IRGF Implementation Documentation
How to operate the Intent-to-Runtime Governance Framework: what to do at each gate, how to score risk so the tiers mean something, where automation must stop, and how to tell whether any of it is working. Written for enterprise architects, AI architects and governance practitioners.
Read this before you commit
IRGF has not been deployed in a real organization. Its mechanisms were designed against a structured requirements set and stress-tested through simulated adversarial review, not through field use. Thresholds, cadences, timeboxes and scoring anchors throughout this documentation are reasoned defaults, not calibrated ones. Treat each as a starting position to adjust against your own incident data, and expect to change several within the first year.
The full limitations register, with the practical mitigation for each, is in Appendix A.
Where to start
Deciding whether to adopt
Start with what the framework governs, then the readiness assessment and the failure modes.
Standing up governance
Assess where you are, follow the phased roadmap, then put the operating model in place.
Running a system through governance
Work the lifecycle in stage order; classification is the chapter that matters most.
Building the Control Plane
Connect telemetry in the right order, and know where automation must stop.
The documentation
A · Orientation
What IRGF governs, the Core Model in practice, and a readiness assessment you can run in a week.
B · The AI build lifecycle
Eleven stages and five gates, one chapter per cluster, with worked examples and the failure modes that recur.
C · Agents and autonomy
The governance chain for systems that act, and detecting autonomy increases nobody authorized.
D · Continuous assurance
Standing up the Control Plane, and triaging each category of drift.
E · The operating model
Two governance bodies, decision rights, escalation and exceptions.
F · Transformation interface
What architecture owes portfolio governance, and what it must not own.
G · Artifacts
Sixteen primary records and four derived views, with filled examples.
H · Adoption
Maturity, roadmap, the minimum viable start, failure modes, metrics, and a full worked walkthrough.
I · Module reference
All twenty modules to a uniform template: purpose, inputs, mechanics, outputs, failure signal.
J · Reference
Pattern library, gate checklists, scoring worksheet and glossary.
How this relates to the research report
This documentation is the operational companion to the research report that designed and stress-tested IRGF. The report answers whether the framework is defensible; this answers what to do on Monday morning. Where the two appear to disagree, the report's specification governs and the discrepancy is a defect here.
Conventions
S0–S10 are lifecycle stages, G1–G5 governance gates, T0–T7 transformation stages, D1–D5 risk dimensions, M1–M20 framework modules, and FR-nn the formal design requirements. Anything marked [Practice recommendation] is advice from this documentation rather than a requirement of the framework; all of them are collected in Appendix B.
Press / anywhere to jump to search.
Comments wanted
IRGF is published for review, not as settled practice. If a gate is unworkable, a threshold is wrong for your sector, a control duplicates something you already run, or a chapter is simply mistaken, that is exactly what this stage of the work needs. Write to info@irgfframework.com, or see how to contribute for the specific gaps where help is most useful.