Governance and Compliance

Policies, controls, review processes, auditability, identity/auth, and guardrails required to safely operate APIs, MCP servers, and agents in enterprise environments.

Problem Statements (42)

Problem Statement Context Impact Naftiko Today Naftiko Tomorrow Type
Need Governed Approach to 3rd-Party Services via MCP
Teams are independently adopting 3rd-party MCP servers without a governed approach to discovery, onboarding, and authentication.
Laura (Head of AI) — AI Context Delivery, Governance and Compliance
Need to Securely Enable MCP in Developer IDEs
Security teams must evaluate and approve MCP server usage within developer IDEs before enterprise-wide adoption can proceed.
Morgan (Security & Compliance Lead) — AI Context Delivery, Governance and Compliance, Agent-Ready Developer Experience
Need MCP Streaming to Work with Enterprise Security
HTTP streaming and SSE connections required by MCP and AI services conflict with existing corporate security policies and infrastructure.
Morgan (Security & Compliance Lead) — AI Context Delivery, Governance and Compliance
Need Agent-to-Agent Identity Propagation
Identity and authorization tokens must be properly propagated when AI agents call other agents or services in multi-hop scenarios.
Morgan (Security & Compliance Lead) — Governance and Compliance
Need AI FinOps
Organizations need to understand and control the total cost of ownership across AI models, MCP servers, and third-party services.
Laura (Head of AI) — Governance and Compliance, Cost and Operations
Need MCP to Integrate with Existing Governance Tooling
Organizations need to understand how MCP fits into existing API infrastructure and governance tooling they have invested in over the past decade.
Pat (Head of Platforms) — AI Context Delivery, Governance and Compliance
Need Governance Rules in Coding Assistants
Governance rules need to be available directly in developers' coding assistants and AI agents, not just in standalone tools and pipelines.
Riley (Head of APIs) — AI Context Delivery, Governance and Compliance, Agent-Ready Developer Experience
Need Governance Rule Distribution in Restricted Environments
Enterprise security restrictions prevent using standard distribution mechanisms to deliver governance rules to all API designers.
Riley (Head of APIs) — Governance and Compliance
Need Governance Review Tracking
Morgan needs to track and report on API governance reviews across the portfolio.
Morgan (Security & Compliance Lead) — Governance and Compliance
Need Centralized Credential Management
Morgan needs teams to obtain API tokens and keys from an internal gateway rather than directly from 3rd-party providers.
Morgan (Security & Compliance Lead) — Governance and Compliance
Need to Govern AI-Generated Code
Morgan needs to ensure AI coding assistants follow security policies when generating code, with attestation of compliance.
Morgan (Security & Compliance Lead) — Governance and Compliance
Need Governance Framed as Golden Path
Developers perceive governance as friction and avoid it unless compliance is the easiest path.
Riley (Head of APIs) — Governance and Compliance
Need Governance to Be Seamless
API governance must be embedded seamlessly into the developer workflow so that the compliant way of building APIs is also the easiest and most secure way.
Pat (Head of Platforms) — Governance and Compliance
Need Governance for Agent-Driving Docs
Organizations can enforce coding standards and CI gates but cannot enforce equivalent governance for the Markdown files that shape AI agent behavior.
Riley (Head of APIs) — Governance and Compliance, Agent-Ready Developer Experience
Need Explicit Agent Boundaries
Repositories need to explicitly declare what AI agents are allowed to change and what is off-limits.
Morgan (Security & Compliance Lead) — Governance and Compliance, Agent-Ready Developer Experience
Need to Govern the Proliferation of Agent Communication Protocols
Beyond MCP, protocols like A2A, ACP, AP2, and x402 are proliferating — enterprises need unified governance across all agent communication protocols, not just one.
Riley (Head of APIs) — Governance and Compliance, Agent-Ready Developer Experience
Need APIs Ready for Agentic Commerce and Autonomous Transactions
Agentic browsers and AI workspaces will autonomously discover, evaluate, and transact via APIs — organizations need APIs that are not just discoverable but transactable by agents with proper governance guardrails.
