You do not need the full platform before the first agent ships. You need the policy system, the registry and the evidence trail. Everything else can be built while agents are already delivering value behind it. The windows below show sequence and dependency; your calendar depends on what already exists.
Stand up the agent registry and register everything already running, including the shadow ones. Publish the autonomy tiers and score existing use cases. Name an accountable owner for each. Write the standards register and agree it with security, risk and legal.
Stand up one policy authority and wire the enforcement points to it. Issue agent identities and propagate delegated principal scope. Stand up the tool broker with short-lived tokens and the private MCP registry. Turn on OpenTelemetry tracing and the append-only decision log. Test the kill switch and record the test.
Build golden sets from production traces. Wire eval thresholds into CI as a release gate. Run the first structured red team against injection, tool misuse and memory poisoning. Ship the repository template so a new governed agent is a matter of hours. Start continuous production sampling.
Promote the first agents to R3 on evidence. Add guardian-agent monitoring and automatic rollback. Consolidate the operator console. Run a full incident drill. Map the control set to ISO/IEC 42001, the NIST AI RMF and the EU AI Act, and produce the first audit extract from the live pipeline rather than from a spreadsheet.
If you are standing up an agent platform, tightening the controls on one you already have, or preparing for an audit that now includes agents, I am happy to look at it with you.
Tell me where you are with agents and what you are trying to make safe. I reply to every enquiry within two business days.