Validation proves that metadata, schemas, mappings, access logic, and capabilities behave as expected. Certification turns those outcomes into enterprise readiness — proof that a system, datasource, or capability is ready for AI-assisted work in a defined scope.
Certification runs whenever capabilities, policies, integrations, or AI-exposed behavior changes. AI changes too quickly for one-off manual certification. Certification is part of promotion readiness and Operational Trust.
Why it matters
Enterprises cannot safely expose AI to integrations that have not been tested against business rules. Validation catches misconfiguration before production use. Certification makes readiness visible to architects, operators, and risk stakeholders — across operations, agent metadata trust, and governance.
Certified does not mean currently authorised. A conversation or a green report does not become operational truth by itself. Runtime Operational Trust still verifies the identified person, role, scope, and approvals for each case.
How it works
Describe the business and integrations
→ Validate structure, permissions, and behavior
→ Certify readiness for a scope
→ Human approval / make available
→ Governed AI use (runtime checks continue)
Validation checks include schema correctness, field mappings, dimension behavior, capability definitions, and tests against real or sandbox systems.
Certification aggregates readiness across three pillars:
| Pillar | What it proves |
|---|---|
| Operations | Integration behavior against live or sandbox systems |
| Agent metadata trust | Business metadata is complete and trustworthy for AI |
| Governance | Subject-scoped visibility matches policy expectations |
Integrators run the detailed command ladder and lifecycle report on the Build track — Certification. This page stays at the business meaning of readiness.
When operational trust gates are enabled, certification outcomes also enforce publish and runtime paths — see Operational trust gates.
When to recertify
Re-run certification when integrations change materially: new datasources, dimension key changes, protection updates, authentication changes, or vendor API upgrades that alter field mappings.
Production Role Assistant scope should include governance proof for subject-scoped data access. Evidence from certification belongs in operational records alongside change tickets — not only on developer workstations.
Executives should see certification as evidence of readiness for a scope — which integrations, roles, and capabilities are approved for AI-assisted work in each environment. Separate frequent validation in development from certification before production Role Assistant use.
Example
Before a customer-search capability is available to a Sales Assistant, the underlying datasource passes validation and certification for that scope. Uncertified or failing sources remain blocked or limited until remediated. Even after certification, each request still runs under Operational Trust for the identified person.
Business value
Validation and certification reduce production surprises, make AI-ready systems visible, and support governance reviews with evidence of readiness — not ad hoc checklists.