> ## Documentation Index
> Fetch the complete documentation index at: https://oximy.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Tool governance and access

> Review AI tools, respond to access requests, and manage policy-driven controls.

Tool governance turns discovered usage into explicit administrative decisions. The governance workspace covers tool review, access requests, policies, and the detections associated with those policies.

<Tabs>
  <Tab title="Tool review">
    Review discovered tools by status. The shipped status model includes pending,
    approved, unapproved, flagged, warn, and blocked states. Open a tool to
    review its evidence before changing its posture.
  </Tab>

  <Tab title="Access requests">
    Administrators can review pending requests and record an approval or denial.
    Completed requests remain available in their corresponding status views.
  </Tab>

  <Tab title="Policies">
    Create and edit policy definitions, control whether an active policy is
    enabled, and review associated detections and alert rules. Draft policies
    can be deleted.
  </Tab>
</Tabs>

## Governance workflow

<Steps>
  <Step title="Review the evidence">
    Check observed usage, users, departments, account posture, and available
    spend context.
  </Step>

  <Step title="Choose the tool posture">
    Record the status that matches your organization's approved-tool process.
  </Step>

  <Step title="Handle access">
    Approve or deny requests using the tool decision and the requester's
    business context.
  </Step>

  <Step title="Apply policy">
    Use a policy when a repeatable condition should be detected or communicated
    consistently.
  </Step>

  <Step title="Revisit detections">
    Review active detections and alert routing as tools, teams, and policies
    change.
  </Step>
</Steps>

<Info>
  Tool review, access decisions, and policy administration are restricted to
  authorized roles. Read access to related analytics can be broader than write
  access to governance controls.
</Info>

## Access to Visibility data

Workspace administrators can assign Visibility roles and grants that combine:

* A module-access set
* Organization-wide or department-based row scope
* Financial-field access

These permissions affect the data and pages available to a viewer. They are separate from a tool user's request to access an AI product.
