Skip to main content
Pre-built governance policies mapped to actual compliance frameworks. Load a template and get enforcement that satisfies auditors — not generic guardrails.

How templates work

Templates define what to enforce at the tool-call boundary. They work with every framework TealTiger supports:
Each template is a YAML file mapping specific regulatory controls to TealTiger features:

Template catalog

Base (cross-industry foundations)

Financial services

Healthcare

Government

Technology

Regulatory control mapping

Each template includes a mapping table showing exactly which TealTiger feature satisfies which compliance control. Example — SOC 2: Example — HIPAA:

Composing templates

Templates are composable. Use a base + an industry template for layered governance:
When composed, the most restrictive policy wins for each check type.

Custom overrides

Extend any template without forking:

What templates produce

Every template generates the same audit evidence:
  • GovernanceDecision per tool call — action, reason codes, risk score, latency
  • TEEC receipts — tamper-evident execution records with correlation IDs
  • Cost tracking — cumulative session spend attributed per tool
  • Deny records — prove unauthorized actions were blocked (auditor evidence)
This evidence maps directly to compliance framework requirements — SOC 2 observation period evidence, HIPAA audit controls, GDPR processing records, FedRAMP continuous monitoring.

Source

All templates are open source (Apache 2.0) and available in the repository: packages/tealtiger-python/src/tealtiger/templates/ Contributions welcome — especially from compliance professionals who can validate regulatory mappings.