The findings graveyard
Every organisation that starts governing AI agents discovers the same thing within weeks: findings are easy. An over-permissioned agent here, an unowned automation there, a connector nobody approved. The findings go into a spreadsheet, the spreadsheet goes into a monthly review, and six months later the same findings are still there — older, better formatted, and just as unfixed.
This isn't a failure of diligence. It's a failure of plumbing. Discovery and assessment produce information; remediation requires action from people outside the governance team, in systems the governance team doesn't run, on a schedule nobody owns. Information without a path to action accumulates. That's what a spreadsheet is.
A finding without an owner, a deadline and a path to done isn't a control. It's a diary entry.
Why the loop breaks
The loop breaks at predictable joints. The finding has no named owner, so it belongs to everyone and no one. The fix requires a change in a platform team's backlog, but arrives as an email rather than a ticket, so it never enters the backlog at all. Nobody is authorised to say what "fixed" means, so remediations are declared done without verification. And when someone asks, a year later, what was done about the finding — there is no record beyond a cell that changed from red to green.
Each of these is a governance failure in miniature: an action performed — or skipped — without authority, tracking or evidence.
Remediation as a governed lifecycle
The alternative is to treat remediation with the same rigour as the findings themselves: as a first-class object with a lifecycle. A remediation plan is drafted against specific findings, with a description of the intended change and its scope. It is submitted for approval, approved or rejected by someone other than its author, dispatched into the systems where work happens, and finally completed, failed or cancelled — each transition recorded, timestamped and attributed. At any moment, every finding either has a live remediation attached or is explicitly accepted, excepted or still queued. Nothing sits in an untracked in-between.
Maker-checker, everywhere
The pattern that holds the lifecycle honest is maker-checker: the person who drafts a plan cannot approve it, and the person who approves it cannot mark their own approval as executed. Borrowed from financial controls, it does two things at once — it prevents both the well-meaning shortcut (fixing something quietly, wrongly) and the malicious one (approving your own cover story). Applied to AI governance, it means no single person can create an agent, approve it, exempt it from policy and close the finding against it.
Four eyes aren't bureaucracy. They're the difference between a decision and an assertion.
Meet the teams where they work
Governance tools fail when they demand that engineers live in them. The teams who will actually revoke the permission, retire the agent or reconfigure the connector work in ticketing systems, task boards and runbooks — so approved remediation plans must flow into those systems automatically, as signed, structured events, and status must flow back. The governance platform keeps the authoritative record; the delivery teams keep their tools. Durable, HMAC-signed delivery with bounded retries means the handoff itself is trustworthy: downstream systems can verify what they received, and a lost message is retried rather than silently dropped.
Exceptions without erosion
Not every finding should be fixed — some risks are genuinely worth accepting. The danger is that exceptions quietly become the norm. Governed exceptions stay narrow by construction: scoped to an exact policy version and an exact rule, time-bounded so they lapse rather than linger, reviewed maker-checker like everything else, and surfaced in a notification queue as expiry approaches. An exception is a documented decision with a shelf life — not a hole cut in the policy.
Evidence that it happened
The end state of a healthy loop is simple to describe: for any finding, at any time, you can show what was found, who decided what to do, who approved it, where the work went, what came back, and when it closed — from an append-only history that nobody, including administrators, can quietly rewrite. That record is what turns "we take AI governance seriously" from a claim into a demonstrable fact.
Apex Warden implements this loop end to end: governed remediation plans with maker-checker approval, signed dispatch into your ticketing and runbook systems, bounded exceptions with expiry, an in-product notification queue, and immutable evidence for every step. Findings stop being a graveyard — and start being a queue that drains.
See the loop close
Book a walkthrough of governed remediation — from finding to approved plan to dispatched work to immutable evidence.
Get a demo