Principled AI Lifecycle Orchestration
Allowed is not verified. Give PALO one AI use case. Leave with a traceable, reviewable evidence dossier and a local validation receipt in less than ten minutes.
No account. No mandatory telemetry. Your answers stay in the browser and export is voluntary. The receipt proves local schema checks and digest binding; it is not certification, legal advice, production approval or independent assurance.
From a clone:
npm run evidence:validateThe starter pack includes three schema-valid gold cases. Use npm run case:contribute -- --help to generate a community case, validate it and prepare its pull request body.
PALO is an open-source framework and toolkit for operational AI governance. It helps teams translate principles, laws, and standards into lifecycle decisions, risk assessments, evidence artifacts, KPIs/KRIs, and repeatable governance gates.
Naming convention: PALO is the canonical project brand. The punctuated form P.A.L.O. is retained only where it is part of an existing publication or mobile-store title.
- Website: paloframework.org
- Android: P.A.L.O. Framework Toolbox on Google Play
- iOS/iPadOS: P.A.L.O. Framework Toolbox on the App Store
- Documentation: PALOFrameworkV2.pdf, PALO v1 paper, and the interactive modules in this repository
PALO is both an open-source governance framework and a published research artifact. GitHub citation metadata are maintained in CITATION.cff, which provides the preferred academic citation for the framework.
Preferred research citation
Degni, F. (2026). Il Framework PALO per la Corporate Governance dell'IA: un paradigma per l'orchestrazione del ciclo di vita dell'Intelligenza Artificiale basato su principi in ambito aziendale. Rivista Corporate Governance, Numero Straordinario 2026. G. Giappichelli Editore. ISSN 2724-1068 / EISSN 2784-8647.
- Cite this repository
- Published paper and recognition sources
- PALO v1 research paper in the repository
PALO (Principled AI Lifecycle Orchestration) is designed for organizations that need practical AI governance across system-lifecycle activities such as ideation, risk classification, design, development, deployment, monitoring, incident response, and decommissioning. Across those activities, the canonical v3 governance decision loop uses six repeatable phases: Frame, Classify, Assess, Control, Measure, and Prove & Review. The eight system activities and six governance phases are complementary views, not competing lifecycle definitions.
The framework is aligned with major AI governance references including:
- EU AI Act
- ISO/IEC 42001 and ISO/IEC 42005
- NIST AI RMF
- OECD AI Principles
- UNESCO Recommendation on the Ethics of AI
- IMDA Model AI Governance Framework for Generative AI, where relevant to agentic AI
PALO is not a certification body and does not provide legal advice. It is a practical pre-screening, documentation, and governance support toolkit.
PALO v3.0.0 semantic foundation: canonical lifecycle definitions, relationships, decision history, evidence claims/evaluations and control-to-gate/source mappings now have stable semantic identity, explicit authority boundaries and executable schema/RDF/SHACL validation. The public Explorer is generated from this spine, and the semantic release inventory is digest-bound. See the v3 semantic foundation guide.
PALO-AI v2.5 full-cycle developer preview: the reference runtime now separates permission from outcome assurance through Effect Contracts, one-time execution capabilities, signed receipts, authoritative post-state verification, incident holds and single-instance recovery. The Governance Hub is an implemented React/Vite interface prototype using illustrative local data. These components are for isolated evaluation: they are not a production authorization service, an unavoidable execution boundary, a compliance certification, or a replacement for organization-owned identity, access control, key management, monitoring, backup, retention, legal review and independent security assurance.
PALO is the umbrella governance system across the AI lifecycle. Its public entry routes now begin with the problem to solve:
- Govern the AI lifecycle with the complete PALO Framework and its guided lifecycle tools.
- Govern agentic systems with PALO-AM, the agentic governance modality inside PALO.
- Enforce agent actions with PALO-AI, the technical control-plane Developer Preview that operationalizes selected PALO-AM controls.
Use the homepage governance map to choose among these connected routes.
PALO-AI is an emerging governance control plane for n8n and agentic automation platforms, designed to make authority, policy enforcement, human oversight and cryptographic evidence visible and enforceable.
