What's in this guide
A practical, enterprise-scale walkthrough, in order:
1. Why prompts need governance — treating prompts as production assets.
2. Policy: the rules that define acceptable prompt use.
3. Approval and review workflows — who signs off, and how.
4. Versioning and rollback — changing prompts safely.
5. PII and data handling — what may and may not enter a prompt.
6. Prompt injection and system-prompt leakage — OWASP LLM01 and LLM07.
7. Audit logging — proving what happened.
8. Model selection — choosing models against documented criteria.
9. The honest limits of governance.
We include a maturity comparison table, FAQs, and a Sources section. Security references point to OWASP; pricing references link to live provider pages.