Operate

Governance is how a company stays in control after the first agent works.

Without it, every team launches a side agent. With too much of it, nothing reaches production. The job is a short set of rules an operator can use.

Adnan Boz
Adnan Boz

How I see it

AI agent governance

Agent governance should answer four questions. Who may put an agent on a workflow? What actions require approval? How is the agent evaluated after launch? Who can shut it off?

That is enough for a first production agent. A 40-page responsible-AI policy is not. The COO needs a decision path that lets a valuable workflow move and stops a risky one from going live on a Friday afternoon.

Governance also includes the do-not-fund list. Some work should stay human. Some work should stay a report. Recording those decisions is part of the system.

As more agents appear, governance becomes portfolio management: owners, cost, quality, and overlap. It should not become a transformation office.

Common mistakes

What teams usually get wrong.

01

Policy without an owner

A document nobody can apply will not stop a shadow agent or help a good one launch.

02

Committee as a default

If every change needs six approvals, the company will either stall or go around the process.

03

Governance after the incident

The first write-back is the moment to have rules, not the first customer complaint.

A useful diagnostic

Five questions before you fund the work.

  1. Can you name the person who can approve a production agent this month?

    If not, you have opinions, not governance.
  2. Is there a written list of actions agents may not take?

    A blank page means every team will invent its own boundary.
  3. Do launched agents have a review date and an owner?

    Unowned agents become abandoned software with access.
  4. Is there a kill switch that operations can use?

    Governance that cannot stop the system is ceremonial.
  5. Are overlapping agent projects visible in one place?

    If not, you will fund the same workflow twice.

Economic model

Minimum governance

approver + forbidden actions + owner + review cadence + kill switch

Add more process only when a second or third agent makes the minimum insufficient.

Three credible paths

How far should you go?

Do not force one solution. Choose the path the economics, the risk, and the organization can support.

01

One-page rules for the first agent

Write the owner, the allowed actions, the review date, and the shutoff path.

Best when

You are launching the first production workflow.

Limitation

Will not cover a portfolio.

02

Lightweight portfolio review

Review agents monthly for value, cost, quality, and overlap.

Best when

Two or more agents are in production or in build.

Limitation

Needs a single person who can say no.

03

Shared controls

Standard identity, logging, evaluation, and approval patterns across agents.

Best when

Several teams want to build and the first controls have been proven.

Limitation

Can become a platform program if you start here.

When this is the wrong next step

Do not fund an agent here.

  • The company wants a governance program instead of a first production result.
  • Legal wants a complete policy before anyone may see a workflow baseline.
  • There is no executive who will accept responsibility for a no.
Adnan Boz

A useful next step

Bring one workflow. Get guided into production.

We guide the implementation, go deep on the technical path, and stay hands-on through operations — or tell you when a simpler answer is better.

Discuss an AI opportunity