Start with Why PALO-AI for the high-level full-cycle assurance case, then choose a code-first, n8n/no-code, or Copilot Studio/MCP quickstart. The cognitive Stakeholder Onboarding chooses an organizational role and objective. The "Govern agent actions" option adds a conditional build-mode question without replacing accountability. Continue in the guided PALO-AI Governance Hub or use the public Agentic Governance overview to connect PALO-AM methodology, PALO-AI runtime contracts, the role-based prototype and capability/readiness evidence.
n8n orchestrates what automation does. PALO governs whether an identified agent or automation is authorized to do it and whether the declared result is later verified. The integration combines four complementary patterns: a visible decision gate, a governed executor, digest-bound human approval, and workflow admission controls. Package 0.2 implements decision-gate and governed-execution prototypes; secure approval resume and instance-level admission remain specified capabilities. The package is unpublished and not n8n-verified.
- PALO-AI n8n governance control-plane architecture
- Why PALO-AI: interactive full-cycle comparison
- PALO-AI quickstarts: code, n8n and Copilot Studio/MCP
- PALO-AI cloud reference architecture
- PALO-AI security assurance and scale plan
- PALO-AI community and market-entry plan
- Governance Hub product specification
- Governance Hub user guide
- Governance Hub workflow and diagram index
- Governance Hub current status, production gaps and delivery waves
- Presentation and launch playbook
- Current n8n developer-preview example
- PALO + Microsoft AGT ACS interoperability proposal
- Installable n8n alpha package
- n8n alpha test report
- Architecture preview publication status and staged release gates
- Four-pattern hero infographic
- Three-minute architecture-preview demo
- Evidence-based capability matrix
- Public Production Readiness route
| Governance challenge | PALO response |
|---|---|
| EU AI Act classification uncertainty | Risk Tiering Calculator and FRIA workflow |
| Fundamental rights documentation gaps | Interactive FRIA Assessment and evidence prompts |
| Weak traceability between principles and controls | Lifecycle gates, KPIs/KRIs, and evidence artifacts |
| Human agency erosion | Human Agency Risk Map and mitigation guidance |
| Hidden or deceptive model behavior | AuditBench Explorer and alignment self-assessment |
| Data poisoning and integrity risks | Poisoning Boomerang module and Article 10/15 guidance |
| AI-assisted development risks | AI Dev Governance extension for coding assistants and rapid prototyping |
| Agentic systems and delegated action | PALO-AM Agentic Governance Modality v2.0 |
| Module | Description | Status |
|---|---|---|
| FRIA Assessment | Fundamental Rights Impact Assessment wizard for EU AI Act Article 27 preparation | Live |
| Risk Tiering Calculator | EU AI Act risk classification workflow | Live |
| KPI Generator | AI governance metrics aligned with PALO dimensions | Live |
| AI Model Canvas | Visual planning canvas for responsible AI use cases | Live |
| Framework Comparison | Compare governance frameworks and standards | Live |
| Human Agency Risk Map | Observatory on 18 activities humans increasingly delegate to AI | Live |
| Human Agency Risk Map IT | Italian version of the Human Agency observatory | Live |
| 2026 Tech Trends Observatory | Analysis of major consulting-firm technology outlooks and governance blind spots | Live |
| AuditBench Explorer | Interactive exploration of 14 hidden AI behaviors from AuditBench with PALO mitigations | Live |
| The Poisoning Boomerang | Data poisoning governance module with detection strategies and lifecycle controls | Live |
| AI Dev Governance | Security and governance extension for AI-assisted software development environments | Live |
| PALO-AM Agentic Governance | PALO extension for AI agents, delegated authority, action-space control, and agentic evidence | Live |
| Mobile Toolbox | Mobile workspace overview for Android and iOS/iPadOS apps | Live |
| Recognition and Sources | Public references, primary sources, and verification notes | Live |
| PALO Evidence Pack | Less-than-ten-minute local route from one AI use case to a reviewable dossier and voluntary validation receipt; built on Assessment Path | Live |
| Regulatory Watch 2026 | Dated AI Act watchlist with Article 4, Article 50, high-risk milestones, and official sources | Live |
| Documentation Library | Searchable HTML documentation with Start, Guide and Reference depth plus audience, task, product and maturity metadata | Live |
| Platform Map | Operational status, stakeholder-intent routes, modules, artifacts, research boundaries, and accessible table navigation | Live |
| Operationalization Explorer / Stakeholder Onboarding | Three-step local stakeholder routing into the six-phase weighted workflow and interactive 3D knowledge graph | Live |
| PALO v3 Semantic Foundation | Versioned semantic spine, lifecycle and gate history, atomic evidence contracts, mappings, RDF/SHACL and digest-bound release inventory | Live |
The P.A.L.O. Framework Toolbox brings the core governance tools to mobile:
- Android: Google Play
- iOS/iPadOS: App Store
The app is designed as a privacy-first mobile workspace for contextual AI governance work. Store listings describe offline use, local-first operation, no data collection, and mobile features such as Evidence Vault, biometric protection, PDF report generation, and direct access to PALO web modules.
