Guide

How to Govern AI Agents Across Platforms: Microsoft, Salesforce, AWS, Google and More

How to Govern AI Agents Across Platforms: Microsoft, Salesforce, AWS, Google and More

Updated October 6, 2026. Part 1 of APERION's Agent Platforms series.

Enterprises govern AI agents across platforms by applying the same four controls everywhere: an inventory of every agent, an identity for each agent tied to an accountable person, policy enforced on the model calls and tool calls the agent makes, and one audit record in one format. Microsoft, Salesforce, Amazon, Google, ServiceNow, Glean and CrewAI each ship their own version of those controls, written for agents on their own platform. An enterprise running agents on five platforms inherits five policy languages and five audit formats. The governance work is deciding, platform by platform, where a common control point can sit: at the model endpoint, on the tool path, or after the fact in trace data.

The number of agents is growing faster than the controls around them. Gartner predicts that 40% of enterprise applications will include task-specific AI agents by the end of 2026, up from less than 5% in 2025 (Gartner, August 2025). KPMG's third-quarter 2026 survey of U.S. companies with $1 billion or more in revenue found 62% building, deploying or developing agents (KPMG, September 2026). Microsoft reported nearly 40 million agents registered in Agent 365 within two months of its general availability (Microsoft earnings call, July 2026). Gartner also predicts that more than 40% of agentic AI projects will be canceled by the end of 2027, and names inadequate risk controls among the causes (Gartner, June 2025).

The Platforms Your Agents Already Run On

Most large enterprises run agents on several of these platforms at once: the productivity suite, the CRM, the cloud provider, the enterprise search tool, and frameworks the engineering teams chose themselves.

PlatformWhere agents are builtNative governance, October 2026
MicrosoftMicrosoft 365 Copilot, Copilot Studio, Microsoft FoundryAgent 365, Entra Agent ID, Purview, Defender
SalesforceAgentforceEinstein Trust Layer, Agentforce Gateway, MuleSoft Agent Fabric, Agentforce Observability
AmazonBedrock AgentCore, Strands Agents, Amazon Quick SuiteAgentCore Identity, Gateway and Policy, Bedrock Guardrails, AgentCore Observability
GoogleGemini Enterprise, Gemini Enterprise Agent Platform, Agent Development KitAgent Identity, Agent Gateway, Model Armor, Agent Registry
ServiceNowAI Agents, AI Agent StudioAI Control Tower
GleanGlean Agents, Agent BuilderPermission-aware retrieval, agent roles and publish approval, Protect+
CrewAIOpen-source framework, CrewAI AMPTask guardrails, execution hooks, AMP role-based access and Agent Control Plane
OpenAI and AnthropicAgents SDK and Agents API; Claude Agent SDK and Claude Managed AgentsGuardrails library and Compliance Logs; managed settings and the Compliance API

Each of the large platforms now offers to register agents built somewhere else. Agent 365 shipped with registry sync for Amazon Bedrock and Google Cloud in preview (Microsoft, May 2026). ServiceNow announced AI Control Tower discovery across AWS, Google Cloud, Azure, SAP, Oracle and Workday (ServiceNow, May 2026). Workday's Agent System of Record registers Workday, customer and partner agents (Workday, February 2026). Each registry sees what its connectors reach, and each enforces policy where its own traffic flows. The enterprise still needs one record that reads the same whichever platform the agent ran on.

Four Controls Every Platform Needs

The same four controls apply on every platform. What changes is where each one lives.

  1. Inventory. Every agent, the platform it runs on, the model it calls, the tools it can reach, and the person who sponsors it. Gartner lists a central inventory among its six steps for managing agent sprawl (Gartner, April 2026).
  2. Identity tied to a person. Each agent gets its own credential, and each action records the person the agent acted for. Microsoft's Entra Agent ID records the user as the subject and the agent as the actor when an agent acts on a user's behalf (Microsoft Learn). A shared API key records neither.
  3. Policy on model calls and tool calls. An agent fails in two places: what it sends to and receives from the model, and what it does with tools. EchoLeak in Microsoft 365 Copilot (CVE-2025-32711), ForcedLeak in Agentforce and GeminiJack in Gemini Enterprise, all disclosed in 2025, each combined untrusted content the agent read with a path that sent data out.
  4. One audit record. Agent, person, platform, model, tool, decision and time, in one schema, kept as long as your longest obligation. Platform defaults differ. Microsoft keeps Copilot Studio and Foundry agent audit records for 180 days under Audit Standard (Microsoft Learn). Bedrock model invocation logging is off until you turn it on (AWS documentation).

