The Tenet control plane

One policy model across two planes of AI.

An AI governance control plane is the policy layer that decides who may use which AI capability, for what purpose, with which data, under which authority, and with what evidence. Tenet applies that model across separate direct-use and backend paths.

Map your district's AI planes
Shared governance

Consistency belongs in policy, not in a universal traffic funnel.

A person using an AI product and an application calling an AI model require different enforcement points. The control plane lets the district express a consistent policy model for both.

One district policy model, applied across two separate AI enforcement planes
District control planeWho + authority + purpose + data + model + evidence
01Available now

Tenet Edge

People use supported AI products directly on managed devices.

Policy applied locallyAllow · guide · redact · block
02Founding-district program

Tenet Gateway

District applications call approved model deployments in the backend.

Operation authorized firstAllow · constrain · deny · record
Six decision dimensions

Every governed operation should have an answer.

The exact inputs vary by plane. The decision model stays legible to district leaders, technology teams, educators, and application owners.

01

Who

Which person or application is acting, and what trusted context is available?

02

Authority

What role, class, delegated scope, or application permission authorizes the action?

03

Purpose

What approved educational or operational task is the AI being used to perform?

04

Data

What information is involved, and what boundary or transformation must apply?

05

Model

Which AI service or model deployment is eligible for this actor, purpose, and data?

06

Evidence

What bounded decision record is needed for review, and where should it live?

Policy lifecycle

From district intent to an operational decision.

Governance remains understandable only when policy authorship, technical delivery, execution, and review can be traced as one lifecycle.

01

Define

Translate board policy, administrative guidance, classroom rules, tool approvals, and data requirements into explicit decisions.

02

Distribute

Deliver the appropriate configuration to Tenet Edge and, for founding program work, the Gateway reference architecture.

03

Decide

Use the trusted context available in that plane to allow, guide, constrain, protect, or deny the operation.

04

Review

Send bounded operational evidence to configured district-owned systems and revise policy with accountable human oversight.

Separation by design

The shared policy model does not erase technical boundaries.

The two planes can align on governance questions without sharing content paths, product status, or enforcement mechanics.

Control-plane elementTenet EdgeTenet Gateway
Trusted identityManaged user and available district classroom contextScoped application identity and optional acting-person context
Policy deliveryConfiguration for the managed Chrome clientVersioned policy inputs in the reference architecture
Content pathPerson to supported AI surfaceApplication to approved model deployment
Primary decisionHow direct use should proceedWhether a backend operation is authorized
Operational statusAvailable nowFounding-district program
District ownership

Governance should remain accountable to the district.

Tenet is designed to make district policy explicit and operational while preserving clear human responsibility for policy, approval, and review.

  • 01
    The district defines acceptable use

    Tenet operationalizes district decisions; it does not replace local governance.

  • 02
    The district selects approved services

    Tool and model eligibility remain part of the district's technology and instructional program.

  • 03
    The district chooses evidence destinations

    Configured analytics can align with systems the district controls.

  • 04
    People remain accountable

    High-impact educational and operational decisions require responsible human review.

Map the control plane

Bring one policy and two real AI workflows.

We will help distinguish direct use, backend operations, shared rules, and the boundaries that should stay separate.