM, DLP, and ticketing integrations
  • Browser / endpoint visibility and stronger Shadow AI discovery
  • Commercial multi-tenancy and customer administration
  • Advanced monitoring, alerting, and production operations
  • Enhanced policy controls and expanded analytics
  • Model / token / cost-aware routing optimization
  • Stronger enterprise resilience and continuity engineering
  • Production-grade security testing and assurance

These are potential future directions. They are not represented as implemented or committed features.

Moving forward

From Capstone MVP to Scalable AI Governance

A credible product path expands control in stages rather than pretending the capstone is already an enterprise platform.

  1. 01CAPSTONE MVP

    Prove the operating workflow: detect, assess, review, remediate, preserve evidence, and provide visibility.

  2. 02PRIVATE BETA

    Refine role management, reporting, policy templates, routing rules, and risk-scoring usability with controlled feedback.

  3. 03SME PLATFORM

    Pursue focused governance, integration, responsible model selection, and cost-conscious AI operations without enterprise-scale complexity.

  4. 04ENTERPRISE-GRADE GOVERNANCE

    Explore deeper identity, security engineering, integrations, observability, resilience, analytics, and measurable governance outcomes.

Product direction, not a delivery commitment.

FROM SHADOW TO SIGNAL

Enable AI. Control risk. Preserve evidence.

Explore the working capstone MVP, then continue the conversation about practical AI governance for the next phase.

Built as a Northwestern MSIS Capstone MVP

QR code opening https://bit.ly/spsram26 Scan to explore the live capstone MVP