DocumentationFor admins

Governance Center

In the anymize Governance Center you centrally decide which AI models, connectors and features your team may use, and what is logged.

5 Min

What the Governance Center is for

The Governance Center is the one place where you decide for your whole firm what is allowed with AI. Everything else in anymize is work on the matter; the rules above that work live here.

You reach it via Settings or directly at /governance. The left column walks you through nine areas, grouped into Policies, Platform and Security. The home page shows the most important ones as tiles, with current counts: how many groups exist, how many connectors are available, how many events were logged in the last 30 days. Dictionary and Knowledge bases are reachable via the left column.

What the Governance Center does not change: names, addresses and file numbers are still replaced by placeholders before a request reaches an AI model. Here you only decide whether that step is optional or mandatory.

The nine areas

Four areas are open to every account, even without a team. The others need a team, and some of them additionally the Owner or Admin role.

AreaWhat you configure thereWho sees it
Compliance & privacyForced anonymization, allowed models and connectors, retention, feature locksEvery account. Admins change settings; regular members see a read-only view
GroupsCreate departments and assign membersOwners and Admins only, Team plan only
DictionaryTerms that are always or never anonymizedEvery account. The personal part works without a team; the shared part does not
DocumentsData processing agreement and BRAO consent declaration for downloadEvery account
Knowledge basesWhether the AI agent may write and with whom sharing is allowedEvery account. Admins change settings; regular members see a read-only view
ModelsWhich AI models appear in the chat pickerEvery account. In a team only Owners and Admins change it
ConnectorsProvide custom MCP connectors for the whole teamOwners and Admins only, Team plan only
SkillsDistribute skills to the team or to individual groupsOwners and Admins only, Team plan only
Audit logWho changed, shared or revealed what and whenOwners and Admins only, Team plan only

What you are not allowed to open is not hidden. The entry stays in the list, greyed out, with a lock and a reason: either “Team plan only” or “Team admins only”. That is intentional. Anyone who never sees a surface assumes it does not exist and writes to support instead of changing plan or asking their admin.

You set rules via groups, not per person

That is the core idea, and it saves you most of the work. Every rule has a default “For everyone”. Underneath you can hang exceptions for individual groups, for example “Secretariat” or “Lawyers”. Individuals never get their own rule.

  • Limit models: For everyone only EU models apply; the “Lawyers” group may additionally use the strongest model.
  • Distribute skills: The skill for your pleading format goes to the “Lawyers” group; the rest of the firm never sees it.
  • Share connectors: The case-management connector is only available to the group that works with it.
  • Lock features: Web search is off for everyone; one group may keep it.

A group rule replaces the “for everyone” rule; it does not stack with it. If someone is in several groups with a rule on the same topic, the strictest wins: for toggles the ban, for retention the shortest period. Only for models and connectors the union counts, because there each group grants something instead of forbidding it.

You create groups under Groups; you set the related rules on the Compliance page. A newly assigned person receives the rules from their first sign-in; before that they appear faded in the list.

Can I stop employees from using certain AI models?

Yes. The rule is called “Model access” and lives on the Compliance page. You set it to either “All models” or “Selected only” and then tick the models that should be allowed. For the most common cases there are two quick picks: “anymize only” and “EU only”.

A blocked model disappears from the chat picker for the people concerned. They see no error message and do not need to know why - the model simply is not in the list.

An empty selection does not mean “no model”; it means “all models”. Otherwise you could lock your whole firm out of chat. So pick at least one model if the rule should apply.

Does the rule still apply if someone bypasses the UI?

Yes. The UI shows a rule and hides what is not allowed. That alone would be cosmetics. So the APIs behind it check the same rule again: anyone who goes via the API or opens an address directly is rejected there.

The same applies to permissions. A regular team member who types the URL of an admin page lands on the Compliance page. And a change they somehow submitted would be rejected by the API.

What a solo account gets from it

Even without a team the Governance Center is not empty. Everything that protects your own data or limits your own choices works the same for a single account.

  • Enforce anonymization, for documents as well as typed messages.
  • Set how long placeholder-to-clear-name mappings are retained.
  • Limit your own model and connector selection.
  • Forbid the AI agent from writing to knowledge bases.
  • Maintain the personal dictionary.
  • Download the data processing agreement and BRAO declaration.

Reserved for a team are the rules that prescribe something to other people: feature locks, groups, team connectors, team skills and the audit log. Those rules still appear in your account, greyed out, with the note “Team plan only”.