Governance guide

How to govern Gemini

A step-by-step guide to governing Gemini with Rencore: detect with 27 policies, review with 7 reports, and remediate with 4 automations.

Definition

Governing Gemini means keeping its access, configuration, and lifecycle under continuous control rather than reacting after something breaks. Rencore governs Gemini with 27 pre-built policies, 7 reports, and 4 automations, so teams can detect risk, review posture, and remediate with an audit trail. The steps below turn that coverage into a repeatable routine.

Steps

  1. Inventory Gemini

    Connect Gemini and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.

  2. Detect with policies

    Turn on the pre-built policies that cover Gemini to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.

  3. Review by owner and severity

    Use the Gemini reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.

  4. Remediate and automate

    Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.

Recommended Gemini policies

Grounded in the Rencore catalog. See the full Gemini catalog on the Gemini connector page.

  • Gemini user is an external identity

    External (guest) users are a more probable attack vector, raising the likelihood that reachable Vertex AI resources are exploited

    Severity: Medium
  • Gemini notebook runtime is running

    Running notebook runtimes are a live, reachable compute surface, raising the likelihood that any weakness is exploited

    Severity: Medium
  • Gemini endpoint is serving traffic

    Endpoints with deployed models are a live, callable prediction surface, raising the likelihood that any weakness is exploited

    Severity: Medium
  • Gemini model is deployed and live

    Models deployed to endpoints are actively serving predictions, raising the likelihood that any weakness is exploited

    Severity: Medium
  • Gemini engine is live with data stores

    Engines connected to data stores actively serve content to callers, raising the likelihood that any weakness is exploited

    Severity: Medium
  • Gemini agent is live and in use

    Agents updated within the last 90 days are live, callable surfaces, raising the likelihood that any weakness is exploited

    Severity: Medium
  • Gemini user is deactivated in Entra ID

    Detects Gemini users who are deactivated in the parent Entra ID

    Severity: Medium
  • Gemini user is external user in Entra ID

    Detects Gemini users which are guest in the Entra ID directory

    Severity: Medium
  • Gemini notebook runtime in unhealthy state

    Detects notebook runtimes that are reporting an unhealthy health state

    Severity: High
  • Gemini agent not updated in 90 days

    Detects deployed reasoning engines (agents) that have not been updated in the last 90 days

    Severity: Medium
  • Gemini agent without description

    Detects deployed reasoning engines (agents) that have no description set

    Severity: Low
  • Gemini tuning job in failed state

    Detects fine-tuning jobs that have failed

    Severity: Medium
Explore the full Gemini governance catalog | All guides

Trusted by

MAPALBAMVille de LuxembourgWACKERGRUNDFOSAMGENOsramLufthansaThyssenKruppSunrisePattern