Upcoming Workshop: Citizen Developer Agentic Software Factory on AWS
Register Here!What happens when an employee deploys an AI-built app
Don runs onboarding in HR operations. He built an app with Claude Code that reconciles the weekly HRIS export against payroll and benefits. His laptop now holds six months of those exports, with SSNs and bank account numbers for thousands of people. Massdriver Architect gets that app off his laptop and onto governed infrastructure, with no cloud credentials, no new copies of restricted data, and an owner and audit trail your risk team can see. Here’s how.
- 01What Architect does
Architect starts from Don’s description. Don names no databases, networks, or cloud accounts.
What your risk team getsDon never holds cloud credentials. His Massdriver token is his only credential.
- 02What Architect does
Architect reads the catalog your platform team published and designs the app from those bundles only.
What your risk team getsNothing outside the approved catalog can be deployed.
- 03What Architect does
It finds hr-warehouse, the database that already holds employee records, and gives the app read access to it.
What your risk team getsNo new copy of restricted data. The app reads the records where they already live.
- 04What Architect does
There is no approved HRIS connector, so Architect files a catalog request with the platform team.
What your risk team getsThe platform team gets a request for the missing connector and decides whether to build it.
- 05What Architect does
Policy checks run, and the app deploys to the environment Don is allowed to use.
What your risk team getsA new inventory entry: owner don.r in hr-ops, reads hr-warehouse (restricted), no new data stores, and an audit record of every change.
Sample scenario. hr-warehouse and the catalog stand for what your own teams publish.
Code scanners and identity providers do not govern where an app runs.
Your SAST and code review tools inspect what the AI wrote. Your identity provider decides who can log in. Neither one knows that an analyst's AI-built dashboard writes customer records to a database that never went through change control, in a cloud account nobody inventoried, under the analyst's own credentials. Massdriver closes that gap at the infrastructure layer, before anything is provisioned.
How it works
Your teams approve a catalog
Your security and platform teams approve the infrastructure options: which databases, which compute, which networks, in which environments.
Builders use only the catalog
Anyone building with an AI agent can use only what is in the catalog for their group. Anything outside the catalog is not available to them.
Every deploy is checked and recorded
Policy checks run before every deploy, and each deploy is recorded and attributed to a person or an agent.
One inventory, with owners
Everything built appears in one inventory with an owner, and engineering can take it over without a rewrite.
How the controls map to your frameworks
Each row names a requirement, the Massdriver control that meets it, and the evidence an auditor can request.
| Framework | Requirement | How Massdriver meets it | Evidence produced |
|---|---|---|---|
| SOC 2 CC8.1 | Changes to infrastructure and software are authorized, tested, approved, and documented | Plan, propose, and deploy are separate permissioned steps; policy runs before deploy; every change is recorded | Per-change record with proposer, approver, plan diff, and policy results |
| SOC 2 CC6.1 / CC6.3 | Logical access restricted by role; least privilege | Attribute-based access control scoped to environment, team, and attributes your organization defines; AI agents hold Massdriver tokens, never cloud credentials | Token scope definitions; access log |
| SOC 2 CC7.2 | System components monitored; anomalies investigated | Live inventory of every provisioned resource with its owner and dependency graph | Queryable inventory export |
| PCI DSS Req 6 / Req 10 | Secure development lifecycle; log and monitor all access | Policy gate before deploy; attributable change log | Policy results per change; log export |
| NIST AI RMF Govern / Manage | Policies for AI system use; risks managed and documented | Agents constrained to the approved catalog; every agent action attributable and reversible | Agent action log |
| ISO/IEC 42001 | AI management system controls over AI-produced outputs | The same controls apply to AI-built and human-built infrastructure | Unified change record |
Three questions an auditor asks
What’s running?
One inventory of every AI-built app and the infrastructure under it, by team, environment, and owner.
Who approved it?
Every deploy carries the proposer, the approver, the policy results, and the diff.
Who owns it when the builder leaves?
The infrastructure is stored as plain Terraform, OpenTofu, and Helm. Engineering can pull it into their own repository without a rewrite.
Trusted by teams at





“Massdriver’s platform has revolutionized our approach to infrastructure, saving us 89% of the time spent managing infrastructure. Our operation could upscale by an order of magnitude.”

For your platform team
Your platform team will ask how this fits with the Terraform they already write and the tools they already run. Massdriver runs their existing Terraform, OpenTofu, and Helm modules as they are, and their policy checks run before every deploy.
Questions from security and risk teams
Does this replace our code scanning or SAST?
No. Those tools check the code. Massdriver governs the infrastructure the code runs on. You need both.
Does this govern Power Platform, Copilot Studio, or Salesforce apps?
No. Those are low-code platforms with their own governance tools. Massdriver governs software that runs on your cloud infrastructure: AWS, Azure, and GCP.
Do employees or AI agents need cloud credentials?
No. A Massdriver token is the only credential they hold. Massdriver holds the cloud credentials.
What does an auditor see?
Per-change records with the proposer, approver, plan, policy results, and outcome; a live inventory with owners; and the scope of every token.
What happens when the builder leaves?
Engineering takes it over. The infrastructure definition is plain Terraform, OpenTofu, or Helm in a registry you control, so nothing needs a rewrite.
Is it self-hosted?
Yes. Massdriver runs self-hosted inside your cloud account, or we run it for you.
Can an AI agent reach production?
Only if your policy allows it. You can let an agent propose a production change and keep the permission to deploy it with a human approver.