-
To create governance strategies, either:
-
API Governance: Governance Administrator
-
API Manager: Manage Policies
-
-
To view governance reports, either:
-
API Governance: Governance Viewer
-
API Governance: Governance Administrator
-
Working with Governance Strategies
Use governance strategies to apply conformance rules and policies across agents, APIs and MCP servers. When your tenant includes Governance and your account has the required role, you can create, manage, and monitor these strategies to validate service design compliance, automate runtime enforcement, and maintain visibility as your portfolio grows.
| The MuleSoft interface uses two terms for strategy types: controls (for guardrail-based strategies) and automated policies. In this documentation, "strategy" refers to both types unless otherwise specified. |
Before You Begin
Before getting started, make sure you have:
-
An Anypoint Platform account.
-
These permissions:
For more information, see Enhanced Experience Permissions.
Access Governance Strategy Workflows
Log in through your organization’s entry path and go to Governance.
From Governance > Governance Strategies, create strategies and map them to approved services or scopes. You can also edit, enable, disable, reorder, or delete existing strategies.
Work with your governance lead when strategy changes affect production or compliance workflows.
Governance Strategy Workflows
-
Create strategies for compliance validation or runtime enforcement. See Create Governance Strategies.
-
Manage strategies by updating scope, rules, status, and priority. See Managing Governance Strategies.
-
Monitor token usage in Governance > Cost Management. See Managing Costs and Token Usage.
-
Review conformance reporting for supported catalog types.
-
Apply policies to services from Portfolio. See Viewing Service Details in the Portfolio.
Akamai Security Findings in Conformance Reports
When Akamai API Security is connected as a provider, the Violations, Warnings, and Info counts in the conformance report include Akamai security findings alongside governance rule results. A service can show a Non-Conformant status even when no governance rules are violated, if Akamai findings contribute violations.
The Conformance tab includes a dedicated Akamai section with two tables:
-
Security Findings: Individual security issues detected by Akamai through live traffic inspection, broken down per instance and per endpoint.
-
Incidents: Recurring threats aggregated over time, with first- and last-seen timestamps and occurrence counts.
Both tables have these sortable columns: Finding, Instance, Endpoint, and Risk.
Akamai severity levels map to conformance tiers as follows:
-
Critical and High map to violations.
-
Medium maps to warnings.
-
Low and Info map to informational findings.
The Severity filter at the top of the Conformance tab applies to both the governance rule results and the Akamai tables.
Review a Finding
Select a row in the Security Findings table to open the finding detail panel, which shows:
-
Triggered On: The endpoint path where the issue was detected.
-
Risk: The severity level.
-
Exposure: Whether the endpoint is internet-facing.
-
Remediation Opportunities: Curated recommended policies for this finding type. Select Apply This Policy to open the policy-apply flow with the policy pre-selected. Select Browse in Policy Library if no curated policy is listed. After a policy is applied, Akamai re-inspects live traffic and updates the finding status automatically.
Review an Incident
Select a row in the Incidents table to open the incident detail panel, which shows: Detection Time, Type, Triggered On, Severity, Occurrences, Exposure, OWASP tags, and Compliance Frameworks.
Refresh Conformance Results
After a scan runs, the API listing and API detail pages don’t automatically reflect the updated conformance status. To see the latest results, manually refresh in one of these ways:
-
Refresh a single API: On the API detail page, open the Conformance tab and select Refresh.
-
Refresh all APIs: On the Governance Strategies page, select Refresh Report.



