Joyst

AI GOVERNANCE

AI governance for the assets your teams actually use

Most AI governance search results talk about policy frameworks and model risk. Those matter — and they still leave a gap if you cannot control the skills, prompts, MCPs, secrets, and agents your people run every day. Joyst is an AI governance platform for that asset layer: permissions, folders, and an audit trail. Not a generic GRC suite. Not an IDP with scorecards.

dash.joyst.app
Group permissions for catalogue resources in Joyst Admin

ASSET-FRAMED

AI governance platform — asset-framed

  • Skills, prompts, MCPs, secrets, agents

    Joyst’s AI governance platform lane is the asset layer your teams actually use — not a policy PDF programme or a model-risk checklist alone.

  • Productised control

    Permissions, folders, and audit on catalogue assets. What Joyst governs is productised control of that layer — not a generic GRC suite.

  • Not ethics-as-product

    Responsible-AI programmes and compliance frameworks still matter. They still leave a gap if nobody controls the skills, prompts, MCPs, secrets, and agents in daily use.

PERMISSIONS

Permissions that match how teams work

  • View, use, and manage

    View / use / manage tiers map to real work. Groups and folder bulk permissions keep large catalogues workable. Drafts stay private until ready.

  • Groups and folders

    Grant rights on assets and folders for the right groups so platform and security buyers scale access without a ticket queue nobody will use.

  • One model across pillars

    The same permission model covers prompts, skills, MCP entries, secret references, and agent packages — so governance does not fragment per tool.

AUDIT

Audit trail

  • Who changed what

    See who changed which prompt, skill, MCP entry, secret reference, or agent package — instead of “someone updated it in Slack.”

  • Central review

    Review changes across the private team catalogue so ops and security share one picture of what moved.

  • Tied to permissions

    Audit sits beside view / use / manage rights — who can change an asset and who did change it stay linked.

APPROVED USE

Approved catalogues

  • Prompts and skills signed off

    Tie governance to approved prompts and published skills so everyday reuse stays within what the org has signed off.

  • MCP allow-list

    Allow-list MCP servers the team and agents may use — rather than unmanaged one-off connections.

  • Secrets kept out of context

    Approved catalogues and secrets kept out of model context keep packages within signed-off use.

AGENTS

Agentic AI governance

  • Govern packaged agents

    Governing agents means governing what packages include and who can publish or use them — including MCP tools and how secrets are referenced.

  • What agents can call

    Control which approved skills, prompts, and MCP servers agent packages may pull — not inventing one-off ingredients per harness.

  • Not a multi-agent runtime

    Joyst governs packaged agents and what they include. It is not a multi-agent orchestration runtime.

BESIDE YOUR IDP

Beside your IDP — not instead

  • Different catalogues

    IDPs catalogue software services and scorecards. Joyst catalogues the AI asset layer — skills, prompts, MCPs, secrets, and agents.

  • Use both

    Platform teams keep their IDP for services. Joyst sits beside it for the AI assets those services and agents consume.

  • Not a replacement claim

    We do not replace Backstage, Port, OpsLevel, or Cortex. Beside your IDP — not instead.

AI governance FAQ

Permissions, folders and an audit trail over the AI assets your teams actually use — skills, prompts, MCPs, secrets and agents — in a private organisation catalogue. Not a generic GRC or responsible-AI ethics programme sold as product.

IDPs catalogue software services and scorecards. They still leave a gap if skills, prompts, MCPs and agent packages spread ad hoc. Joyst sits beside the IDP for that AI layer.

When agents are packaged setups — govern what packages include and who can publish or use them, including which MCP tools and how secrets are referenced. Joyst isn’t a multi-agent runtime.

Govern the AI assets your teams actually use

Start free beta