Ask a question, create an output, or build an app that works across your tools and governed enterprise data.
Get started across the organization
Enterprise AI Control Center
Build an executive AI control center showing every production and pilot AI application, owner, data class, model route, policy status, and monthly spend. Include DLP and release exceptions.
AI
I need scoped access to AI usage metadata and the application registry.
Gatekeepers: AI Gateway + Application RegistryRequesting read-only access to application ownership, model routes, token and cost totals, policy outcomes, and release status. Prompts, responses, customer records, and employee records remain excluded.
Approved for aggregated metadata only. Preserve each viewer's existing permissions.
AI
Access granted. Sharing restrictions will follow every observed resource.
Enterprise AI Control Center is ready with illustrative data. It surfaces two policy exceptions and seven contained DLP events without exposing restricted content.
Draft a target-state Zero Trust blueprint for store support, payment-adjacent applications, corporate workforce, cloud administrators, vendors, and AI agents across a 21,000-plus-store enterprise.
AI
I will ground the blueprint in centrally governed standards and public scale context.
Context library: Architecture + security + complianceLoading read-only architecture principles, security controls, vendor requirements, NIST SP 800-207, and PCI DSS 4.0.1 mappings. Current network topology and cardholder data are not requested.
AI
The blueprint needs four explicit decisions:
1. Human or service identity on every access path 2. Application-level least privilege for store and vendor support 3. Isolated credentials and governed egress for agents 4. Resiliency patterns that cannot become permanent bypasses
AI
Store & Payment Zero Trust Blueprint v1.0 is ready. Every recommendation maps to a guardrail, approval owner, and validation artifact.
Build a 90-day secure AI roadmap for the CIO, CISO, and Head of AI. Prioritize jobs to be done, human ownership, enterprise context, permission boundaries, model controls, and measurable scale gates.
AI
I will request only portfolio-level planning and control data.
Gatekeepers: Portfolio planning + architecture repository + AI GatewayRead initiative names, accountable teams, stage, milestones, approved architecture decisions, and aggregate model usage. Ticket comments and personal data remain excluded.
Approved. Keep recommendations advisory and require named owners for every production workflow.
90-Day Secure AI Roadmap is ready. It links foundation work, cross-functional pilots, champions, and human approval gates to measurable executive outcomes.
Enterprise AI Governance
Illustrative dataLive app
18
Registered production and pilot AI applications
100%
Model calls through an approved gateway
2
Policy exceptions requiring executive review
$42.8K
Illustrative monthly inference spend
Executive attention
Release ownership: One pilot has no named successor for its production workflow. Deployment remains blocked.
Data policy: A supply chain copilot approval expires in three days and needs control-owner review.
DLP working as designed: Seven restricted-data detections were contained this week; blocked values were not sent to model providers.
AI Gateway analyticsAggregate requests, tokens, spend, errors, model routes, and DLP outcomes. Prompt content excluded.
Application registryRead application owner, purpose, data classification, budget, and release state.
Identity policy catalogRead approved user, service identity, and access-policy metadata.
Observed-resource policySharing is allowed only when each viewer can access every resource used to produce the app.
Store & Payment Zero Trust Blueprint v1.0
Illustrative draft
Store & Payment Zero Trust Blueprint
Version 1.0 · Illustrative draft · August 2026 · Owner: Security Architecture
1. Purpose
Define a consistent target state for store support, payment-adjacent applications, corporate workforce, cloud administration, third-party access, and AI automation across a 21,000-plus-store enterprise. This blueprint uses public scale context and does not represent Dollar General's current network topology.
2. Design principles
Attribute every session and action to a verified human or service identity.
Grant application-level access instead of broad network reachability.
Give agents no more permission than the person directing them.
Keep credentials isolated from users, agents, and generated code.
Preserve store resiliency without creating unmanaged bypass paths.
Carry observed-resource authorization into every shared app and output.
