AI Agents
An agent is a caller that decides for itself what to call next. That changes the governance question from what a user asked to what authority the agent holds, what it can reach with it, and what record survives the session. These posts follow that shift as enterprises hit it. See agent governance, agentic governance in Smartflow, and the A2A protocol.
Governing Google, ServiceNow, OpenAI, Anthropic and LangChain Agents
Hosted agent platforms keep model calls inside the vendor. Developer SDKs run in your code. How to govern both kinds across Google, ServiceNow, OpenAI, Anthropic and LangChain.
Microsoft Copilot Agent Governance: Copilot Studio, Foundry and Agent 365
Agent 365, Entra Agent ID, Purview and Defender each cover part of governing Microsoft agents. How they fit together, and the gaps to close, in seven steps.
Amazon Bedrock AgentCore Governance: How to Govern AI Agents on AWS
AgentCore Policy evaluates the calls that pass through AgentCore Gateway. How to route the calls that matter through it and govern AI agents on AWS in seven steps.
Agentforce Governance: How to Secure Salesforce AI Agents
LLM data masking is disabled for Agentforce agents, so what an agent can reach decides what it can expose. How to govern Agentforce in seven steps.
Glean Agents Governance: Permissions, Tools and Audit
Glean agents read what each user can read and act in connected apps. How to govern them in seven steps, from source permissions to one audit record.
How to Govern AI Agents Across Platforms: Microsoft, Salesforce, AWS, Google and More
Every agent platform ships its own controls. How to apply one inventory, one identity model, one policy and one audit record across all of them, with a map of the control points on each platform.
CrewAI Security and Governance: How to Run Crews in Production
CrewAI's guardrails and hooks check an agent's work inside the run. How to put the controls that must survive a code change outside it, in seven steps.
The missing verb
Agents act on a person's authority at machine speed. When one goes past what the person authorized, where does the action go?
OpenAI, Hugging Face, and the Deployment Flag
The attacking models ran with cyber refusals reduced for an eval. The responders ran with guardrails at full strength and got refused. The variable that decided who got capability was a deployment flag. OpenAI's fix concedes the missing layer and raises the harder question of who should own it.
Governed AI for Multinational Hotel Operations: China, Saudi Arabia, and the EU
How international hotel groups deploy AI agents across mainland China, Saudi Arabia, and the EU without moving guest data across borders. Global policy, local enforcement, portable evidence.
The WOPR Brief: your monitoring stack is now an attack surface
Loops Moved the Work Up a Level. The Risk Moved Down One.
The field moved from prompting agents to designing the loops that run them. The developer conversation has the right cautions. Inside a regulated enterprise, the loop's connectors reach actions that do not reverse, and what the agent sends to the model is a disclosure on its own.