Back to Directory/Developer Tools

GIA Governance Intelligence Automation

AI governance engine — decision controls, compliance, audit chains, knowledge packs.

Developer ToolsJavaScriptv0.3.1

GIA Governance Intelligence Automation

Enterprise AI governance through the Model Context Protocol.

GIA is a production governance engine that gives AI agents enforceable decision controls, compliance scoring, immutable audit chains, and human-in-the-loop gates. Built for organizations operating under NIST, FedRAMP, CMMC, EU AI Act, and SOC 2 requirements.

29 MCP tools. One integration point. Works with Claude Desktop, Claude Code, OpenAI Agent Builder, and any MCP-compatible client.

Quick Start

bash
npx gia-mcp-server

Or install globally:

bash
npm install -g gia-mcp-server
gia-mcp-server

The server connects to the hosted GIA engine at https://gia.aceadvising.com. Configure your API key:

bash
GIA_API_KEY=your-key npx gia-mcp-server

Claude Desktop

Add to your claude_desktop_config.json:

json
{
  "mcpServers": {
    "gia-governance": {
      "command": "npx",
      "args": ["-y", "gia-mcp-server"],
      "env": {
        "GIA_API_KEY": "your-key"
      }
    }
  }
}

Claude Code

bash
claude mcp add gia-governance -- npx -y gia-mcp-server

OpenAI Agent Builder

Point to the Streamable HTTP endpoint:

https://gia.aceadvising.com/mcp

Smithery

npx -y @smithery/cli install @knowledgepa3/gia-mcp-server --client claude

Tools

Decision Controls (MAI Framework)

ToolDescription
classify_decisionClassify agent decisions as Mandatory, Advisory, or Informational
approve_gateHuman-in-the-loop approval for Mandatory gates
evaluate_thresholdCompute escalation health (Storey Threshold)
score_governanceWeighted governance scoring (Integrity, Accuracy, Compliance)

Compliance & Audit

ToolDescription
audit_pipelineQuery the hash-chained forensic audit ledger
verify_ledgerVerify SHA-256 chain integrity from genesis
map_complianceMap controls to NIST AI RMF, EU AI Act, ISO 42001, NIST 800-53
assess_risk_tierEU AI Act risk tier classification
generate_reportGovernance status reports (summary, detailed, executive)

Knowledge Packs

ToolDescription
seal_memory_packCreate immutable, TTL-bound knowledge artifacts
load_memory_packLoad packs with trust level and role enforcement
transfer_memory_packGoverned knowledge transfer between agents
compose_memory_packsMerge packs with risk contamination rules
distill_memory_packExtract governance patterns from usage history
promote_memory_packPromote packs to higher trust levels after review

Security & Operations

ToolDescription
monitor_agentsAgent health, repair history, failure counts
srt_run_watchdogInfrastructure health probes (API, disk, memory, TLS, DB, DNS)
srt_diagnoseIncident diagnosis with playbook matching
srt_approve_repairHuman-approved repair execution
srt_generate_postmortemStructured incident postmortems with TTD/TTR metrics

Infrastructure Remediation

ToolDescription
gia_scan_environmentScout swarm for environment detection
gia_list_packsList remediation, patrol, hardening, and audit packs
gia_dry_run_packPreview pack execution with blast radius analysis
gia_apply_packExecute remediation with mandatory human approval
gia_run_patrolRead-only posture checks and compliance audits

Impact & Value

ToolDescription
record_value_metricTrack time saved, risks blocked, autonomy levels
record_governance_eventLog gates, drift prevention, violations blocked
generate_impact_reportEconomic + governance ROI reporting
system_statusEngine health, uptime, configuration

Architecture

GIA enforces governance through three layers:

  1. Decision Controls — MAI classification gates side effects and high-impact actions
  2. Step Hooks — Workflow progression control at each pipeline stage
  3. Kernel Hooks — Resource control at the LLM boundary, including sub-agents

Every governance action is recorded in a SHA-256 hash-chained audit ledger that can be independently verified.

Compliance Coverage

  • NIST AI RMF — Risk management framework mapping
  • EU AI Act — Risk tier assessment and control mapping
  • ISO 42001 — AI management system alignment
  • NIST 800-53 — Federal security control mapping
  • CMMC 2.0 — DoD cybersecurity maturity
  • FedRAMP — Federal cloud authorization
  • SOC 2 — Service organization controls

About

Built by Advanced Consulting Experts (ACE) — a Service-Disabled Veteran-Owned Small Business (SDVOSB).

GIA was designed by William J. Storey III, a 17-year Information System Security Officer with experience across DoD contracts and U.S. Army Ranger Battalion operations. The same discipline applied to securing classified systems now governs AI agent workforces.

License

MIT

Learn More