What you can assign
An ownership assignment connects one governed target to one or more owners.
Owners can be individual directory users or directory groups.
Ownership does not change the target user’s role, grant permanent access, or
automatically approve a request.
How requests are routed
When Forge creates a governance request, it attempts to find the most specific matching owner in this order:- An owner explicitly selected by the originating workflow.
- The owner assigned to the matched policy.
- The owner assigned to the affected AI system.
- The owner assigned to the requester’s directory group.
- The organization-wide Responses queue when no owner matches.
Add an owner
- Open Settings.
- Select Ownership.
- Select Add owner.
- Choose whether the assignment applies to a policy, AI system, or user group.
- Select one or more governed targets.
- Select the users or groups who should own matching work.
- Configure optional notifications.
- Select Save owner.
Notify owners
Each ownership assignment can use one or more notification methods:
Slack channel and direct-message delivery require a connected Slack workspace.
Direct messages also require the selected directory user to have a resolved
Slack identity.
Notification preferences affect delivery only. They do not change who is
authorized to review the request.
See Notifications for organization-wide event
preferences and delivery verification, including Slack, email, and the
organization notification webhook.
Review assigned work
Owners review matching governance work from Responses. The Mine view contains requests routed to the current owner. Authorized policy managers can use All to review organization-wide requests, including requests that could not be assigned automatically. Depending on the workflow, a request can provide actions such as:- Approve the requested access.
- Deny the request with a reason.
- Approve a supported scope or duration.
- Authorize a supported remediation.
- Review the resulting grant or session control.
JIT Viewing
JIT Viewing uses Ownership to distribute requests for temporary session-content access. When the session user belongs to a directory group with an active owner assignment, Forge routes the request to that group owner. If no owner matches, policy managers can still review it from the full Responses queue. This allows business teams to govern access to their employees’ session content without giving them permanent access to every session in the organization.Changes and audit history
Ownership settings can be updated as responsibilities change. Existing governance records retain their assignment and decision history. Forge records ownership and governance activity, including:- Ownership assignment changes.
- The target and resolved owners.
- Request routing and reassignment.
- Notifications and delivery outcomes.
- Approval or denial decisions.
- The reviewer and approved scope.
Related pages
JIT Viewing
Require temporary approval before sensitive session content can be viewed.
Responses
Review assigned requests, decisions, grants, and session controls.
Notifications
Configure governance, Shadow AI, and Registry notifications.
Roles
Control organization permissions and administrative access.