Scope: Access & provisioning, credits/usage, system setup, updates/releases.
Access and Provisioning
AI Ops manages Lovable access via service desk requests. Uses Okta/SSO where applicable. Lovable operates on a credit-consumption model; no automated deprovisioning workflow exists.
Credits and Usage
Managed by AI Ops as a shared organizational pool. Follow the AIPM Playbook: Lovable Credit & Capacity Management for requests and burndown calculations. Near-term operational decisions (e.g., 250 monthly credit caps) are temporary and not a permanent baseline.
System Setup
Uses AI Ops security baseline: company SSO, MFA, least privilege, private-by-default projects, and restricted publishing. Lovable code intended for production must be connected to the company GitLab repository. Note: Lovable is NOT cleared for public-facing or customer-data hosting; the approved alternative is re-architecture onto Vercel with Okta/CATO-gated access.
Updates and Releases
Governed release path: Lovable project extraction → GitLab merge-request review → Wiz security scan → AI code review → dependency checks → deployment. Open gap: verifying whether GitLab pipelines preventively block unsafe changes.