Nico (Partner/Integration AI Lead) — Agent-Ready Developer Experience, Governance and Compliance
Need an Internal MCP Server Registry as an Allow-List
Enterprises need an internal registry of approved MCP servers that surfaces inside the developer IDE, acting as an allow-list so developers discover only vetted servers.
Maya (Developer Experience & AI Engineering Lead) — AI Context Delivery, Governance and Compliance, Discoverability and Reuse
Need to Separate MCP Discovery Registry from Package Distribution
The MCP discovery registry (which servers are approved) and the package registry (where the binary actually lives) are two different systems with different governance requirements.
Maya (Developer Experience & AI Engineering Lead) — AI Context Delivery, Governance and Compliance
Need to Align Enterprise AI Rollout with Product GA Timing
Enterprise contracts only cover generally-available features, so AI tooling rollouts at scale must wait for GA even when developers are already asking for preview capabilities.
Maya (Developer Experience & AI Engineering Lead) — Governance and Compliance
Need Cross-Organizational Patient-Centered Data Flow Across Legal Silos
Iris sees the patient's data sit in adjacent organizations that legally cannot share it — region vs municipality, primary vs secondary purpose, country vs country — even though all of them care for the same person. She needs a patient-centered data fabric that the law can actually permit.
Iris (Healthcare Data Standards Researcher) — Governance and Compliance
Need Synthetic Data Generation for Regulated-Domain Research Access
Iris waits months to years for ethical approvals and data extractions before she can touch real patient data. She needs a synthetic-data pipeline that's data-driven, schema-conformant, and privacy-preserving — so research can move while the legal track runs in parallel.
Iris (Healthcare Data Standards Researcher) — Cost and Operations, Governance and Compliance
Need Standards Adoption Forced by Regulation
Iris has watched well-designed healthcare data standards stall for years until regulation made them mandatory — FHIR via 21st Century Cures, openEHR via the European Health Data Space. She needs the regulation-to-implementation path to be cheap, demonstrable, and reusable.
Iris (Healthcare Data Standards Researcher) — Governance and Compliance
Need Multi-Stakeholder Patient-Centered Interoperability
Iris's project pulls in a vendor, a consultancy, a healthcare provider, and a university — each cares about a different slice of the same patient. She needs an interoperability fabric that lets every stakeholder see only what they should and contribute only what they own.
Iris (Healthcare Data Standards Researcher) — Governance and Compliance, Discoverability and Reuse
Need Governance Investment Paired with Cost-Driven API Centralization
Enterprises that centralize APIs purely as a cost-reduction play without pairing governance investment end up paying the governance bill later — usually right when AI and agent rollouts make the gap visible.
Pat (Head of Platforms) — Governance and Compliance, Cost and Operations
Need Internal API Marketplace with Admin Model From Day One
Internal API marketplaces shipped without a defined roles, permissions, and admin-ownership model become unworkable — discovery surfaces with no governance underneath cost more to maintain than they save.
Pat (Head of Platforms) — Discoverability and Reuse, Governance and Compliance
Need Policy Enforcement for Enterprise AI Consumption
Enterprises need a gateway-enforced layer that authenticates, meters, and tier-routes employee and application AI consumption — not just visibility into spend, but active enforcement of token quotas, model-tier fallback, and outbound traffic restrictions.
Laura (Head of AI) — Governance and Compliance, Cost and Operations
Need Air-Gapped Agent and MCP Deployment
Regulated enterprises need agentic and MCP runtimes that deploy fully inside their own VPC, OpenShift, or air-gapped environment — with complete traceability of every call — rather than depending on SaaS control planes or pay-per-use utility-model vendors.
Morgan (Security & Compliance Lead) — Governance and Compliance, AI Context Delivery
Need Trading-Partner Superset Schema with Per-Partner Validation
Integration platforms exposing data to consumers across thousands of trading-partner relationships need a superset schema for inbound retrieval (so callers see every property and per-partner nuance) paired with per-trading-partner schemas for outbound writes (carrying the required / conditional / optional flags translated from source-system syntax to JSON Schema validation rules).
