Policies & Drift
A policy is a rule that checks your AI assets on an ongoing basis, not just at registration. Collate runs a fixed set of built-in checks against the governance details recorded on each AI asset, such as its data access, risk classification, and evidence on file. Each check returns Passing, Breached, or Not Applicable for that asset. When a check fails, that’s a breach, and it’s listed on the Policy Breaches tab.Note: Policy evaluation currently uses the built-in checks described on this page. Drift monitoring, evaluation of custom policy rules, and enforcement actions (such as blocking an asset or creating a remediation task) aren’t active yet. The Drift threshold check always returns Not Applicable until drift telemetry is available.
Why It Matters
Registration and approval are a snapshot at one point in time. Policies keep checking after that:- Compliance isn’t a one-time check. An asset that passed review can fall out of compliance later, for example if it starts accessing personally identifiable information (PII) without a data protection impact assessment (DPIA) on file, or if human oversight is turned off.
- Breaches point to a specific cause. Each breach ties back to a specific asset and reason, so you know what to fix.
- Coverage is estate-wide by default. The built-in checks run across your whole AI estate, without configuring them per asset.
Access Policies & Drift
- In the left navigation bar, select Governance.
-
Under the AI Assets section, select Policies & Drift.

Explore Policies & Drift Home Page
The home page is split into three parts: a set of status cards summarizing your policy compliance, an Active Policies tab, and a Policy Breaches tab.Status Cards

- Total policies: How many policies were loaded, up to 100.
- Breached today: How many violations in the sample were observed in the past 24 hours.
- Assets affected: How many distinct AI assets appear in the sampled violations.
- Avg time to remediate: Displays a dash. This metric isn’t calculated yet.
Active Policies

- Policy: The policy’s name and a short description of what it checks.
- Severity: How serious a breach of this policy is, for example Medium or Critical.
- Scope: The kind of check it performs (for example, ComplianceCheck or PerformanceStandard) and which assets it applies to, such as Whole estate.
- Enforcement: The enforcement level set on the policy, Warning or Blocking. It’s recorded for reference and doesn’t currently block an asset or trigger any action on a breach.
- Last Updated: When the policy was last changed.
Policy Breaches

- The asset and policy it breached, shown together (for example, the asset “Warehouse SQL Query” with the policy “PII access requires DPIA”).
- The reason, such as “No DPIA on file” or “Not declared.”
- When the breach was detected.
- A Breached status badge.