Skip to content

Project PARS

An enterprise AI governance platform designed to bring visibility, security, policy management, cost control, and learning together within a unified AI operating model.

Problem

As AI adoption accelerates across enterprises, understanding which tools are being used, by whom, with what data, and for which purposes becomes increasingly difficult. When security, data privacy, cost, policy compliance, and employee enablement are managed as separate concerns, building a sustainable organization-wide approach to AI governance becomes significantly harder.

Context

Project PARS is designed not merely as a control layer that blocks AI usage or records activity, but as an “AI Operating System” that brings usage visibility, governance, policy management, cost control, and learning together within a unified platform.

Constraints

Protecting enterprise data and preventing uncontrolled data exposure outside the organization are fundamental design constraints. The solution must integrate with existing identity, device, and network environments, remain independent of individual AI providers, and enforce policies without creating unnecessary friction for users. At the same time, the system should not become a security tool understandable only by technical teams. It needs to provide meaningful visibility for management, IT, and end users alike. This requires an architecture that balances security, usability, performance, cost, and operational manageability.

Goals

Enable AI usage rather than simply blocking it, while making that usage safe and manageable. Provide organization-wide visibility into AI adoption and make it measurable. Define enforceable policies based on sensitive data, users, devices, domains, and usage scenarios. Bring usage, risk, and cost information together within a centralized governance layer. Create a learning model that helps employees use the right AI tools for the right scenarios. Build a provider-independent and extensible architecture capable of supporting different AI services and future models. In the long term, establish a sustainable AI operating layer that unifies governance, learning, policy, cost, and agent management within the same ecosystem.

Solution

Project PARS is designed as a layered AI governance platform rather than a closed system attempting to control all enterprise AI usage from a single point. At the usage layer, browser extensions and the gateway provide visibility into AI interactions while helping identify sensitive data and risky usage patterns. The Governance Dashboard turns this information into meaningful insights across the organization, teams, users, and usage scenarios. Policy Builder translates organizational policies into technical controls. Cost Center provides visibility into usage and cost. The Learning layer is intended not merely to restrict employees, but to guide them toward more appropriate and effective AI usage. Additional capabilities such as Prompt Library and Agent Management extend the platform beyond today's generative AI tools, preparing it for increasingly common enterprise AI agents and automation scenarios. The goal is to bring security, governance, learning, cost, and operations—often handled through separate tools—under a common management model.

Architecture

PARS is designed around a layered architecture that is not dependent on a single application. At the user-facing layer, browser extensions for Chrome, Edge, and Firefox observe AI usage and are responsible for risk classification, policy checks, and generating the required audit data. At the enterprise network layer, the Gateway acts as a centralized policy enforcement, authentication, and audit collection point while taking organizational context such as user, device, domain, and IP into account. Integration with SSO, MFA, and enterprise identity systems is a core part of this layer. At the management layer, the Governance Dashboard provides centralized visibility into usage, risk, policy, and operational data. Modules such as Policy Builder, Learning, Cost Center, Prompt Library, and Agent Management operate around the same governance model. On the backend, sustainability and modular growth are priorities. The architecture uses Clean Architecture, a Modular Monolith, pragmatic DDD, and lightweight CQRS where appropriate, allowing modules to remain clearly separated without introducing unnecessary distributed-system complexity at an early stage. Rather than being tightly coupled to a specific LLM or AI provider, the architecture is designed to support different models and services under shared governance policies.

My Role

I created the product concept, problem definition, scope, and technical direction of Project PARS. I lead both the product and technical aspects of the initiative. My responsibilities include defining use cases, shaping module boundaries, establishing the governance approach, designing the system architecture, and making key technical decisions. My focus is not only on making the solution technically functional, but also on ensuring that it addresses real enterprise needs, strikes the right balance between security and user experience, and establishes an architectural foundation capable of evolving into a sustainable product. I develop the project through small, verifiable steps, using prototypes, architectural decisions, testing, and feedback loops together to guide its direction.

