Joyst

Gareth MorgansGovernance

AI governance for skills, prompts, MCPs, secrets, and agents

Most "AI governance" results talk about policy frameworks, model risk, and responsible-AI programmes. Those matter -- and they still leave a gap if you cannot control the skills, prompts, MCPs, secrets, and agents your people run every day.

That gap is the asset layer. Joyst is an AI governance platform for that layer: permissions, folders, and an audit trail. Not a generic GRC suite. Not an IDP with scorecards.

Start free beta | AI governance


Related: ownership of skills and prompts | private MCP catalog vs marketplace | Joyst for platform teams.

AI governance platform for the asset layer

Your team's AI capability lives in concrete artefacts:

If those assets have no owners, no publish gates, and no audit, governance stays a PDF. Productised control means view / use / manage rights on the things people actually change.


Permissions and audit

Governance you can operate looks like:

  • Groups and folders so large catalogues stay workable

  • Draft vs published so experiments are not the live path

  • An audit trail of who changed which prompt, skill, MCP entry, secret reference, or agent package

  • Approved catalogues so usage stays within what the org signed off

Detail on controls: permissions and audit trail.


Vs model-risk GRC and vs IDP

Model-risk and responsible-AI programmes set standards. They rarely inventory your Cursor rules or which MCP server someone connected last week.

Internal developer portals catalogue software services and scorecards. Joyst catalogues the AI asset layer. Use both -- see beside your IDP and AI registry vs developer portal. Joyst does not replace Backstage, Port, OpsLevel, or Cortex.


Agentic AI governance (Joyst sense)

Governing agents means governing what packages include and who can publish or use them -- including MCP tools and how secrets are referenced. It is not a multi-agent orchestration runtime.

Keep keys out of model context via the secrets vault. Package setups under agents.


FAQ

What is an AI governance platform (Joyst definition)?

A product that controls permissions and audit for the AI assets your teams use -- skills, prompts, MCPs, secrets, and agents -- in a private org catalogue.

Is this responsible-AI ethics software?

No. We do not sell ethics programmes or model-risk frameworks as the core product. We govern the asset layer those programmes often leave uncontrolled.

Do we replace our GRC stack?

No. Joyst sits beside policy and risk tools. It productises control of day-to-day AI assets.


Start free beta | Book a demo | Pricing