| Date | Release | Highlights |
|---|---|---|
| 2026-08-12 | v3.0.1 - Evidence Pack Activation | One primary activation route, preloaded local case, voluntary digest-bound validation receipt, three gold cases, case:contribute and a 30-day new-module freeze |
| 2026-08-12 | v3.0.0 - Semantic Foundation | Canonical semantic spine, append-only gate decisions, atomic evidence/claim/evaluation contracts, RDF/SHACL invariants, mapping governance, Semantic Inspector and digest-bound releases |
| 2026-07-18 | v2.5.0 - Full-Cycle Agentic Assurance | Effect Contracts, one-time execution capabilities, trusted receipts, authoritative outcome attestations, held assurance incidents, crash recovery, and the n8n Governed Action preview |
| 2026-07-17 | v2.4.1 - PALO-AI Developer Preview | Versioned agentic contracts, reference MCP transports, draft Rego v1 policies, prototype approval and evidence flows, and non-production n8n/Dify examples |
| 2026-07-12 | v2.4.0 - Reliable Operational Evidence | Deterministic publication, local evidence workflows, P2 adoption foundations, the public Platform Map, and Explorer navigation mode |
| 2026-07-11 | v2.3.2 - Stakeholder Onboarding | Three plain-language questions, deterministic stakeholder routes, local JSON/Markdown export, guided handoff into the weighted workflow and 3D operational graph, plus cross-page module and Companion App coherence fixes |
| 2026-07-11 | v2.3.1 - Theory to Practice | Dedicated operating loop connecting all core PALO modules to concrete decisions, controls, KPI/KRI, evidence, and review outputs |
| 2026-07-11 | v2.3.0 - Workspace UI Refresh | New PolicyWatcher-inspired command bar, workspace hero, mobile navigation, compact footer, shared Community shell, and removal of non-essential compliance badges from the main UI |
| 2026-07-11 | v2.2.1 - PolicyWatcher Ecosystem Link | Added PolicyWatcher as a cited external monitoring companion for public policy changes, source QA, methodology, and post-deployment context |
| 2026-07-11 | v2.2.0 - Guided Assessment and Evidence Hub | Start Here entries, Assessment Path with local JSON/Markdown evidence bundle export, Regulatory Watch 2026, Documentation Hub, unified v2.1 shell, and Proof & Community media kit |
| 2026-07-11 | v2.1.0 - Regulatory Readiness and Trust Foundations | Article 27/50 wording review, accessibility status, privacy/security policy refresh, public recognition page, SEO metadata and sitemap alignment |
| 2026-06-22 | v2.0.1 - Documentation Sync | README roadmap, CHANGELOG, homepage changelog, RSS and release metadata aligned |
| 2026-06-22 | v2.0.0 - PALO-AM | Agentic Governance Modality for AI agents: identity, authority, risk matrix, control layer, evidence layer, action-space/autonomy matrix, KPI/KRI registry |
| 2026-05-15 | v1.8.0 - AI Dev Governance | Governance extension for AI-assisted software development, rapid prototyping, vibe coding, coding assistants, controlled environments, and evidence trails |
| 2026-04-08 | v1.7.1 - iOS/iPadOS App | App Store release for iPhone and iPad with Evidence Vault, biometric protection, PDF reports, and direct access to PALO web modules |
| 2026-03-25 | v1.7.0 - Poisoning Boomerang | Data poisoning module covering Miasma, Nepenthes, Nightshade, Glaze, Cloudflare AI Labyrinth, AttackAI, detection strategies, and EU AI Act Article 10/15 implications |
| 2026-03-12 | v1.6.0 - Android App | Google Play release of the offline, privacy-first P.A.L.O. Framework Toolbox |
| 2026-03-03 | v1.5.0 - AuditBench Explorer | Interactive analysis of 14 hidden behaviors and alignment auditing techniques |
See CHANGELOG.md for the full release history.
