TL;DR: Enterprise software is starting to turn decision traces into a compounding data loop, with context graphs converting human-plus-agent judgments into a queryable record of how organisations actually decide, according to Arize. The governance shift is less about analytics novelty than about who owns decision history, because that history now sits at the intersection of workflow, AI, and identity-led approval paths.
NHIMG editorial — based on content published by Arize: Using context graphs to build a data moat like Google’s using your enterprise data
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- NHIs outnumber human identities by 25x to 50x in modern enterprises.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
Questions worth separating out
Q: How should security teams govern AI-enabled workflows that can act on their own?
A: Treat them as identity-governed execution paths, not just software features.
Q: Why do context graphs create new risk for IAM teams?
A: Because context graphs let AI combine many individually permitted items into a sensitive whole.
Q: What breaks when AI agents capture reasoning but the organisation does not own the history?
A: The organisation loses portability, continuity, and auditability.
Practitioner guidance
- Classify decision traces as governed records Define retention, access, and audit requirements for decision traces before enabling broad collection.
- Separate operational logging from governance evidence Store trace data so teams can use it for analytics without exposing sensitive rationale to every operator.
- Set ownership for context graphs early Assign clear accountability across IAM, data governance, and AI platform teams for who can approve schema changes, retention changes, and cross-system linkage.
What's in the full article
Arize's full analysis covers the operational detail this post intentionally leaves for the source:
- How Arize AX records trigger, context, proposal, resolution, and outcome as structured traces.
- How reviewers annotate traces to enrich the dataset for future tuning and policy changes.
- How context graphs surface recurring vendor, policy, and approver patterns across thousands of decisions.
- How Arize frames portable decision history versus platform-locked compounding loops.
👉 Read Arize's analysis of context graphs and enterprise decision traces →
Decision traces and context graphs: what this means for governance?
Explore further
Decision traces are becoming identity-adjacent governance assets. Once AI agents sit inside approval workflows, the trace is no longer just telemetry. It becomes a record of who approved what, under which context, and with which exceptions. That places decision history close to identity governance, because the value lies in the linkage between action, authority, and accountability. Practitioners should treat this as governed decision evidence, not generic AI logging.
A question worth separating out:
Q: Who is accountable when an AI-assisted workflow leaks sensitive data?
A: Accountability sits with the organisation that allowed the workflow to operate outside governed controls. Security, IAM, and business owners all share responsibility for ensuring approval, logging, and lifecycle management exist before data moves through the path. If no one can block or revoke it, no one is governing it.
👉 Read our full editorial: Enterprise decision traces are becoming a compounding data moat