New One-call approvals are live in the console
For the org-wide AI rollout

Your AI rollout is now a permissions problem.

Every team picked a different assistant. Every assistant wants its own connectors. Every connector has its own permission model, its own admin screen and its own idea of who you are. Govna collapses that into one address, one approval screen and one audit trail — without asking anyone to change the tool they like.

01 Problem

Every new assistant multiplies the permissions you own

Each client wants its own connector to each app, and each of those connectors has its own permission model and its own admin screen. The work is not the rollout — it is keeping all of it in agreement.

Salesforce
GitHub
Google
Atlassian
Sentry
Claude
ChatGPT
Cursor
Custom agents

20 permission models, four admin surfaces, no shared record.

One address
agw.govna.io/mcp
One approval screen
the same consent every time
One audit trail
every call, every client
02 Audit trail

One session trail across every assistant and every app

Which app was called, which tool, by which person, under which login, at what time, and what came back — in one place, whichever client made the request.

Time Authorized by Client App · tool App login Outcome
14:02:11 dana@acme.com Claude salesforce · search_records sfdc-readonly allowed
14:02:48 dana@acme.com Claude google · read_document workspace-team allowed
14:06:02 ravi@acme.com Cursor atlassian · create_issue jira-bot pending
14:07:19 ravi@acme.com Cursor github · merge_pull_request gh-service denied
14:11:37 lena@acme.com ChatGPT sentry · list_issues sentry-readonly allowed
03 Substance

The four things that actually decide this

Not features — the questions the decision turns on.

Stop re-solving access per tool

Set permissions once, at the app. Every assistant your teams use reaches them the same way — nothing to rebuild when a team switches tools next quarter.

Let teams move without a ticket queue

Permission sets give a team the access its job needs in one click, inside limits you set. Self-service that does not become a permanent exception.

Have one answer for the auditor

One searchable trail across every client and every app: who authorized it, what it reached, what happened. Not four exports you have to reconcile.

Days to set up, not a quarter

Connect an app, approve its tool list, write two permission sets. If what you need is not an MCP server, point Govna at its OpenAPI description instead — an internal REST service becomes a governed tool without anyone building an integration for it.

04 Chain of command

One call, end to end

The same seven stages apply no matter which client made the request.

Someone asks
Permission set
Login
Tool
Rules
Outcome
Receipt
01 Someone asksA person asks an agent to do something, starting from a permission set.
Next step

Where to go next

Two readers, two different next steps.

Rollout path

The order that survives a security review.

Everyone else

Start with the words: permission set, session, approved tool list, receipt.