Your AI rollout is now a permissions problem.
Every team picked a different assistant. Every assistant wants its own connectors. Every connector has its own permission model, its own admin screen and its own idea of who you are. Govna collapses that into one address, one approval screen and one audit trail — without asking anyone to change the tool they like.
Every new assistant multiplies the permissions you own
Each client wants its own connector to each app, and each of those connectors has its own permission model and its own admin screen. The work is not the rollout — it is keeping all of it in agreement.
20 permission models, four admin surfaces, no shared record.
One session trail across every assistant and every app
Which app was called, which tool, by which person, under which login, at what time, and what came back — in one place, whichever client made the request.
| Time | Authorized by | Client | App · tool | App login | Outcome |
|---|---|---|---|---|---|
| 14:02:11 | dana@acme.com | Claude | salesforce · search_records | sfdc-readonly | allowed |
| 14:02:48 | dana@acme.com | Claude | google · read_document | workspace-team | allowed |
| 14:06:02 | ravi@acme.com | Cursor | atlassian · create_issue | jira-bot | pending |
| 14:07:19 | ravi@acme.com | Cursor | github · merge_pull_request | gh-service | denied |
| 14:11:37 | lena@acme.com | ChatGPT | sentry · list_issues | sentry-readonly | allowed |
The four things that actually decide this
Not features — the questions the decision turns on.
Stop re-solving access per tool
Set permissions once, at the app. Every assistant your teams use reaches them the same way — nothing to rebuild when a team switches tools next quarter.
Let teams move without a ticket queue
Permission sets give a team the access its job needs in one click, inside limits you set. Self-service that does not become a permanent exception.
Have one answer for the auditor
One searchable trail across every client and every app: who authorized it, what it reached, what happened. Not four exports you have to reconcile.
Days to set up, not a quarter
Connect an app, approve its tool list, write two permission sets. If what you need is not an MCP server, point Govna at its OpenAPI description instead — an internal REST service becomes a governed tool without anyone building an integration for it.
One call, end to end
The same seven stages apply no matter which client made the request.
Where to go next
Two readers, two different next steps.
Start with the words: permission set, session, approved tool list, receipt.