Operate

Regional governance

Keep regulated workloads on eligible infrastructure

This recipe combines data classification, runtime region, provider evidence and route simulation.

1. Classify

Identify PHI, PII, financial data, secrets and export-control requirements before selecting a model.


2. Define hard constraints

Require the permitted runtime region, provider contract, ZDR posture and model capabilities. Unknown evidence is not compliant evidence.


3. Simulate

Use POST /v1/route/simulate with a scoped operator identity and representative metadata. Review the explanation without invoking a provider.


4. Enforce and prove

Move an internal tenant from shadow to enforce, test denial and rollback, then retain policy revision, region and safe decision evidence.

NextMigrate an OpenAI app