WHAT IT READS
Named sources, and a posture per source.
Each source is a shipped adapter with a real parsing contract. Each carries a posture derived from live wiring rather than a marketing list — so the surface cannot claim a source the backend cannot actually ingest. The per-vendor parsing contracts are set out on the platform page; this is the short list.
SIEM & log
- Splunk
- Microsoft Sentinel
- Datadog
- Generic SIEM webhook
- Plain log lines
HTTP Event Collector including the batched newline-delimited stream, Azure Monitor / Log Analytics common-schema columns, and the Datadog logs intake with ddtags decomposed into user, host and env dimensions.
Secure egress & endpoint
- Zscaler
- Netskope
- Palo Alto Networks
- CrowdStrike
Internet Access web logs by way of Cloud NSS; CASB, SWG and web-transaction events; PAN-OS TRAFFIC and URL logs from Strata Logging Service. Threat and WildFire logs are deliberately out of scope — that is malware signal, not AI-usage signal.
Identity
- Okta
- Microsoft Entra ID
- Google Workspace
- Microsoft 365 Copilot
System Log OAuth grants and application sign-ins, directory audit events, admin Reports token grants on a scheduled poll, and Graph Copilot usage reports for the ongoing activity a one-time consent event does not cover.
LLM gateways
The gateway's own per-request logs, ingested as an AI-usage feed: which models and providers each user and key actually called. Both are coexistence feeds — GovernorAI reads the gateway's telemetry rather than becoming the gateway.
Cloud AI platforms
- AWS Bedrock
- Microsoft Azure
- Google Vertex AI
- Databricks
Enumerated with list and get calls against the control plane, per configured region, and resolved to detail records where the role permits it.
Enterprise SaaS
- Salesforce
- ServiceNow
- Microsoft 365
- Workday
- SAP AI Core
- Atlassian
- Slack
- Zendesk
- HubSpot
- n8n
Each a connector against the platform's own API, with required credentials and supported auth types stated per platform. Only Salesforce and ServiceNow support a single connection carrying both discovery and governed execution; the rest are discovery-only.
MCP & frameworks
- Official MCP registry
- GitHub discovery
- Your manifest repo
- LangChain
- LangGraph
- CrewAI
- n8n
Catalog entries move through discovered, validated, assessed and then approved, blocked or quarantined. Framework runtimes are registered through onboarding or by the runtime itself.
connected An enabled feed exists And it reports its own health: healthy, stale or not configured. A feed that is enabled but has never reported is stale, because silence is not health.
available Shipped, not yet wired The adapter is registered and the catalog will offer it. Nothing about that source is being read until you connect it.
planned Nothing ships Printed rather than omitted, so the coverage grid shows a genuine gap instead of a blank cell.