PALO's public record is separated below by evidence type so that a journal publication, a public presentation, and independent media or institutional references are not presented as equivalent forms of recognition. The Recognition & Sources page provides the underlying links and verification notes.
- Rivista Corporate Governance, Numero Straordinario 2026. Fabrizio Degni's PALO paper, "Il Framework PALO per la Corporate Governance dell'IA: un paradigma per l'orchestrazione del ciclo di vita dell'Intelligenza Artificiale basato su principi in ambito aziendale", was published on 4 March 2026 by G. Giappichelli Editore. The journal carries ISSN 2724-1068 / EISSN 2784-8647. This publication is also the repository's
preferred-citation.
- Human Economic Forum 2025. The official programme for the 9 December 2025 event at the Italian Chamber of Deputies lists Fabrizio Degni in the panel Diritto, responsabilità e coesione sociale. The event forms part of the documented public provenance of PALO and its creator. Open the programme.
- World AI Council. A public World AI Council post refers to PALO and notes recognition through Reuters coverage. Read the public reference.
- Rivista AI. Independent coverage examined the P.A.L.O. Framework Toolbox 2.0 in the context of AI governance and the Human Economic Forum. Read the article.
- Rivista Corporate Governance. The publisher's 2026 special-issue materials include the PALO contribution in the issue record. Open the special issue index.
These references provide research, provenance, and external context. The repository and framework documentation remain the source of truth for PALO's current implementation, capabilities, release status, and technical boundaries.
Open the PALO Evidence Pack. The synthetic agentic invoice case is preloaded, runs locally and can produce a reviewable dossier plus a voluntary validation receipt in less than ten minutes. Existing PALO modules remain available as downstream tools after the evidence route identifies what is needed.
The website remains static. The optional, non-production PALO-AI reference runtime uses Node.js 20+ and OPA.
To validate or regenerate the v3 semantic foundation, use npm run semantic:validate, npm run semantic:generate, and npm run semantic:release. The full release gate remains npm run p0; it bootstraps the locked Governance Hub dependencies and the verified OPA binary so the gate is reproducible from a clean clone after the root npm ci.
git clone https://github.com/sev7enITA/PALOframework.git
cd PALOframework
python3 -m http.server 8000Then open:
http://localhost:8000
You can also open index.html directly in a browser, although serving locally is recommended for consistent asset behavior.
The commands below are for isolated development and testing only. Do not connect this preview to production agents, sensitive data, privileged tools, or consequential decisions.
Remote n8n and MCP clients must use the PALO-AI Online VPS Deployment, which exposes authenticated HTTPS endpoints while keeping OPA on a private container network. The 127.0.0.1 commands below are only a laptop-development option.
npm ci
npm run opa:install
export PALO_OPA_URL=http://127.0.0.1:8181
export PALO_HMAC_KEYS_JSON='{"key-support-2026":"replace-with-a-secret-from-your-secret-manager"}'
npm run palo:mcpFor the non-production Dify or n8n examples, start the localhost gateway in a separate process. The bearer token is only a coarse developer control: it does not provide principal identity, role separation, administrative authorization, reviewer authentication, or production secret lifecycle. Do not commit these values or expose the gateway publicly.
export PALO_GATEWAY_TOKEN='replace-with-at-least-24-random-characters'
npm run palo:gatewayThe canonical contracts are under schemas/; executable runtime code is under packages/palo-mcp-server/; the synchronized MCP catalog and connector examples are under examples/agentic-interface/.