For the protocol side of agent security, see our guide to MCP, A2A and the agent attack surface.

Where the Control Points Are on Each Platform

A common control can sit in three places. At the model endpoint, where a platform lets you set the model's base URL, a gateway sees and can enforce policy on every model call. On the tool path, where a platform calls remote MCP servers, a gateway in front of those servers sees every tool call. After the fact, where a platform exports OpenTelemetry traces, you get evidence for the record, without the ability to stop a call in flight.

PlatformModel callsTool callsTrace export
CrewAIConfigurable base URL on LLM()MCP servers you name, by URLAMP exports to your OpenTelemetry collector
Amazon Bedrock AgentCoreYour agent code chooses the endpoint, including AgentCore Gateway inference targetsMCP servers as AgentCore Gateway targetsOpenTelemetry through CloudWatch
Google Agent Development KitCustom endpoint through LiteLlm(api_base=...)Agent Gateway governs MCP and A2A trafficOpenTelemetry to Cloud Trace
OpenAI and Anthropic SDKsCustom client; ANTHROPIC_BASE_URLMCP servers you configureCustom trace processors; Claude Code OpenTelemetry
Salesforce AgentforceYour own models through the LLM Open Connector; the reasoning engine's model is Salesforce-managedExternal MCP servers you registerSession tracing on an OpenTelemetry-based data model
GleanGlean-managed key, or your own key with OpenAI, Azure OpenAI, Anthropic, Vertex AI or Amazon BedrockRemote MCP servers you connect (beta in agents)OTLP export of agent runs, tool calls and model calls
Microsoft 365 Copilot and Copilot StudioMicrosoft-managed; no documented customer proxyMCP servers through connectors, under Power Platform data policiesPurview audit; Foundry tracing on OpenTelemetry

The pattern is consistent. Frameworks your teams run in their own code give you the model endpoint and the tool path. Software-as-a-service agents give you the tool path and a trace export, and keep the model call inside the vendor's boundary. The platform guides in this series cover each row in detail.

How to Govern AI Agents Across Platforms in 7 Steps

1. Build one inventory from every registry

Export agents from each platform's own registry or admin console: Agent 365, AgentCore, Agentforce, Glean's agent analytics, CrewAI AMP. Reconcile them by owner and by credential. Count the agents your engineers run outside any platform, on frameworks and open-source runtimes, because they appear in no registry until someone looks.

2. Give every agent its own identity and a human sponsor

Retire shared keys. Issue one credential per agent, name a sponsor who answers for it, and when the agent acts for a user, record both. Microsoft states that Conditional Access does not apply when an agent authenticates with an API key, because the key bypasses Entra token issuance (Microsoft Learn). The same gap exists on any platform where a static key stands in for an identity.

3. Classify actions by consequence

Sort what agents can do into reads, internal writes, external sends, and actions that move money or change access. Decide which classes an agent may take on its own and which need a person. KPMG found 49% of large U.S. companies have defined high-risk use cases where autonomous AI decisions are prohibited (KPMG, September 2026).

4. Put a control point on every path you can reach

Where the platform exposes the model endpoint, route model calls through a gateway that enforces policy and writes the record. Where it calls MCP servers, put the gateway in front of them. Where it exposes neither, configure the native controls and collect the trace export.

5. Send out-of-authority actions to a person

When an agent attempts an action outside its authority, the call pauses and a named person decides. Platforms offer pieces of this: Glean pauses write tools for user confirmation in its web app, and CrewAI supports human input on tasks and feedback steps in Flows. Decide who approves each class of action, and record the approval with the action.

6. Normalize the audit record

Map each platform's logs into one schema, and set retention to the longest obligation that applies. Check defaults platform by platform: Glean's admin audit log records configuration changes and leaves out end-user activity (Glean documentation).

