basenull
4 min readBasenull AI Ops

You don't need an AI platform. You need ten boring controls.

The procurement reflex says: big new risk category, so issue an RFP for a big new platform. Meanwhile the actual gaps in most AI operations are small, specific, and closable in days each. Here are the ten controls that matter — none of which requires a nine-month rollout or a seven-figure commitment.

AI GovernanceSecurityStrategy

There is a reflex that kicks in when an enterprise recognizes a new risk category: form a committee, write requirements, issue an RFP for a platform. The AI governance platform market is happy to oblige — end-to-end suites, single panes of glass, nine-month implementations, pricing on request.

Before signing any of that, it's worth asking what problem is actually unsolved. Decompose "we need to get control of our AI" into its concrete failures and you get a list of small, specific gaps — each closable in days with focused tooling, none requiring a platform to host it. Here are the ten that matter.

1. An inventory of AI systems and their connections. Every model, agent, and assistant in production, plus the third-party surfaces (MCP servers, integrations, plugins) each is wired to, with an owner per row. This is a list, not a product category. It is also the prerequisite for the other nine.

2. Snapshots and diffs of third-party AI surfaces. For every external tool surface your agents consume, capture what it exposes today and alert when it changes. Point-in-time approvals of mutable surfaces expire silently; a diff makes the expiry visible.

3. A named owner for every agent. Not a team — a person, who knows they own it, gets its alerts, and can turn it off. Most agent incidents compound because the first hour is spent discovering whose problem it is.

4. A durable record of agent actions. What each agent did, in what order, on whose authority — kept somewhere that survives the agent's own context. The systems an agent touches log their side; the run-level trail is what's missing everywhere.

5. Workflow conformance checks. The defined process for each consequential agent workflow, checked against actual runs, with deviations alerting like failed health checks. Output quality is measured by your evals; process quality is measured by nothing unless you build this.

6. A managed prompt library. The prompts doing real business work, brought out of personal notes into a shared, versioned, owned collection — with review for anything customer-facing. Business logic belongs inside your controls.

7. Log retention that meets your obligations. The EU AI Act expects deployers of high-risk systems to retain generated logs; your own incident reviews expect the same. Decide retention deliberately, per system, now — not during the first regulatory inquiry.

8. A human oversight assignment with an escalation path. For each system where oversight is required (by regulation or by sense), a named, competent person with actual authority to intervene — and a runbook that reaches them at 2am. "Human in the loop" without a name and a pager is a slogan.

9. A workforce capability baseline. Measured, role-specific AI literacy — who can delegate safely, who can verify output, who isn't using the tools at all — so enablement spend follows evidence instead of license counts.

10. Executive reporting of deltas, not demos. A regular, boring report to the leadership table: what changed, what broke, what it cost, what it returned. Comparable period over period. Demos communicate capability; deltas communicate control.

Why boring beats big

Notice what's true of every item: each is independently deployable, testable in a week, and valuable without the other nine. That shape has consequences.

You learn before you standardize. Your practices around agent operations are months old, not decades. Committing to a platform now freezes v0 assumptions into a system of record before you know which assumptions survive contact with reality. Small controls let the practice mature first; consolidation is cheap later, once you know what you actually do.

Failure is contained. A platform program that stalls delivers nothing for anyone. Ten small controls fail — when they fail — individually, and each success compounds: the inventory makes the diffing deployable in an afternoon, the diffing feeds the runbooks, the run records make the reporting honest.

The platform pitch quietly depends on the same list. Look inside any AI governance suite and you'll find these ten controls wearing a shared navigation bar. The integration is real value, eventually — but integration of controls you haven't operationalized is a dashboard over an empty warehouse. The sequencing only works one way: controls first, consolidation second.

None of this says never buy a platform. It says a platform is how you scale a practice, not how you acquire one. If the board asks what the AI governance program looks like, "we issued an RFP" and "we run these ten controls, here's this quarter's delta on each" are both answers. Only one of them survives the follow-up question — and only one of them costs less than the committee that would have written the RFP.

From the operator

Basenull AI Ops ships purpose-built tools for the IT executive whose org is already running AI in production. Governance, supply-chain security, agent ops, observability — the operational layer that usually arrives after the first incident.

Explore products