PALOframework/
|-- index.html # Homepage
|-- PALO_FRIA.html # FRIA Assessment
|-- PALO_RiskTiering.html # EU AI Act Risk Tiering Calculator
|-- PALO_KPIGenerator.html # KPI Generator
|-- PALO_ModelCanvasAI.html # AI Model Canvas
|-- PALO_ComparisonTool.html # Governance framework comparison
|-- PALO_HumanAgencyRiskMap.html # Human Agency Observatory (EN)
|-- PALO_HumanAgencyRiskMap_IT.html # Human Agency Observatory (IT)
|-- PALO_TechTrends2026.html # 2026 Tech Trends Observatory
|-- PALO_AuditBench.html # AuditBench Explorer
|-- PALO_PoisoningStudy.html # Data Poisoning Governance module
|-- PALO_VibeCoding.html # AI-assisted development governance
|-- PALO_AgenticGovernance.html # PALO-AM Agentic Governance
|-- PALO_CompanionApp.html # Mobile app landing page
|-- PALO_Community.html # Community and open collaboration
|-- PALO_Recognition.html # Public references and source notes
|-- PALO_AssessmentPath.html # Guided assessment and evidence bundle export
|-- PALO_RegulatoryWatch.html # Dated regulatory watchlist and sources
|-- PALO_DocumentationLibrary.html # Canonical searchable documentation index
|-- PALO_DocumentationHub.html # Backward-compatible transition page
|-- PALO_PlatformMap.html # Operational platform status and navigation map
|-- designs/
| +-- theory-to-practice-infographic/ # Stakeholder onboarding, weighted workflow, and 3D Explorer
|-- AppStoreListing.md # Store listing copy and source notes
|-- PALOFrameworkV2.pdf # Framework v2 documentation
|-- ThePALOFramework_*.pdf # PALO v1 paper
|-- assets/ # Static assets and templates
|-- framework/ # Framework documentation archive
|-- insights/ # Research sources and supporting material
|-- json/ # Canvas/data exports
|-- sitemap.xml # Search sitemap
|-- feed.xml # RSS feed
|-- accessibility.html # Accessibility statement
|-- privacy-policy.html # Privacy policy
|-- security-policy.html # Security policy
|-- README.md
|-- CHANGELOG.md
|-- CONTRIBUTING.md
|-- CODE_OF_CONDUCT.md
|-- SECURITY.md
+-- LICENSE
The Documentation Library is the canonical web-native reference for the lifecycle, modules, source set, semantic contracts, and contribution links. The former Documentation Hub remains as a backward-compatible transition page; the PDF remains the stable primary download record.
Primary framework documents and artifacts:
- PALOFrameworkV2.pdf
- The PALO Framework v1 paper, Feb 2026
- PALO-AM Agentic Governance page
- PALO-AI Governance Integration Guide
- Why PALO-AI
- PALO-AI Quickstarts
- PALO-AI Capability Matrix
- PALO-AI Production Readiness
- PALO Documentation Library
- PALO-AI Online VPS Deployment
- PALO-AM standalone document
- FRIA worksheet
- PALO Canvas JSON template
- PALO Assessment Path for a guided local evidence bundle
- Regulatory Watch 2026 for dated official-source checks
PolicyWatcher is a separate civic-tech portal by Fabrizio Degni for monitoring public privacy policies and terms of service, mapping policy changes, and exposing methodology and source-quality context. It complements the PALO lifecycle at Deployment and Monitoring, but it is not a PALO module, legal certification, or replacement for official sources.
Assessment Path can import a versioned palo-policywatcher-signal JSON file locally. The complete observation is preserved as a non-authoritative monitoring source pending human review; no assessment or Case File data is submitted to PolicyWatcher.