3. Control decisions
Zero Trust control decisions by access path
Access path
Target-state decision
Required guardrail
Validation evidence
Store support
Application-specific support access; no standing network reachability
Phishing-resistant MFA, managed device, least privilege
Identity, device, and application-access logs
Payment support
Dedicated, segmented administrative paths for approved services
PCI-scoped policy, explicit service identity, time limits
Control mapping and quarterly access review
Corporate workforce
Identity-aware access and secure web policy
Continuous device and session evaluation
Identity provider, device, and policy telemetry
Third-party support
Approved, time-bound access to named applications
No shared accounts or standing vendor VPN access
Approval, session, expiry, and revocation trail
AI & automation
Service identity, governed egress, and typed resource capabilities
Gatekeeper-held secrets, DLP, approved model routes
Observation log, policy decisions, and usage analytics
Human accountability: AI can summarize context and recommend a response, but it cannot authorize privileged access or a production release. The deterministic workflow pauses for a named human approver.
4. Validation sequence
Inventory critical access paths, assign owners, define evidence requirements, validate representative store and corporate flows, test failure modes, and use measured results as the decision gate for phased rollout.
Grounding sources
Dollar General FY2025 Form 10-KPublic scale, technology modernization, payment protection, cyber governance, and third-party risk context.
NIST SP 800-207Zero Trust architecture concepts and deployment models.
PCI DSS 4.0.1Access control, segmentation, logging, and testing requirements.
Cloudflare OS principlesCurated context, least privilege, Gatekeepers, observed-resource policy, and human ownership.
Document connections
Enterprise context libraryRead-only architecture, security, AI, compliance, and vendor standards.
Access policy catalogRead approved identity, device, application, and service-account patterns.
Architecture repositoryRead decisions and route proposed revisions for human review.
90-Day Secure AI Roadmap
Slide deck
Slide 1 of 4
90-Day Secure AI Roadmap
Governed context. Scoped access. Human accountability.
Slide 2 of 4
Foundation and pilot portfolio
Illustrative secure AI workstreams
Workstream
Accountable team
Stage
Progress
Identity & Gatekeeper patterns
Security Architecture
Validate
55%
AI Gateway policy & spend
AI Platform
Pilot
65%
Enterprise context library
CIO Office
Build
40%
Replenishment exception copilot
Supply Chain
Design
35%
Employee service assistant
HR & IT
Discovery
25%
Illustrative portfolio data for demonstration.
Slide 3 of 4
Executive scale gates
100%Apps have an owner, data class, and budget
100%Model calls use approved gateway routes
0Production releases without required approval
<15mContainment and rollback drill target
Slide 4 of 4
90-day execution path
Days 1-30Baseline. Inventory use cases, assign human owners, classify data, publish context, and recruit champions across functions.
Days 31-60Pilot. Connect scoped resources, encode deterministic workflows, and route model traffic through policy controls.
Days 61-90Validate. Measure quality, safety, cost, user adoption, rollback readiness, and business outcomes.
DecisionScale gate. Approve patterns, owners, funding, and phased expansion based on evidence.
Aggregated source records
Source systems used by the roadmap
System
Scope
Fields used
Permission
Portfolio planning
Secure AI initiatives
Initiative, owner, stage, milestone
Read-only
Architecture repository
AI and access decisions
Decision, state, review date
Read-only
AI Gateway
Approved applications
Aggregate usage, cost, error, policy
Read-only
Scoped data connections
Portfolio planningSecure AI initiatives and milestones only; ticket comments excluded.
Architecture repositoryOpen AI, security, integration, and data decisions.
AI Gateway analyticsAggregated model usage, policy, cost, reliability, and DLP measures.
Context
Illustrative, centrally governed reference material available read-only to authorized agents and workspaces across the organization.
MD
enterprise-strategy.md
Company mission, operating priorities, annual objectives, and key results by business function.
MD
brand-and-customer-experience.md
Brand voice, customer communications, accessibility standards, and approved messaging patterns.
MD
security-and-compliance.md
Enterprise security controls, privacy guardrails, PCI requirements, and cryptographic standards.
MD
responsible-ai-policy.md
Approved AI uses, human accountability, data classifications, evaluations, and release controls.
MD
architecture-principles.md
Technology standards, decision criteria, review templates, and reusable reference patterns.
MD
vendor-risk-requirements.md
Third-party assessment criteria, risk tiers, evidence requirements, and review cadence.
MD
enterprise-service-catalog.md
Illustrative service catalog with ownership, criticality, dependencies, and support expectations.
MD
operations-and-supply-chain.md
Operating procedures, distribution workflows, supplier standards, and exception playbooks.
MD
people-and-hr-policies.md
Hiring, onboarding, leave, performance, employee support, and compensation guidelines.