I spent several years delivering a multi-domain master data and data quality program: customer, membership, certification and product, across roughly a dozen source systems, built domain by domain from proof of concept to production.
The program's hardest work was not the pipelines. It was deciding which record represented which real customer, and keeping that decision stable as a dozen systems argued about it. Cross-reference tables and survivorship rules existed so that any downstream question could be answered with "this record, from this source, at this time, by this rule."
Agent governance asks the same question about actions. Which agent did this, on whose authority, using which entitlement, at what time. The agent registry and the decision log are the cross-reference table of the agentic era. Build them first, for the same reason.
That program used a trust framework where each source system carried a confidence weight per attribute, set by hand in workshops with the business. It was slow to configure, but it turned an unwinnable argument about which system was right into a tunable dial.
Agent autonomy tiers work the same way. Binary allowed-or-not governance produces either paralysis or shadow adoption. A tier that an agent earns through evidence, and can lose, gives the business a dial instead of a fight.
Stewards on that program worked across six tools and five consoles to resolve one record. Each tool was defensible on its own. Together they made the daily job slow enough that people worked around the process, which is exactly what governance is supposed to prevent.
The same risk sits in front of agent platforms today: one console for identity, another for policy, another for traces, another for evals, another for cost. Consolidate the operator view early. If checking an agent takes five tabs, nobody checks.
That hub loaded daily, which put a 24-hour ceiling on freshness. Applications that needed real-time reads ended up with their own local caches. The architecture was correct for its era and its constraints, and the workaround was a rational response to a real limit.
Agent platforms hit the same shape of constraint through latency. If the governed path adds seconds to every tool call, teams will build a faster ungoverned one. Budget the control-plane latency as a design requirement from the start.
If you are standing up an agent platform, tightening the controls on one you already have, or preparing for an audit that now includes agents, I am happy to look at it with you.
Tell me where you are with agents and what you are trying to make safe. I reply to every enquiry within two business days.