RSS Amplifier

Joe’s Substack · Jun 7, 2026

Every campus is running dozens of AI tools. Almost none can tell you where they all are.

0
Sign in to vote or save

Joe Sabado · Joe’s Substack

Walk into any college or university today and ask a simple question: What AI tools are we using, who owns them, and what data are people allowed to put into them?

You will rarely get one answer. You’ll get five — from IT, from the provost’s office, from a research lab, from whoever signed the last vendor contract. The acceptable-use policy lives on one web page. The tool “catalog,” if it exists, lives on another. The risk reviews live in someone’s shared drive. The model details live in a vendor PDF nobody has read.

None of this happened on purpose. Campus AI didn’t arrive through a single decision — it accumulated. A sandbox here, Copilot licenses there, AI features quietly switched on inside the CRM and the LMS, a research cluster spun up for a grant. Each one made sense on its own. Together, they became a sprawl that nobody fully documents.

I’ve spent a while thinking about how to bring order to that sprawl without turning it into a paperwork exercise. This post introduces what I came up with — a Campus AI Registry & Governance Framework — and, more importantly, a working demonstration site you can actually click through to see how it would look in practice.

The core move is to stop treating “AI documentation” as one thing and treat it as a stack of layers, each answering a narrower question than the one above it:

  1. Institutional governance — principles, acceptable use, data classification, academic integrity.

  2. NIST AI RMF profiles — risk guidance tailored to specific contexts (teaching, research, administration, and so on).

  3. Service catalog — the index of what’s supported.

  4. Service cards — what a tool is, who it’s for, and the rules, written for users.

  5. System cards — the deployment behind a tool: architecture, controls, audit.

  6. Model cards — the models underneath, vendor or internal.

  7. Supporting evidence — the risk registers and reviews that auditors rely on.

The second move is just as important: every artifact carries a visibility label — Public, Institution-wide, Restricted Internal, or Confidential. That’s what makes this a transparency framework rather than a “publish everything” free-for-all. Transparency isn’t dumping your risk register on the open web; it’s disclosing the right thing to the right audience, on purpose.

I went back and forth on what to call this. “Documentation framework” was accurate but flat — it described the activity, not the result. What you actually end up with is a registry: a single, browsable record of the AI an institution uses, each entry documented and labeled. Several cities already run public “AI registers” for exactly this reason. Higher ed should too.

So: the Campus AI Registry & Governance Framework.

A framework diagram only gets you so far. The thing I most wanted to answer was, “Okay — but what would this actually look like as a real campus site?”

So I built one. Meridian State University is a fictional institution, and its AI Registry & Governance Hub is a fully clickable demonstration of the framework in practice. It looks and behaves like a real campus AI portal:

  • A tool directory of ten AI services you can filter by category, audience, and visibility.

  • Guidance by role — what students, faculty, staff, and researchers can each use, and the rules that apply.

  • Policies — principles, acceptable use, academic-integrity course stances, data classification, and the institution’s RMF profiles.

  • Detail pages for every tool, from the managed “Meridian GPT” sandbox to Copilot, the LMS features, the admissions CRM, and a secure research cluster.

And because the whole point is documentation, each artifact can also be viewed as an actual document — a formatted, classification-stamped, printable card you could hand to a reviewer. You can see what a public service card looks like, what a Restricted Internal system card looks like, and — importantly — what a Confidential risk-evidence review looks like, so the difference between the visibility tiers is concrete rather than abstract.

One small example I’m fond of: a managed sandbox is the clearest case of how the cards relate — one service runs on one system, and that system offers many models. The site draws that relationship out as a simple diagram, because once you see the 1-to-1-to-many shape, the whole structure clicks.

If you’re a CIO, a provost’s office, an AI governance committee, or anyone tasked with getting a handle on campus AI, my hope is that this gives you two things: a structure to organize what you already have, and a concrete picture of where it could lead. Most of the pieces already exist at most institutions, scattered. The framework is mostly about connecting them — and deciding, deliberately, what to publish.

The framework, the site, and a downloadable whitepaper are released under CC BY 4.0. Use it, adapt it, build your own institution’s version — all I ask is attribution.

One note: this is a personal project. It isn’t associated with, supported by, or endorsed by my employer, and the views here are my own.

If this is useful, I’d love to hear how you’d change it for your campus. Click through the demo, read the whitepaper, and tell me what’s missing.

👉 Explore the framework and the Meridian State demo site →

Read the original on joesabado.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.