Noah (Head of Integration) — Discoverability and Reuse, Governance and Compliance
Need Schema Drift Detection with Human-in-the-Loop Approval
Integration platforms focus almost entirely on detecting drift in incoming-data schemas, but rarely on detecting drift in the backend business-system schemas — ERPs, WMS, custom fields — leaving integration teams to react to silent backend changes after data has already been mapped to the wrong place.
Noah (Head of Integration) — Governance and Compliance, Cost and Operations
Need a Bottom-Up Leadership Buy-In Playbook for Agent-Era API Strategy
Engineering leads see agent-era API strategy as urgent before leadership does. They need a playbook — language, evidence, and risk framing — to convince executives without sounding like AI hype, especially at responsibility-mindset enterprises that won't move fast just because the market is.
Riley (Head of APIs) — Agent-Ready Developer Experience, Governance and Compliance
Need MCP Behavioral Conformance Governance
Need a way to control that an MCP server actually behaves like it is intended to behave at runtime, not just that it exists in a registry.
Morgan (Security & Compliance Lead) — Governance and Compliance, Agent-Ready Developer Experience
Need MCP Data Leak Prevention
MCP servers must be prevented from letting sensitive data out of the enterprise when someone on the implementation side didn't pay enough attention to egress controls.
Morgan (Security & Compliance Lead) — Governance and Compliance
Need AI-Assisted OpenAPI-to-EDM Consistency Checking
Need a productized way to check incoming OpenAPI schemas against an enterprise data model so governance teams know where each new API fits or diverges before it ships.
Riley (Head of APIs) — Governance and Compliance, AI Context Delivery
Need API Referential with Auto-Published Portal and Changelog
Need an asset database of APIs that auto-publishes specs and breaking-change changelogs into the systems developers actually use — Confluence, intranet, internal portal — because most enterprises do not yet have a true internal developer portal.
Riley (Head of APIs) — Discoverability and Reuse, Governance and Compliance
Need Coherence Vector: Strategy-to-Work Traceability for API Programs
Need every API to carry first-class metadata linking it to the job-to-be-done, the team goal, and the group strategic objective it serves, so anyone working on it knows they are going in the right direction.
Riley (Head of APIs) — Governance and Compliance, Discoverability and Reuse
Need Customer Migration Tooling for Legacy-to-V2 API Platform Cutovers
Need tooling that lets a platform team carry both a legacy API estate and a V2 API platform until customers are fully migrated, without doubling staffing or budget.
Pat (Head of Platforms) — Cost and Operations, Governance and Compliance
Need Agent Trusted-Consumer Bootstrap Identity
Need a way to create a trusted consumer identity for agents so API providers can issue tokens to a known-and-vouched-for agent rather than treating every agent as either anonymous or a human-delegation proxy.
Francois (Head of AI Security) — Governance and Compliance, Agent-Ready Developer Experience
Need API Provider Behavioral Change for Agent Consumers
Even with identity and onboarding solved, API providers carry advertising-era baggage — own the user, distrust middlemen — that blocks them from issuing tokens to agents at all.
Riley (Head of APIs) — Governance and Compliance, Agent-Ready Developer Experience
Need Internal Enterprise Agent Platforms with Data Residency
Sovereign-data enterprises need agent platforms they can stand up internally — controlled deployment, controlled training data, controlled residency — rather than calling out to a third-party SaaS.
Morgan (Security & Compliance Lead) — Governance and Compliance, Cost and Operations
Need Orchestration Tooling for Fleets of Role-Based Agents
Need tooling that lets a non-engineering operator define skills, create role-based agents, give each agent its skill, and wire them together as a working fleet — VP of Marketing agent, Social Media Manager agent, Paid Ads Manager agent — on a single reviewable dashboard.
Harper (Head of Product Marketing Running a Fleet of Agent Roles) — Agent-Ready Developer Experience, Governance and Compliance
Need Server-Side Logging for Agent Traffic on Developer Platforms
Developer platforms need server-side telemetry on agent traffic — who's calling, what they're trying, whether they succeeded — because client-side signals like user-agent strings can be spoofed and tell you nothing useful.
Pat (Head of Platforms) — Governance and Compliance, Agent-Ready Developer Experience