Home The signal Anatomy of an agent Reference architecture Risk-Tiers Guardrail stack Governance in action Best practices Standards and crosswalk Implementation From the field Roadmap Companion toolkit Straight answers Glossary References
11 · Roadmap

Twelve months, four moves

You do not need the full platform before the first agent ships. You need the policy system, the registry and the evidence trail. Everything else can be built while agents are already delivering value behind it. The windows below show sequence and dependency; your calendar depends on what already exists.

0–30 DAYS Establish registry · tiersaccountability 30–90 DAYS Enforce policy authorityidentity · evidence 90–180 DAYS Measure evals · red teamgolden path 180–365 DAYS Scale bounded autonomyaudit ready SEQUENCE AND DEPENDENCY, NOT A CALENDAR
Days 0 to 30 · Establish the floor

Registry, tiers and the accountability model

Stand up the agent registry and register everything already running, including the shadow ones. Publish the autonomy tiers and score existing use cases. Name an accountable owner for each. Write the standards register and agree it with security, risk and legal.

Agent registry liveTier model publishedStandards register agreedShadow agent discovery
Days 30 to 90 · Build the enforcement point

Policy system, identity, tool broker, evidence log

Stand up one policy authority and wire the enforcement points to it. Issue agent identities and propagate delegated principal scope. Stand up the tool broker with short-lived tokens and the private MCP registry. Turn on OpenTelemetry tracing and the append-only decision log. Test the kill switch and record the test.

One policy authorityAgent identity issuedShort-lived tokensDecision logKill switch tested
Days 90 to 180 · Make quality measurable

Evaluation, red teaming and the golden path

Build golden sets from production traces. Wire eval thresholds into CI as a release gate. Run the first structured red team against injection, tool misuse and memory poisoning. Ship the repository template so a new governed agent is a matter of hours. Start continuous production sampling.

Eval gate in CIGolden setsRed team cadenceGolden path templateProduction sampling
Days 180 to 365 · Scale with confidence

Bounded autonomy, portfolio management, audit readiness

Promote the first agents to R3 on evidence. Add guardian-agent monitoring and automatic rollback. Consolidate the operator console. Run a full incident drill. Map the control set to ISO/IEC 42001, the NIST AI RMF and the EU AI Act, and produce the first audit extract from the live pipeline rather than from a spreadsheet.

First R3 promotionsGuardian monitoringUnified operator consoleIncident drill completeAudit extract automated
If you only do one thing this quarter. Give every agent a registered identity behind one policy authority, and write an append-only record of every decision it makes before the action runs. Every other control in this document becomes straightforward once those two exist, and almost none of them are possible until they do.

Where would you start?

If you are standing up an agent platform, tightening the controls on one you already have, or preparing for an audit that now includes agents, I am happy to look at it with you.