AI Governance · targe.okodi.ai

Govern AI from the first idea to live in production.

Targe is a multi-tenant SaaS that turns half-formed ideas into graded, gated, audit-ready AI projects. Every tenant gets its own white-labelled subdomain, its own Claude and voice keys, and row-level isolation enforced at the database — not by a WHERE clause.

Targe mark
The problem

AI is shipping faster than the governance to back it up.

UIA and DPIA templates live in scattered Word docs. Compliance is a slide someone updates monthly. Sign-offs happen by email. When a regulator asks show me how this AI system was approved, a spreadsheet is not an answer — and the EU AI Act, POPIA s71, GDPR Art. 22, ISO 42001 and King V don't grade on effort.

End-to-end flow

From half-formed idea to live, one gate at a time.

Every AI initiative in the company walks the same path. No dev without green compliance. No deploy without the sign-offs the playbook requires.

1

Ideas + BA Coach

Anyone can log a half-formed idea. A Coach sub-agent guides framing — problem, users, value, risk. A BA chat (voice or text) drills into scope until the brief is promotable.

2

Promote & analyse

One click turns the idea plus chat history into a project with a pre-filled solution doc, user stories and required stack. The analyser runs synchronously.

3

Stack assessment

Required tech cross-referenced against your approved catalogue. If Clerk is proposed but Supabase Auth is approved, Targe recommends the substitute — automatically.

4

Compliance grading

Every requirement scored against POPIA, GDPR, EU AI Act, NIST AI RMF, ISO 42001, King V. Auto-re-runs when jurisdictions or evidence change.

5

SDLC gates

A five-phase playbook engine enforces the transitions. Server-side. Clients can't fake green — the gate is the database, not the UI.

6

Live, tracked, reported

Sponsor and steerco views, model + prompt versioning, incident register, DPIA on demand, quarterly workspace review exported to PowerPoint in a click.

Inside the portal

What governance teams actually get.

BA chat with voice + avatar

Push-to-talk transcript in, streamed audio out, animated avatar. Generates DPIAs, user stories and risk callouts on demand. BYO ElevenLabs key.

Solution intake analyser

Upload the BA doc; Claude decides whether it's AI-related, extracts user stories with acceptance criteria, proposes an approach, lists the stack — under your Claude key.

Model & prompt versioning

Every model and prompt change is hashed and dated. Compliance re-runs automatically. "What was the model running when this decision was made?" — answerable to the day.

Workspace compliance review

Quarterly AI-strategy review grounded in NIST AI RMF, covering AI Policy, Roles & Responsibilities matrix and 12-month Roadmap. One-click export to a board-ready .pptx.

AI incident register

Severity 1 → 4 lifecycle, server-enforced state machine, auto-fires alerts for sev 1/2. Closes SOC 2 CC7.3 evidence — no more Slack-thread-as-incident-record.

Acceleration kit

UIA scorer, Claude 14-item enforcement checklist, vendor due-diligence RAG scoring, agent prompt library — persisted per project.

Try Targe free

Get a workspace in minutes.

Bring your own Claude and voice keys, register your first initiative, and see the compliance grade before you commit to anything.

Your own tenant workspace

Row-level isolation from day one. You get {workspace}.targe.okodi.ai, an admin seat, and space for your team.

BYO Claude + ElevenLabs keys

Your keys, envelope-encrypted at rest. Your model traffic never mixes with anyone else's. You keep the invoice.

All frameworks unlocked

Toggle POPIA, GDPR, EU AI Act, NIST AI RMF, ISO 42001, King V. Grade a real initiative against the strictest control set that applies.

Full audit trail included

Every decision written down, append-only, tamper-evident. Export a board-ready PowerPoint for your next steerco.

No credit card required. Upgrade when you're ready.

Prefer a walkthrough first?

See Targe with a real initiative.

Bring an AI project you're weighing up — internal, live or paused. We'll walk it through the flow end-to-end in under an hour.

