# AI Data Governance & Privacy Tools: evaluation worksheet

Source: https://dutygraph.com/directory/ai-governance/categories/data-governance/
Editorial date: 2026-09-07

## Scope

- Organization / team:
- Task and expected output:
- Human owner:
- Product and version:
- Evaluation date / environment:
- Reviewer:

## Questions

### 1. Are source permissions enforced at retrieval time and after entitlement changes?

- Observation (demonstrated / described / unknown):
- Evidence reference:
- Limitation or follow-up:

### 2. Which copies of data are retained in prompts, outputs, logs, indexes and caches?

- Observation (demonstrated / described / unknown):
- Evidence reference:
- Limitation or follow-up:

### 3. What can redaction miss, and can a reviewer inspect the transformation safely?

- Observation (demonstrated / described / unknown):
- Evidence reference:
- Limitation or follow-up:

### 4. Can lineage and deletion behavior be demonstrated across the complete data path?

- Observation (demonstrated / described / unknown):
- Evidence reference:
- Limitation or follow-up:

## Evidence checklist

- [ ] A data-flow and retention map
- [ ] Cross-team permission and revocation tests
- [ ] A redaction or deletion trace showing covered stores

## Boundary to check

A privacy feature is not a general compliance determination. Establish the applicable requirements with the responsible team. Data protection also depends on the identity, tool permissions and operational configuration around the product.

## Decision

- Fit for the scoped task:
- Unresolved gaps:
- Next action, owner and date:

This is a planning worksheet, not an endorsement, access approval or compliance certification. Keep confidential evaluation notes in your organization's approved storage.
