← All insights

News analysisLens: United States4 min read

SAS AI Navigator starts governance with an inventory. Mapping a use case to a rule is not compliance

SAS's governance SaaS, now on Microsoft Marketplace with six months of free access, inventories AI use cases, models and agents and maps them to policy packs from Protiviti and Asenion.

Listen to this article · 5 min

AI-generated narration of the full article.

Tall warehouse racks stacked with boxes and pallets, in La Madre duotone, beside the words Count it first
Photo: rawpixel (CC0)

Ask a large company how many AI systems it runs and the honest answer is usually a range. Copilot agents built by employees, models inside SaaS products, data science models from five years ago, a few pilots that quietly reached production. Every AI governance program eventually discovers that it cannot govern what it has not counted. SAS made its answer to that problem available on October 5.

What SAS released

SAS AI Navigator, first presented at SAS Innovate in April, is now available as a SaaS product on Microsoft Marketplace. According to SAS’s release from Cary, North Carolina:

  • it compiles an inventory of AI use cases, and of the models, agents and tools behind them, whether built in-house or bought from third parties, including LLMs, agents, open-source models and SAS’s own;
  • it lets organizations align use cases with government regulations and internal policies, across the lifecycle from experimentation to retirement;
  • it can govern use cases powered by agents or models such as Claude or Microsoft Copilot;
  • policy packs from SAS partners Protiviti and Asenion provide ready-made questions and risk classifications to apply to use cases;
  • customers get six months of free access.

The release does not describe a technical integration with Microsoft beyond Marketplace distribution and SAS’s partnership with Microsoft, so do not assume it reads your Microsoft 365 or Azure estate automatically. SAS’s language is careful: Navigator helps “align” use cases with regulations. It does not claim to make anyone compliant, and buyers should not read it that way either.

Why the use case is the right unit

Most agent registries count agents; most model registries count models. SAS anchors the inventory on the use case, the point where AI touches a business decision. That is the level at which risk actually exists. The same model can draft marketing copy and screen job applicants; only one of those use cases is high-risk. A registry that only knows the model cannot tell them apart.

It complements, rather than replaces, the agent-level control planes we covered in our analysis of agent governance above vendors. You need both views: what each agent can do, and which business decisions depend on it.

What an inventory record has to hold

One inventory record per AI use case01Businessowner andprocess02Models,agents andvendorsbehind it03Datacategories itreads andwrites04Risk tier andapplicablepolicies05Evidence thecontrols work06Status andnext reviewdateFacts you collectJudgment you document
  1. Business owner and process
  2. Models, agents and vendors behind it
  3. Data categories it reads and writes
  4. Risk tier and applicable policies
  5. Evidence the controls work
  6. Status and next review date

Facts you collectJudgment you document

A policy pack can supply the questions. Only your teams can supply the evidence.

Intake is the hard part. The inventory is only as complete as the way entries arrive. Self-declaration forms miss the most important cases. Feed it from systems that already know: procurement contracts with AI clauses, cloud billing for model endpoints, Microsoft Entra Agent ID for agents, and the Copilot agents people build themselves.

Policy packs are borrowed judgment. Protiviti’s and Asenion’s packs save months of drafting questions and risk tiers. They are still someone else’s reading of the rules. Your legal and risk teams need to adopt each pack explicitly, adjust it, and own it. The accountability does not transfer with the content.

Mapping is not evidence. Linking a use case to a requirement records that the requirement applies. Compliance needs proof that the control works: test results, review records, monitoring. As we argued in our analysis of controls that produce evidence, a control without evidence is a promise.

For U.S. teams, the NIST AI Risk Management Framework already asks for this: its GOVERN 1.6 practice calls for mechanisms to inventory AI systems, resourced according to risk. With federal rules still voluntary, that inventory is also what enterprise buyers increasingly ask suppliers for, the trend we described in our piece on buyers becoming the regulator.

What to do now

  1. Choose the use case as your inventory unit, linked to the models and agents behind it.
  2. Feed the inventory from systems, not only from forms: procurement, billing, identity.
  3. Adopt policy packs deliberately, with a named owner in legal or risk.
  4. Require evidence per control, not just a mapping to a requirement.
  5. Plan for month seven: decide before the trial ends whether the inventory will live in Navigator or elsewhere, and how to export it.
  6. Check the Marketplace terms with procurement, including whether the purchase counts toward existing Azure commitments.

The bottom line

SAS AI Navigator is a reminder that AI governance starts with a spreadsheet problem: knowing what exists. Anchoring the inventory on use cases is the right design. Just remember that a mapped requirement is a to-do item, not a finished control.

Have an AI use case stuck between prototype and production?

Tell us what you’re trying to ship. We’ll reply with honest next steps.

Discuss a use case