Whitepaper

The principal model: human and AI governance actors

How Procela models authority for stewards, owners, and agents — and the three-tier autonomy framework behind it.

By the Procela team · 8 min read

Governance is ultimately about accountability: who is responsible for a piece of data, and what are they allowed to do with it. As AI systems begin to take on real governance work — classifying assets, proposing owners, flagging policy violations — that question gets sharper. A recommendation is only trustworthy if you know exactly who or what made it, and under what authority. Procela's answer is the principal model.

What is a principal?

A principal is any actor that can hold a governance role — a human or an AI agent — with a defined scope of authority. Every action in Procela is attributable to a named principal, and every principal's authority is explicit. There are no anonymous, ambient decisions.

Human principals

Data owners and domain stewards are the familiar roles. Owners are accountable for a domain; stewards do the day-to-day work of classification, review, and remediation. In Procela these aren't just labels in a spreadsheet — they carry an explicit scope of authority, and their decisions are logged against them.

AI principals

The important move is treating AI agents as first-class principals rather than as background automation. An agent that reviews classifications or proposes stewardship assignments is a named actor with its own scope and its own audit trail. You can see what it did, why, and on whose authority — just as you can for a human.

app.procela.ai
Procela agents view listing AI, pipeline, and service-account principals with their type and status.

AI agents and service accounts modeled as named principals, each with a type and status.

A framework for autonomy: three tiers

Not every governance task warrants the same level of independence from an agent. A useful way to reason about how humans and AI share authority is to think in three tiers:

Procela's AI agents today operate in the more conservative end of that spectrum: they are AI-assisted, run on a schedule, and are review-gated, so a human confirms their work before it takes effect. The framework is a way to talk about how much authority you extend to an agent for a given kind of work — from low-risk catalog hygiene to strictly advisory handling of export-controlled data.

Authority, scope, and auditability

Every principal's authority is bounded and inspectable. Because roles and process ownership are explicit, Procela can derive a full RACI matrix — who's Responsible, Accountable, Consulted, and Informed for every activity — automatically.

app.procela.ai
Procela RACI matrix mapping process activities to responsible, accountable, consulted, and informed principals.

A RACI matrix generated from process ownership and governance-role assignments.

Combined with a tamper-evident log of every classification, assignment, and policy decision, that means you can always answer the auditor's core question: who did this, and were they allowed to?

Why it matters for regulated environments

In defense, financial services, and healthcare, “the system did it” is not an acceptable answer. The principal model makes AI participation defensible by keeping it accountable — every actor named, every authority explicit, every action logged.

← Back to resources

See Procela against your environment

We'll walk through how this applies to your stack and stand up a governance baseline.

Request a demoExplore the platform