Privacy & confidentiality
Potentially sensitive personal, client, employee, applicant, vendor, or business-confidential information can enter an unapproved workflow.
Privacy-first Safe AI Enablement + Shadow AI Governance
Put a Gate Between AI and Risk
Enable AI without losing control. PrivAI Guard converts an AI-use event into an actionable governance workflow—so risk can be reviewed, owned, remediated, preserved as evidence, and made visible to management.
Unapproved tools.
Unclear data.
No accountable trail.
Risk identified.
Owner assigned.
Evidence visible.
The business problem
The problem is not AI adoption. The problem is AI adoption without an operational governance process.
Employees use generative AI because it creates real productivity value. The blind spot appears when the organization cannot consistently see what tool is being used, what information may be submitted, who is affected, who owns the decision, what remediation is required, or what evidence remains afterward.
Potentially sensitive personal, client, employee, applicant, vendor, or business-confidential information can enter an unapproved workflow.
External tools can create unmanaged data exposure and reduce control over where information is processed, retained, or accessed.
Email, spreadsheets, and ad hoc judgment make governance difficult to repeat, measure, assign, or defend.
Leadership and auditors need a durable record of what happened, who reviewed it, what action was assigned, and whether it was resolved.
The PrivAI Guard solution
One structured path turns an informal AI-use event into a governed record with human decision points.
Sensitive-data indicators
Risk + potential data-subject impact
Recommend a safer approved internal AI pathway where appropriate
Create accountable remediation
Preserve governance evidence
Provide management visibility
What management gets
Business value before technology: help people use AI more safely, convert risk into accountable work, and give management a clearer operating picture.
ENABLE
Give employees guidance and safer alternatives instead of relying only on blanket prohibitions.
OWN
Translate identified risk into responsible owners, priorities, due dates, status, and remediation.
SEE
Provide structured evidence, remediation status, governance activity, and dashboard-level visibility.
Why SMEs should care
Small and medium enterprises can face the same AI-governance questions as larger organizations while operating with smaller privacy, security, compliance, and engineering teams.
PrivAI Guard demonstrates a focused cloud-based governance layer: visibility, accountable ownership, safer AI-use guidance, evidence, and management insight—without requiring an enormous governance program as the starting point.
Strategic product direction: SME commercialization is a future direction, not a claim that the Capstone MVP is already a commercial multi-tenant SaaS product.
Responsible AI resource & token efficiency
Cost-conscious AI routing can become part of responsible governance, but the frozen MVP does not establish measured token savings.
The implemented product evaluates risk and can recommend an approved internal AI pathway where appropriate. The recommendation is reviewed by a human and does not automatically transmit data.
A production version could extend routing intelligence to consider model suitability, task complexity, context minimization, token usage, approved-model cost, privacy requirements, data residency, performance needs, and business criticality.
Use the safest appropriate model—not automatically the largest or most expensive model.
Signature capstone section
PrivAI Guard is not one class applied to one application. It is the integration point for the MSIS learning journey.
The project brings security, privacy, architecture, resilience, delivery, and transformation thinking together around one operational business problem.
PrivAI Guard application: Shadow AI governance, risk-based controls, innovation-versus-risk decisions, and security positioned as an enabler.
Business lesson: Governance should enable responsible innovation—not simply prohibit it.
PrivAI Guard application: role-aware security, server-side authorization, Row Level Security, input validation, controlled data boundaries, and fail-closed behavior where implemented.
Business lesson: A governance system must itself be trustworthy.
PrivAI Guard application: data minimization, synthetic data, sensitive-data identification, data-subject impact review, human review, redacted excerpts, and audit evidence.
Business lesson: Privacy is designed into the workflow rather than added afterward.
PrivAI Guard application: limited read-only BC/DR checkpoint visibility, RTO/RPO awareness, backup-status records, ownership, and readiness information.
Business lesson: Governance matters only if the supporting service can remain recoverable and accountable.
PrivAI Guard application: Supabase PostgreSQL, structured relational records, persistence, integrity constraints, relationships, controlled RPC boundaries, and authoritative governance evidence.
Business lesson: Accountability requires reliable information, relationships, and system-of-record thinking.
PrivAI Guard application: spec-driven development, iterative implementation, automated quality gates, local RLS/E2E validation, hosted UAT, GitHub source control, Vercel Preview hosting, scope control, and release gates.
Business lesson: How the solution is built matters as much as what is built.
GitHub Actions validates the repository; final documentation does not claim that GitHub Actions itself performs Vercel deployment.
PrivAI Guard application: converts informal Shadow AI behavior into a governed operating process and balances adoption, risk, agility, accountability, and cloud-enabled delivery.
Business lesson: Digital transformation requires operating-model change, not merely new technology.
Project Management — scope, dependencies, milestones, UAT, release control, stakeholder priorities. Enterprise Agility — iteration, adaptation, feedback, focused delivery. Business Analysis — translating a governance problem into users, requirements, workflows, risks, and acceptance criteria. UI / Application Design — turning complex privacy and security decisions into understandable employee and management workflows.
These are presented as broader professional disciplines unless separately identified as formal course titles in the project source material.
Technology — supporting, not leading
The frozen MVP uses a deliberately compact stack so the architecture serves the governance workflow rather than becoming the story.
EXPERIENCE
Browser-based role-aware interface for employee and governance workflows.
GOVERNANCE LOGIC
Deterministic risk scoring, authorization, human review, routing recommendations, remediation, and aggregation.
TRUSTED DATA
Authentication, persistence, Row Level Security, controlled database functions, and governance audit records.
CLOUD DELIVERY
Vercel hosts the non-production Preview. GitHub provides source control and a repository quality gate.
Safety by design
The capstone does not treat privacy and security as a disclaimer added at the end. They shape the data boundary, authorization model, decision process, and evidence trail.
Inside the frozen MVP
Selected screenshots from the final capstone documentation show the employee check, governance review, remediation, audit evidence, and management dashboard.





The MVP boundary
Transparency is part of the product story. The capstone demonstrates a real working governance workflow, but it is not enterprise-production software.
These are potential future directions. They are not represented as implemented or committed features.
Moving forward
A credible product path expands control in stages rather than pretending the capstone is already an enterprise platform.
Prove the operating workflow: detect, assess, review, remediate, preserve evidence, and provide visibility.
Refine role management, reporting, policy templates, routing rules, and risk-scoring usability with controlled feedback.
Pursue focused governance, integration, responsible model selection, and cost-conscious AI operations without enterprise-scale complexity.
Explore deeper identity, security engineering, integrations, observability, resilience, analytics, and measurable governance outcomes.
Product direction, not a delivery commitment.
FROM SHADOW TO SIGNAL
Explore the working capstone MVP, then continue the conversation about practical AI governance for the next phase.
bit.ly/spsram26
Built as a Northwestern MSIS Capstone MVP
Scan to explore the live capstone MVP