Configure governance once. Not once per vendor.
You own the connectors, the identities and the blast radius. Govna gives you one connection address that every client — Claude, ChatGPT, Cursor, custom agents, CLI tools, desktop apps — reaches under the same approval screen.
The four things that actually decide this
Not features — the questions the decision turns on.
One integration surface
Apps, logins, permission sets and rules are set up once and apply to every client. No per-vendor integration to build or maintain.
Change is reviewable
An app update lands as something to review: new tools hidden, changed tools paused, removed tools stopped, until you approve.
Policy where you need it
Checks run before a call and after it. Deny, require approval, or trim the request — never expand it.
Rollout without exceptions
Permission sets let teams help themselves inside limits you set, instead of asking you for a permanent exception.
One call, end to end
The same seven stages apply no matter which client made the request.
Where to go next
Two readers, two different next steps.
Start with the words: permission set, session, approved tool list, receipt.