Agents plan, decide and act. That moves the control problem out of the model and into the architecture. This is the standards set, the reference architecture and the runtime guardrails I would put in front of any enterprise agent program.
Five points. If you read nothing else on this site, read these.
A model produces text. An agent plans, calls tools and changes state. Instructions in a prompt steer behaviour; they cannot stop it. Anything that must not happen belongs in code on the enforcement path, where injected text cannot reach it.
One agent can retrieve a policy document, draft a reply, update an address and move money. Those are four different risk classes. Score the use case and the action class on reversibility, blast radius, data sensitivity and impact on people, then let regulatory classification cap the result.
Author policy once and version it centrally. Enforce it at the gateway, the tool broker, the memory service, the retrieval layer and the workflow engine. A single physical chokepoint for all traffic becomes a bottleneck and an availability risk. The rule is no ungoverned paths, not one pipe.
Allow-lists, value caps, tenant boundaries, short-lived audience-bound credentials, egress control, sandboxing, idempotency and circuit breakers are code. Injection screening, grounding checks and guardian agents add signal and catch drift. They are not the boundary for an irreversible action.
Log the intent, the policy decision and the inputs before the tool runs, to an append-only store, with the policy version attached. If the write fails, the action fails. That single ordering rule turns explainability, audit, incident replay and evaluation from projects into by-products.
Six things that hold whatever your platform, your sector or your model vendor turns out to be.
Identity, named accountable owner, purpose, tier and an expiry date. The registry becomes the allow-list, and everything else hangs off it.
Intent, decision, inputs and policy version to an append-only store. If logging fails, the action fails. Cheap now, impossible to retrofit after an incident.
Exchange identity plus delegated scope for a short-lived, audience-bound token at the moment of use. Nothing outlives the task, nothing passes through.
Tool and parameter allow-lists, value caps, tenant boundaries, egress rules, sandboxes, idempotency, circuit breakers. Assume every probabilistic check misses.
Self-service at the bottom, real scrutiny at the top. If the governed path is slower than building around it, teams build around it.
Per agent, per tool, global. Test it on a schedule and log the test. An untested kill switch is a belief, not a control.
Each card opens its own page: a diagram, a short orientation, then the detail. Warmer cards carry the core architecture argument; cooler ones are context, reference and tooling.
What changed through 2026: agent-specific regulation, a rewritten threat model, identity as a platform feature, and a moved EU deadline.
Read the signal 02 Anatomy of an agentNine components, each with its own owner, its own control and its own way of failing. Naming them separately is what makes governance tractable.
See the components 03 Reference architectureSeven planes, two control rails, 57 platform examples, and the policy administration, decision, information and enforcement points drawn apart.
Open the architecture 04 Autonomy and riskTiers R0 to R4 for the agent, classes A1 to A4 for the action, and the overlays that cap a ceiling instead of averaging into it.
Set the tiers 05 Guardrail stackPreventive, runtime and detective. Which controls are hard enough to be a boundary, and which are only ever a signal.
Build the stack 06 Governance in actionOne claims refund end to end, then the same request carrying a prompt injection, and exactly which controls stop it.
Follow the request 07 Best practicesSeven disciplines, eight rules each, with the standard I would hold and the trap I would expect, from integration through to developer enablement.
Read the practices 08 Standards and crosswalkFifteen enforceable controls, each with a mechanism and evidence, mapped to ISO 42001, NIST, the EU AI Act, IMDA and OWASP.
Open the register 09 ImplementationTools, process and people across coding agents, customer operations, regulated research and platform operations. Plus who owns what.
See the patterns 10 From the fieldWhat a multi-domain master data programme taught me about identity, trust scoring, console sprawl and the constraint you will actually hit.
Read the lessons 11 RoadmapFour moves over twelve months. You do not need the whole platform before the first agent ships, but you do need three things.
See the sequence 12 Companion toolkitSeven downloadable artifacts: agent card, risk assessment, standards register, threat model, event schema, scorecard, readiness checklist.
Get the templates 13 Straight answersEleven questions that come up in every design review, answered without hedging.
Read the answers 14 GlossaryFifty terms and acronyms, filterable. Agent governance borrows vocabulary from four disciplines at once.
Look something up 15 ReferencesNineteen sources, every one linked and attributed, with commercially interested material flagged.
Check the sourcesIf you are standing up an agent platform, tightening the controls on one you already have, or preparing for an audit that now includes agents, I am happy to look at it with you.
Tell me where you are with agents and what you are trying to make safe. I reply to every enquiry within two business days.