- PolicyWatcher Observatory
- PolicyWatcher Timeline
- PolicyWatcher Confidence Methodology
- PolicyWatcher Trust and Quality
- Local PolicyWatcher signal schema
Contributions are welcome. Useful areas include:
- Improving regulatory mappings and citations
- Reviewing controls and KPIs/KRIs
- Adding examples and worked case studies
- Translating modules
- Improving accessibility and mobile behavior
- Adding tests/checklists for generated reports
The fastest contribution path is a synthetic or safely publishable Casebook artifact:
npm run case:contribute -- \
--slug retail-returns-assistant \
--title "Retail returns assistant" \
--sector retail \
--scenario "An assistant drafts a recommendation while a named employee approves refunds." \
--community builders \
--author "@your-github-handle"The command generates a Case File, validates the public schema and prepares a PR body. It never pushes or opens a pull request automatically.
Please read CONTRIBUTING.md, CODE_OF_CONDUCT.md, and SECURITY.md before opening issues or pull requests.
Current baseline: v3.0.1 Evidence Pack Activation, released 2026-08-12. It adds one focused local activation route, three gold cases, voluntary digest-bound receipts and a Community Casebook contribution path on top of the v3.0.0 semantic foundation and PALO-AI v2.5 full-cycle reference runtime.
Activation focus: new non-essential modules are frozen from 2026-08-12 through 2026-09-10. Work is concentrated on Evidence Pack completion, external review, accessibility, negative tests and Community Casebook contributions. See the activation freeze.
Completed in H1 2026:
| Area | Status |
|---|---|
| Human Agency Risk Map | Complete |
| 2026 Tech Trends Observatory | Complete |
| Community and open collaboration page | Complete |
| AuditBench Explorer | Complete |
| Android mobile toolbox | Complete |
| iOS/iPadOS mobile toolbox | Complete |
| Poisoning Boomerang module | Complete |
| AI-assisted development governance extension | Complete |
| PALO-AM Agentic Governance Modality v2.0 | Complete |
| Documentation and release hygiene sync | Complete |
| Regulatory readiness and trust foundations | Complete |
| Guided assessment and evidence hub | Complete |
| Workspace UI and navigation refresh | Complete |
| Theory-to-practice operating loop | Complete |
| Stakeholder onboarding and Operationalization Explorer | Complete |
| Release reliability foundation | Complete |
| Operational platform and research map | Complete |
| PALO-AI contracts and reference runtime | Developer preview |
| PALO-AI full-cycle assurance and Governance Hub | Developer preview |
Planned roadmap:
| Target | Focus | Planned scope |
|---|---|---|
| v3.1 | Identity, durability and validated connectors | Identity-aware BFF, workload identity, scoped RBAC, managed key custody, durable state/queues and fresh n8n connector validation |
| v3.2 | Evidence and governance board packs | Board templates, decision logs, KPI/KRI registers, review packets and audit-ready summaries built on verified outcomes |
| v4.0 | Production integration layer | Independently assessed deployment patterns and integrations for enterprise workflows, issue trackers, GRC platforms and documentation systems |
Exploratory items:
- HarmonyOS Next feasibility for the mobile toolbox
- Mobile push delivery for remote approval requests; the current runtime supports MCP and authenticated local-gateway approval resolution without claiming a remote notification service
- Lightweight test suites for generated governance reports and evidence exports
PALO is an educational, governance-support, and pre-screening toolkit. It does not provide legal advice, does not certify compliance, and does not replace professional legal, technical, security, or conformity-assessment review.
PALO-AI v2.5 is explicitly non-production. Allowed records a policy decision; only a matching authoritative outcome may be labelled verified, and even that does not certify that an action was safe or lawful. Deployers remain responsible for independent threat modelling, authenticated identities and roles, least privilege, policy ownership, connector idempotency, trusted approval context, key custody and rotation, observability, incident response, backup, retention and validation against their real tools and environments.
This project is licensed under the MIT License. See LICENSE.
- Website: paloframework.org
- Email: contact@paloframework.org
- GitHub: sev7enITA/PALOframework