-
Notifications
You must be signed in to change notification settings - Fork 0
Home
Principled AI Lifecycle Orchestration
Current public baselines: PALO Web 3.1.0 (23 August 2026) and the independently versioned PALO-AI 2.7.0 developer preview (25 August 2026).
PALO is an open-source framework and toolkit for operational AI governance. It helps organizations translate principles, laws, standards, and risk signals into lifecycle decisions, controls, evidence, KPIs/KRIs, review gates, and accountable outcomes.
PALO is a governance support framework. It is not a certification body, does not provide legal advice, and does not replace organization-owned identity, security, risk, legal, audit, or assurance functions.
| Your objective | Start here | What it provides |
|---|---|---|
| Govern the complete AI lifecycle | PALO Framework | Lifecycle governance, risk classification, assessment, controls, evidence, metrics, monitoring, and decommissioning |
| Govern delegated and agentic systems | PALO-AM | Agent identity, authority, autonomy, action-space, human oversight, agentic risk, and evidence methodology |
| Enforce and verify agent actions | PALO-AI | Developer-preview contracts and runtime patterns for policy enforcement, approvals, one-time capabilities, receipts, and outcome verification |
The three routes are complementary: PALO is the umbrella framework, PALO-AM is its specialist agentic governance modality, and PALO-AI is a technical developer-preview implementation of selected agentic controls.
PALO supports governance from initial purpose through retirement:
- Ideation and ethical screening — clarify purpose, affected people, expected value, and unacceptable uses.
- Assessment and planning — classify risk, assess fundamental-rights impacts, map stakeholders, and define controls.
- Responsible development and validation — test data, models, workflows, security, human oversight, and evidence requirements.
- Deployment and monitoring — approve release gates, monitor performance and risk, manage incidents, and preserve evidence.
- Continuous improvement and decommissioning — review changes, reassess context, retire safely, and retain accountable records.
- Live PALO website
- Stakeholder onboarding
- Documentation Library
- Platform Map
- Assessment Path
- Release verification record
- Repository README
- Release history
PALO-AI separates permission from outcome assurance. A policy engine may allow an action, while PALO independently verifies whether the approved effect actually occurred.
The PALO-maintained Microsoft Agent Governance Toolkit interoperability proposal uses Microsoft AGT ACS as an optional, replaceable pre_tool_call decision provider. PALO retains the immutable Action Claim, digest-bound approval, one-time capability, trusted execution receipt, authoritative post-state verification, Case File, and incident-hold workflow.
The adapter is a community interoperability proposal maintained by PALO. It is not maintained, certified, sponsored, or endorsed by Microsoft.
- The static PALO website and governance tools are the supported public experience.
- PALO 3.1 provides the current governance control-plane and semantic baseline. PALO-AI is versioned independently.
- PALO-AI v2.7, the reference runtime, Governance Hub, MCP transports, approval flows, data-assurance contracts, and connector examples are developer previews for isolated evaluation.
- PALO-AI v2.7 adds Action Claim 1.4, payload-minimized external context evidence, purpose-bound Data Fitness Decisions, signed Data Disclosure Contracts and Receipts, AI system and agent registry records, tenant-bound MCP operations, and continuous invalidation.
- The capability inventory contains 40 tracked capabilities: 5 implemented, 28 prototype, 7 specified, and 0 production-ready.
- Preview components must not be treated as production authorization services or unavoidable security boundaries.
- Production use requires organization-owned identity, access control, key custody, tenant isolation, monitoring, resilience, retention, legal review, and independent security assurance.
PALO is MIT-licensed and welcomes evidence-based contributions, documentation improvements, translations, integrations, and critical review.