Guides

Enterprise AI Governance Guides

Long-form reference on enterprise AI governance: gateways, control planes, firewalls and the architecture underneath them. See the glossary and documentation.

In-depth technical and strategic guides for CISOs, CTOs, and enterprise architects evaluating AI governance infrastructure.

📚

Governing Google, ServiceNow, OpenAI, Anthropic and LangChain Agents

Hosted agent platforms keep model calls inside the vendor. Developer SDKs run in your code. How to govern both kinds across Google, ServiceNow, OpenAI, Anthropic and LangChain.

Craig Alberino · 7 min read min read
📚

Microsoft Copilot Agent Governance: Copilot Studio, Foundry and Agent 365

Agent 365, Entra Agent ID, Purview and Defender each cover part of governing Microsoft agents. How they fit together, and the gaps to close, in seven steps.

Craig Alberino · 6 min read min read
📚

Amazon Bedrock AgentCore Governance: How to Govern AI Agents on AWS

AgentCore Policy evaluates the calls that pass through AgentCore Gateway. How to route the calls that matter through it and govern AI agents on AWS in seven steps.

Craig Alberino · 6 min read min read
📚

Agentforce Governance: How to Secure Salesforce AI Agents

LLM data masking is disabled for Agentforce agents, so what an agent can reach decides what it can expose. How to govern Agentforce in seven steps.

Craig Alberino · 6 min read min read
📚

Glean Agents Governance: Permissions, Tools and Audit

Glean agents read what each user can read and act in connected apps. How to govern them in seven steps, from source permissions to one audit record.

Craig Alberino · 6 min read min read
📚

How to Govern AI Agents Across Platforms: Microsoft, Salesforce, AWS, Google and More

Every agent platform ships its own controls. How to apply one inventory, one identity model, one policy and one audit record across all of them, with a map of the control points on each platform.

Craig Alberino · 8 min read min read
📚

CrewAI Security and Governance: How to Run Crews in Production

CrewAI's guardrails and hooks check an agent's work inside the run. How to put the controls that must survive a code change outside it, in seven steps.

Craig Alberino · 6 min read min read
📚

FINRA Rule 3110 and AI Agents: A Supervision Guide

Model risk guidance stepped back from agentic AI. FINRA did not. What Rule 3110 requires of a broker-dealer deploying AI agents, and what the supervisory record has to contain.

Craig Alberino · 4 min read min read
📚

Model Coverage, Routing, and Failover in Smartflow: What Enterprise AI Gateway Support Actually Means

How Smartflow supports any LLM endpoint through registry-based architecture, and how client-defined routing, failover, and task routing work. Model support is an architecture question, not an integration count.

Craig Alberino · 5 min read min read
📚

Governed AI for Multinational Hotel Operations: China, Saudi Arabia, and the EU

How international hotel groups deploy AI agents across mainland China, Saudi Arabia, and the EU without moving guest data across borders. Global policy, local enforcement, portable evidence.

Craig Alberino · 5 min read min read
📚

AI Agent Governance: MCP, A2A, and the New Attack Surface

AI agents are connecting to enterprise systems, executing transactions, and communicating with other agents. Each tool invocation is a data flow and a permission decision.

Craig Alberino · 2 min read min read
📚

EU AI Act Compliance: What U.S. Enterprises Need to Know in 2026

The amended high-risk timeline, who is in scope, and which obligations cannot be discharged by a document.

Craig Alberino · 2 min read min read