AI agent governance

Governance has to run where agents act.

AI agent governance is the runtime discipline of enforcing who an agent is, what it can access, which actions need approval, and what evidence survives every decision.

The authority question

Can you show what an agent was allowed to do before it acted?

If the answer lives only in a prompt, a wiki, or someone’s memory, it is not yet an operational control.

The practical distinction

Policies that guide language are not policies that govern actions.

Guidance

Prompt and output controls

Help shape what a model is asked to do and how it responds.

Governance

Runtime authority controls

Determine whether a proposed retrieval, tool call, external action, or escalation can proceed.

A model can propose an action. A governance runtime evaluates authority, applies policy, asks for approval when needed, and records the decision. That boundary matters most once agents connect to real systems.

Runtime controls

Six controls that make agent governance operational.

The exact policy will differ by system and risk. The essential work is making authority explicit, enforceable, and inspectable.

Identity and delegated authority

Give each agent, workflow, and handoff a clear principal. Authority should be explicit, scoped, and revocable—not implied by a shared API key.

Tool and action policy

Evaluate every proposed tool call against the task, actor, target system, parameters, and current policy before it executes.

Data, memory, and tenant boundaries

Keep retrieval, long-term memory, and tenant context inside the boundary intended for that agent and run.

Human approval gates

Require a human decision where the consequence warrants it—and retain the reason, approver, and resulting action.

Evidence and recovery

Record decisions, tool results, failures, and handoffs so a team can investigate, resume, or stop a run with context.

Lifecycle controls

Treat policies, integrations, prompts, models, and workflow versions as operational changes that can be reviewed and rolled back.

A decision path

Make the control point visible.

Governance should not be a post-hoc report. It should be a normal part of the execution path.

  1. 01

    Frame the task

    Associate the run with a purpose, actor, workspace, and boundary.

  2. 02

    Propose an action

    The model or workflow requests a retrieval, tool call, or handoff.

  3. 03

    Evaluate authority

    Policy checks identity, scope, data, tool, parameters, and current state.

  4. 04

    Allow, gate, or deny

    Execute only within grant; otherwise collect approval or stop safely.

Decision record
proposed_action: refunds.create
actor: support-triage-agent
task_scope: ticket-4812
requested_amount: 1240
policy: refunds-require-approval-over-500

decision: approval_required
evidence: request, policy version, approver
next_state: awaiting_human_review

The record should make an action understandable to the person who investigates it later—not only to the system that made it.

Where to start

Start with the agents that can cause the most operational change.

Customer-facing agents

External communication, refunds, account changes, and customer data create immediate consequences.

Engineering and operations agents

Code, repositories, cloud infrastructure, internal APIs, and production controls need scoped authority.

Long-running workflows

Durable agents need visible state, recoverable handoffs, cost boundaries, and interruption points.

Questions teams ask

AI agent governance FAQ

What is AI agent governance?+

AI agent governance is the set of technical and operating controls that define and enforce what an agent may access, decide, and do. For production agents, it must operate at runtime—when a tool call, retrieval, approval, or escalation occurs.

How is AI agent governance different from model guardrails?+

Guardrails can guide model behavior and filter inputs or outputs. They do not, by themselves, create a durable enforcement boundary around credentials, data scope, tool calls, approvals, or run evidence. Agent governance covers that operational authority.

Do AI agents need separate identities?+

Yes, when they operate across real systems. A separate or delegated identity makes it possible to scope permissions, attribute activity, revoke access, and distinguish the agent’s authority from a human operator’s broader permissions.

What should require human approval?+

Use approval gates where an action has material impact, irreversible effects, elevated privileges, financial consequences, external communication, or a meaningful uncertainty that cannot be resolved by policy alone.

Is governance only for regulated industries?+

No. Any team that gives agents access to production tools, customer information, code, communications, or financial systems needs a way to make authority visible and enforceable. Regulatory obligations add requirements; they are not the only reason to build controls.

Next step

Find the gaps between your policy and your agent’s real authority.

Use Tandem’s free AI Governance & Agent Security Readiness Assessment to review 32 controls across eight governance domains.

Get the free assessment