Governance is ultimately about accountability: who is responsible for a piece of data, and what are they allowed to do with it. As AI systems begin to take on real governance work — classifying assets, proposing owners, flagging policy violations — that question gets sharper. A recommendation is only trustworthy if you know exactly who or what made it, and under what authority. Procela's answer is the principal model.
What is a principal?
A principal is any actor that can hold a governance role — a human or an AI agent — with a defined scope of authority. Every action in Procela is attributable to a named principal, and every principal's authority is explicit. There are no anonymous, ambient decisions.
Human principals
Data owners and domain stewards are the familiar roles. Owners are accountable for a domain; stewards do the day-to-day work of classification, review, and remediation. In Procela these aren't just labels in a spreadsheet — they carry enforceable scope, and their decisions are logged against them.
AI principals
The important move is treating AI agents as first-class principals rather than as background automation. An agent that reviews classifications or proposes stewardship assignments is a named actor with its own scope and its own audit trail. You can see what it did, why, and on whose authority — just as you can for a human.

AI agents and service accounts modeled as named principals, each with a type and status.
The three-tier autonomy framework
Not every domain warrants the same level of independence from an agent, so Procela gives you three tiers to configure per domain:
- Advisory. The agent recommends — a classification, an owner, a policy match — and a human decides. Best for your highest-sensitivity data.
- Propose & approve. The agent prepares changes and routes them for approval. Nothing takes effect until a steward signs off, and every decision is logged.
- Autonomous. For well-understood, low-risk work, the agent acts independently inside policy boundaries you define — with a complete audit trail.
Because the tier is set per domain, you can let agents run autonomously over low-risk catalog hygiene while keeping export-controlled data strictly advisory — all in the same program.
Authority, scope, and auditability
Every principal's authority is bounded and inspectable. Because roles and process ownership are explicit, Procela can derive a full RACI matrix — who's Responsible, Accountable, Consulted, and Informed for every activity — automatically.

A RACI matrix generated from process ownership and governance-role assignments.
Combined with a tamper-evident log of every classification, assignment, and policy decision, that means you can always answer the auditor's core question: who did this, and were they allowed to?
Why it matters for regulated environments
In defense, financial services, and healthcare, “the system did it” is not an acceptable answer. The principal model makes AI participation defensible by keeping it accountable — every actor named, every authority explicit, every action logged.