Book a walkthrough
Governance coverage

The frameworks Targe grades against.

Turn on ZA, EU, US, UK or Global from Settings. A highest-standard resolver picks the strictest applicable control set — EU's 72-hour breach window wins over POPIA's "reasonable time", and so on.

POPIA

s8 lawful basis · s71 automated decisions and right-to-recourse · Cybercrimes Act alignment.

GDPR

Art. 6 lawful basis · Art. 22 right to explanation · Art. 35 DPIA · Chapter V cross-border transfers.

EU AI Act

Annex III high-risk triage · Annex IV technical documentation · model and prompt versioning.

NIST AI RMF

Map · Measure · Manage · Govern — the workspace compliance review is grounded in this framework.

ISO 42001 & King V

§7.4 AI management responsibilities · ethical leadership · board-level visibility · documented decisions.

Michalsons & SOC 2

AI Policy · Roles & Responsibilities matrix · 12-month Roadmap · SOC 2 CC7.3 incident response evidence.

How it's built

The boundary is the database, not the app.

Real multi-tenancy, real key isolation, real audit — the parts that matter when a CISO reads the security questionnaire.

Row-level tenant isolation

Postgres RLS on every tenant-owned table with FORCE ROW LEVEL SECURITY. 42 pgTAP assertions prove tenant A can't read tenant B — in CI, every commit.

Envelope-encrypted BYO keys

Per-tenant Claude and ElevenLabs keys, AES-256-GCM encrypted, master key from KMS. Decrypted in memory for a single run; buffer zero-filled in finally.

Append-only audit log

RLS denies UPDATE and DELETE. Every gate transition, evaluation and key rotation is recorded and tamper-evident — readable only to the tenant that owns it.

White-label, out of the box

Each tenant gets {tenant}.targe.okodi.ai, plus an optional custom domain. Brand colours and logo drive the whole portal via CSS variables.

Frequently asked

AI governance, answered.

The questions we hear most from executives and risk owners weighing up an AI governance platform.

What is AI governance?

AI governance is the set of policies, controls and evidence that decide which AI initiatives a company runs, how they are approved, how they are monitored in production, and how the record survives an audit. It sits between AI strategy and day-to-day AI use — the layer that turns "we should govern this" into a system of record.

Does my company need AI governance?

If your teams already use AI — even informally, in copilots, chatbots or spreadsheets — you already need governance. The question is whether it is written down or whether the person answering "who approved that?" is guessing. Any company subject to POPIA, GDPR, the EU AI Act, ISO 42001 or a board risk register benefits from formal AI governance.

Is AI governance legally required in South Africa or Namibia?

Not as a standalone law today, but it is required to comply with several existing laws that touch AI. POPIA (South Africa) governs automated decisions and personal data. GDPR applies if you process EU data. The EU AI Act applies to any high-risk AI system used with EU users. King V requires the board to oversee technology risk — which now includes AI. Targe grades against all of these automatically.

What is the NIST AI RMF, and does Targe use it?

The NIST AI Risk Management Framework is the US National Institute of Standards and Technology's voluntary framework for governing AI — organised around four functions: Govern, Map, Measure and Manage. It is the most widely adopted AI governance framework in the world. Yes — Targe's workspace compliance review and playbook engine are structured around the four functions.

How is Targe different from an AI policy document?

A policy document is a snapshot in time. Targe is the system that enforces the policy at every idea, every model change, every gate and every deploy — and writes the evidence down as it happens. When a regulator asks for proof, you point them to the append-only audit log, not a Word file.

Can Targe support POPIA and GDPR compliance for AI systems?

Yes. Targe grades every registered AI initiative against POPIA, GDPR, EU AI Act, ISO 42001, NIST AI RMF, King V and Michalsons — automatically and continuously. Turn on the frameworks that apply to you and every project inherits the strictest applicable control set.

Further reading

From the Targe field notes.

All posts →