Docs/patterns/enterprise pattern/problem

Enterprise Pattern — Problem

Pattern: Enterprise
Component: problem.md
Version: 1.2 | Updated: 2026-07-29


Statement

Org-wide copilots and write MCP land without SoA, tenant isolation, or eval gates — then audits and incidents arrive together.

Measurable symptoms

Symptom How you detect it
Tool sprawl Write MCP on by default
Tenant bleed Retrieval crosses customers
Logo compliance ISO/NIST claimed from slideware
No SoA row Allowlists undocumented

Root cause

Enterprise AI is sold as enablement velocity. Governance artifacts feel optional until they are the only defense in an audit.

What breaks when this pattern is skipped

  • Security blocks org rollout late
  • Cross-tenant data incidents
  • Assurance teams reject “we use AIES” claims

Non-goals of this pattern

  • Not a conformity certificate
  • Not a substitute for counsel on legal classification
  • Not permission to skip HITL on irreversible effects

Changelog

  • 1.2 (2026-07-29): Enterprise problem page expanded with skip-impact and operator symptoms.