Tech Stack

Backend: .NET / ASP.NET Core Frontend: Angular / TypeScript Architecture: Clean Architecture, Modular Monolith, pragmatic DDD, lightweight CQRS Identity & Access: SSO, MFA, JWT-based authentication, enterprise identity integrations Data: SQL-based operational data layer and audit/event-oriented data models Gateway: Centralized policy enforcement and audit layer within the enterprise network Browser Extension: Chrome, Edge, and Firefox AI Integrations: Provider-independent LLM/AI service integration approach Deployment: Container-based deployment, Docker, and enterprise/on-premises scenarios Observability: Centralized monitoring of audit events, usage, risk, and policy decisions

Key Decisions

Designing an AI governance platform that balances security with productivity rather than a security product focused solely on blocking AI usage. Avoiding reliance on the browser extension as the only control point by positioning the Extension, Gateway, and centralized Governance layer as complementary components. Building a provider-independent architecture in which different LLM and AI providers can operate under common governance policies. Treating Governance, Learning, Policy, Cost, and Agent Management not as isolated products, but as capabilities built around a shared data and governance model. Avoiding unnecessary microservice complexity in the early stages. Clean Architecture and a Modular Monolith preserve clear boundaries while keeping operational complexity under control. Treating on-premises deployment as a core architectural requirement because of enterprise usage scenarios. Ensuring that PARS does not stop at displaying risk in a dashboard, but connects observed usage and risk information to policies, actions, and learning processes.

Challenges

One of the biggest challenges is balancing security with user experience. Controls that are too restrictive can reduce the value employees gain from AI, while an overly permissive approach increases enterprise data and governance risks. The rapid evolution of the AI ecosystem creates another fundamental challenge. Models, providers, and usage patterns can change quickly, so the architecture needs to be designed around adaptable boundaries and policies rather than today's specific tools. Understanding usage context is also more than a technical problem. The same data or prompt may carry different levels of risk depending on the user, device, department, or business scenario. Policy decisions therefore cannot be reduced to simple keyword or content checks. Another challenge is finding the right boundary between visibility and privacy. The system needs enough audit information to support governance without collecting unnecessary user or content data. Finally, PARS is not a single-module product. Extension, Gateway, Dashboard, Policy, Learning, Cost, and Agent capabilities must continue to evolve without becoming disconnected or turning the product into unnecessary complexity.

Results

Project PARS is currently an actively evolving product vision. It has moved beyond the idea stage, with the scope and architecture of core capabilities such as usage control, the Governance Dashboard, policy management, learning, and the enterprise Gateway already taking shape. Initial validation work has focused on generating usage and risk information through the browser extension, collecting that information under a centralized audit model, and making it meaningful through the dashboard. The Gateway approach expanded the architecture further by demonstrating how control can be applied not only at the client level, but also within enterprise infrastructure. The most important outcome at the current stage is the emergence of a modular product model that goes beyond controlling a single AI tool and instead brings usage, security, governance, learning, and cost together within a common system. PARS continues to evolve. The next stages focus on validating the architecture against real-world usage scenarios, maturing individual modules, and producing measurable outcomes.

Lessons Learned

One of the most important lessons has been that AI governance is not simply a security or access-control problem. An effective enterprise AI strategy requires security, user experience, learning, cost, policy, and operations to be considered together. A second key learning is that visibility is a prerequisite for control. Without understanding how AI is actually being used across an organization, it is difficult to define appropriate policies or measure their effectiveness. Applying the same policy to every scenario is unlikely to be sustainable. Evaluating user, device, data, application, and business context together creates a more meaningful governance model than a simple allow-or-block approach. From an architectural perspective, establishing boundaries that can accommodate change is more valuable than designing excessive complexity around predictions of the future. AI providers and models will change; governance principles, the audit model, and clear responsibilities between modules should be more durable. Ultimately, the purpose of a strong AI governance system should not be to reduce AI adoption. It should enable the organization to create value from AI in a safer, more deliberate, and measurable way.