Four visibility labels

Every artifact in the framework is tagged with one of four labels. They describe how widely a document can be shared.

Public Safe for open publication — appropriate for prospective students, external stakeholders, and the open web.
Institution-wide Visible to all campus users with institutional credentials, but not published openly.
Restricted Internal Limited to approved internal stakeholders such as governance bodies and service owners.
Confidential Limited due to sensitive security, privacy, legal, or incident content.

Visibility by document type

A default visibility for each artifact, with the peer pattern that tends to accompany it.

Document typePrimary audienceDefault visibilityPeer pattern
Institutional AI strategy & principlesCommunity, leadership, publicPublicOften published
AI acceptable use guidanceStudents, faculty, staff, researchersPublic / Institution-wideCommonly published or broadly shared
Academic integrity & teaching guidanceStudents, faculty, teaching supportPublic / Institution-wideVery commonly visible
Data classification & sensitive-data guidanceUsers, data stewards, IT, complianceInstitution-wideSummarized publicly, detail internal
AI RMF profilesGovernance bodies, service owners, reviewersRestricted InternalPublic summaries possible, full profiles internal
AI service catalogEntire campusPublic / Institution-wideCommon among early adopters
AI use-case registryService owners, approvers, governance teamsInstitution-wide / RestrictedEmerging; summaries sometimes published
AI service cardsEnd users, approvers, support teamsPublic / Institution-wideOften partial via catalog entries
System cardsSecurity, privacy, technical owners, auditorsRestricted InternalUsually not public
Vendor model cardsDevelopers, reviewers, governance teamsPublicAlready public when vendor-supplied
Internal model summariesGovernance teams, reviewers, ML teamsRestricted InternalRarely public
Per-deployment risk registersLeadership, governance, security, auditorsConfidentialInternal only
Consolidated AI risk registryLeadership, governance bodies, auditorsRestricted InternalPublic summaries possible
Privacy, security, accessibility reviewsCompliance teams, service owners, auditorsConfidential / RestrictedInternal evidence
Vendor due diligence & contractsProcurement, legal, privacy, securityConfidentialInternal only
Evaluation, red-team & incident reportsTechnical owners, governance, leadershipConfidential / RestrictedInternal only

Simple publication defaults

When in doubt, four defaults resolve most publishing decisions without a committee.

Lead with guidance

  • Publish user guidance by default.
  • Publish summaries when full documents are too sensitive.

Protect the evidence

  • Keep control evidence internal by default.
  • Treat model documentation as mixed-visibility.