Campus AI Development Governance checklist

13 — Governance checklist

Settle policy before buying tools

Thirteen questions every institution should be able to answer before scaling AI-assisted development. Tick them off as you go; your answers stay on this device.

13 questions · your answers are saved on this device

After proliferation

Know which agents are running

Once building is cheap, the number of agents and automations outgrows anyone’s memory. A policy can say who may build; these controls show what was built, what it can reach and what it costs.

  1. 01A registry of agents and automationsEvery agent, scheduled job and automation that touches institutional systems is listed with its owner, purpose, data it reads, systems it writes to and review date. See campusairegistry.com for a registry model.Security · IT operations
  2. 02Scoped, revocable credentialsEach agent gets its own service identity with the narrowest scope, never a person’s login. Credentials expire and can be revoked in one place.Identity and access management
  3. 03Budgets and rate limitsPer-team token and API budgets, alerts at thresholds and a kill switch, so one runaway loop can’t drain a shared pool.IT finance · Platform team
  4. 04Audit logs that outlive the builderActions are logged to a central store the builder can’t edit, kept on the institution’s retention schedule rather than in a personal account.Security operations
  5. 05Shared-resource limitsQuotas on compute, storage and calls to the student information system and other shared systems, enforced by the platform rather than by goodwill.Enterprise architecture
  6. 06OffboardingWhen a builder leaves or changes role, their agents are reassigned or retired, and their credentials revoked, as part of normal offboarding.HR · IT service management
The shared-pool failureA campus license often pools tokens or API calls across many users. An agent stuck in a retry loop, or a popular tool nobody budgeted for, can exhaust the pool and stop everyone’s work. Budgets per team and an alert before the limit matter more than the total.

Sequencing

Fix the data before scaling agents

Agents multiply whatever disorder the data already has. If three offices define a “registered student” three ways, three agents will report three numbers, faster and with more confidence. Settle the foundations in this order; campusdatagov.com covers data governance in depth.

  1. 01Agree on definitionsPublish a data dictionary for the terms agents will query: enrolled, registered, active, full-time, retained.
  2. 02Name ownersEach data domain has a steward who approves which agents may read it and for what.
  3. 03Point at the source of truthAgents read the system of record, not exports, spreadsheets or shadow copies.
  4. 04Set access rulesMap each data classification level to roles and approved tools before any agent credential is issued.
  5. 05Then scaleAdd agents domain by domain, starting where definitions are already settled.

Licensing, IP and open source

Who owns what the model wrote

The checklist asks how licenses are reviewed. In practice, four questions come up for research software and operational tools alike.

OwnershipState how the institution’s IP policy treats AI-assisted work by staff, faculty and students. In the US, the Copyright Office has said purely AI-generated material isn’t protected without human authorship.
ReleaseBefore publishing generated code as open source, check the tool’s terms, scan for license matches and confirm the institution’s open-source policy allows it.
License conflictsTurn on public-code filters where the tool offers them, scan for matches to licensed code, and prefer enterprise terms that include IP indemnity.
Research softwareRecord AI assistance in the repository and citation file. Funders and journals increasingly expect disclosure.