7. Re-check the platforms every quarter

Agent products change monthly. OpenAI deprecated its Agent Builder in June 2026 and set its shutdown for November 30, 2026 (OpenAI). Re-verify names, defaults and preview status each quarter, and date every claim in your control documentation.

Standards That Make Cross-Platform Governance Possible

  • Model Context Protocol. Governed by the Agentic AI Foundation at the Linux Foundation since December 2025 (Linux Foundation). The 2026-07-28 specification documents conventions for carrying OpenTelemetry trace context in request metadata (MCP changelog). Open standard.
  • Agent2Agent (A2A). Version 1.0 added signed agent cards, and A2A joined the Agentic AI Foundation in August 2026 (AAIF). Open standard.
  • OWASP Top 10 for Agentic Applications. Released December 2025; covers ten risks specific to autonomous agents (OWASP). Industry guidance.
  • NIST NCCoE agent identity project. A February 2026 concept paper on identity and authorization for software and AI agents (NIST). Guidance in development.
  • EU AI Act. High-risk obligations for Annex III systems apply from December 2, 2027, as amended in 2026 (European Commission). Enforceable regulation.

Details as published by each organization, verified October 6, 2026.

Operating Limits

  • A registry records agents. Enforcement happens where calls flow.
  • A static key identifies a secret. Only a per-agent credential tied to a sponsor identifies who acted.
  • Trace export is evidence after the fact. It cannot stop a call in flight.
  • Native controls end at the platform boundary. Each platform enforces policy on its own traffic.
  • Defaults change. Check them at every release.

How APERION Fits

APERION's Smartflow sits in the request path between agents and the models and MCP servers they call, on any platform that exposes those paths. It accepts the OIDC token your identity provider already issues, gives each agent its own key with model and route allowlists, applies tool rules to MCP calls, and sends an out-of-authority call to a person with approval rights. Every request and denial lands in one hash-chained audit record. Talk to APERION.

More in This Series

Frequently Asked Questions

What is an AI agent platform?

An AI agent platform is software for building, running and managing agents that call models and take actions through tools. Examples include Microsoft Copilot Studio, Salesforce Agentforce, Amazon Bedrock AgentCore, Google Gemini Enterprise, Glean and CrewAI. Most also ship their own identity, policy and logging controls.

How do you govern AI agents across multiple platforms?

Apply four controls on every platform: an inventory, a per-agent identity tied to a sponsor, policy on model calls and tool calls, and one audit record. Place a common control point at the model endpoint or on the tool path wherever the platform exposes it, and collect trace exports where it does not.

What is AI agent sprawl?

Agent sprawl is the growth of agents across teams and platforms faster than the organization can inventory, own and govern them. Its signs are agents with no named owner, shared credentials, and actions that no audit record ties to a person.

If my platform has its own governance features, do I need anything else?

If all of your agents run on one platform, its native controls may be enough. Once agents run on several platforms, each platform enforces its own policy on its own traffic, and you need a common inventory, a common identity model and one audit record across them.

Can a gateway govern Microsoft 365 Copilot?

Microsoft documents no way to route Microsoft 365 Copilot's model calls through a customer proxy, and states that Copilot integrations can fail when TLS inspection interferes with the connection. Govern it with Microsoft's own controls: Purview, Agent 365, Entra Agent ID and the tool controls in the Microsoft 365 admin center.

What is the difference between an agent registry and runtime enforcement?

A registry lists agents, owners and permissions. Runtime enforcement evaluates each model call or tool call as it happens and allows it, blocks it, or pauses it for a person. Governance needs both.

Which standards apply to AI agent governance?

The Model Context Protocol and A2A for how agents call tools and each other, OpenTelemetry for traces, the OWASP Top 10 for Agentic Applications for risks, the NIST NCCoE agent identity work for identity, and the EU AI Act where it applies.


Craig Alberino is the CEO and Founder of APERION, which provides Smartflow, the runtime governance layer for enterprise AI in regulated industries. Learn more about Smartflow →

Craig Alberino
Craig Alberino
Craig Alberino is the Founder and CEO of APERION, which builds the runtime governance layer for AI agents in regulated enterprises. Inline policy enforcement and identity-bound audit, deployable on premises.

Put this in the path of your own agents.

Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.

Request a Demo Read the docs