Problems/03

An approved policy that nothing enforces is a document, not a control.

The policy your board signed becomes the rules running in front of every request: versioned, enforced in path, and changed without waiting for a release.

The problemPolicy deployment gap

The policy deployment gap is the distance between the AI policy your organisation approved and the controls actually enforced in front of every request.

Inspect a policy version record All problems
Where it becomes visible

Nobody discovers this problem in a planning meeting

A new project starts

It runs ungoverned until someone remembers to onboard it.

A policy update is issued

The document changes in a day, production takes a quarter.

An exception is granted

It lives in an email thread with no scope and no expiry.

Two teams read the same rule

And ship two different controls.

An audit samples a project

The sample shows local settings that never matched the policy.

A review asks who enforces this

The answer is a document, and a promise.

What it costs

The bill arrives as delay, not as an incident

01The policy cannot be evidenced

You can show intent, not enforcement.

02Every project is onboarded by hand

Governance scales with headcount instead of traffic.

03Exceptions never expire

Temporary permission becomes permanent posture.

04Updates reach production late

Between approval and enforcement, the gap is the risk.

05Reviews find drift, repeatedly

The same finding returns every cycle.

Why the usual tooling does not close it

The gap

How obstruo closes it

The control

A policy in a wiki cannot refuse a request.
Controls are enforced in the request path, so the policy acts.
Per-application SDK configuration drifts between teams.
Organisation policy is inherited by every project, with locked controls that cannot be edited locally.
CI checks cover code, not the traffic that code produces at runtime.
Enforcement happens per request, including calls no reviewer anticipated.
Exceptions are granted outside the system that enforces the rule.
An exception is a record with an owner, a scope and an expiry date.
No version history ties a past decision to the rules then in force.
Policy versions are retained, and every decision points at the version that governed it.
The evidence artefact

A policy version is a deployable object with an owner and a propagation time.

This is the shape of the record obstruo produces. It is the same artefact a reviewer, an auditor and an enterprise buyer each ask for, and it exists before they ask.

Append-only Owner named Exportable
Policy version record IN FORCE
Policyeu-pii-strict v14
Approved byM. Lindqvist, CISO, 2026-06-02, apr_2188
Changed in v14approved model list narrowed to 4, was 6
fail closed when detection cannot run
batch-model exception scoped to claims-automation
Inherited by23 projects, propagated in 41 seconds
Locked controls3, editable locally 0
Open exceptions1, expires 2026-09-14
Requests governed under v141,284,910
Previous versionv13, in force 2026-03-11 to 2026-06-02
Approval and enforcement are the same event. What was approved is what runs, and past decisions still point at v13.
The other three

They arrive together, and the same controls answer them

01
AI evidence debt
Read the problem page
02
Agent authority drift
Read the problem page
04
Live processor blindness
Read the problem page

Your AI. Your data. Your control.

Send us one clause from your AI policy. We will show it as a locked control, with the record it produces.

Inspect a policy version record See pricing