Skip to content

The practice, explained

What is enterprise agent governance?

Enterprise agent governance is the set of policies, controls and records an enterprise uses to decide what its AI agents may do, and to show afterwards what they did. It covers every agent, whichever vendor made it. Each platform's own controls govern the agents on that platform. The enterprise keeps its own rule for what any agent may change.

AI Acts. Crelis Decides. · Runtime authorization for AI agents

The blue clay Crelis robot stands behind one desk while four cream clay agents, each in a different coloured cap, queue to hand over a glowing card.
Scope
Every agent, from every vendor
Owner
The enterprise
Outcomes
Allow, require human approval, escalate, or block
Record
Tamper-evident evidence

Why it exists

As agents multiply, authority can spread out

A pilot often starts with one agent on one platform. That platform's own controls govern it, and that is appropriate.

Then more agents arrive. Some are built in-house, some are bought, and some are switched on inside software the enterprise already owns. Each comes with its own controls, configured platform by platform, so one business rule can end up written in several places.

Every one of those controls can be working correctly. The open question is where the enterprise keeps its own rule for what any agent may change, so that it reads the same for all of them.

Every platform governs its own agents; the enterprise decides what any of them may change.

How it differs

Each area answers its own question

Each of these is useful, and they work together. Enterprise agent governance relies on all of them and adds the enterprise's own question.

Platform-native controls

What may the agents on this platform do?

On each platform

Identity and access

Who is this agent, and what can it reach?

Wherever access is granted

Agent security

Is this agent, or this interaction, safe?

Wherever an agent runs

Orchestration

What does the agent want to do next?

Wherever work is planned

Enterprise agent governance

What may any of our agents change?

Across every agent and vendor

Platforms govern their agents. The enterprise governs what may change.

One decision point

One rule, one decision, one record

An enterprise-wide decision point is one place where the enterprise's own rule is applied to each consequential action, whichever agent attempts it. Everyday read-only work is untouched.

  1. One rule

    The enterprise states its rule once. It reads the same for every agent.

  2. One decision

    Each consequential action gets one answer: allow, require human approval, escalate, or block.

  3. One record

    What each agent attempted, and what was decided, kept as evidence.

What regulators point to

Controls at the moment an agent acts

We publish an independent, primary-sourced reference mapping SAFR, NIST AI RMF and EU AI Act requirements to controls at AI-agent execution time. It cites the source documents and implies no endorsement.

If you are evaluating

Questions to ask about your own agents

Questions for your own teams, and for any vendor you speak to.

  1. 01How many AI agents do we run, and who made each one?
  2. 02Which of their actions change something that matters?
  3. 03Where is our own rule for those actions written down?
  4. 04How many copies of the same rule exist across our agent platforms?
  5. 05For one past action, can we show which rule applied and who approved it?
  6. 06Which team owns the rule that applies to every agent?

FAQ

Enterprise agent governance, in short answers

The questions people ask about governing AI agents across an enterprise.

What is enterprise agent governance?

Enterprise agent governance is the set of policies, controls and records an enterprise uses to decide what its AI agents may do, and to show afterwards what they did. It covers every agent, whichever vendor made it. Each platform's own controls govern the agents on that platform. The enterprise keeps its own rule for what any agent may change.

How do you govern AI agents?

List the agents you run and the systems they can change. Decide which of their actions are consequential. Set the rule for those actions in one place, and keep a record of each decision. Platform-native controls stay in place and work alongside.

How do you govern AI agents from multiple vendors?

Keep the enterprise's own rule in one place and apply it to every agent. Each vendor's platform governs its own agents. The enterprise decides what any agent may change in its consequential systems, and that decision is the same whichever vendor made the agent.

Who governs AI agents when they come from different vendors?

The enterprise does. Each platform governs the agents that run on it. The rule that spans all of them is the enterprise's own, and it often involves the security, risk, identity, compliance and audit teams. Their shared question is which control decides what any agent may change.

What happens to AI agent governance as a company adds more agents?

The enterprise's own rules can end up written in several places. Agents arrive from many vendors, and each platform's controls are configured on that platform. Those controls are appropriate and stay in place. As more agents are added, keeping policy and evidence consistent across them can become harder.

Is enterprise agent governance the same as runtime authorization?

No. Enterprise agent governance is the wider practice: the policies, controls and records that cover every agent an enterprise runs. Runtime authorization is one control within that practice. The runtime authorization page explains that term.

Where does Crelis sit when a company runs many AI agents?

Crelis is deliberately independent: one place that decides authority across the AI ecosystems a company uses. Each consequential action you route through Crelis passes through one authoritative, deterministic evaluation before it can execute. Crelis sits beside your systems, not inside your model. Tested so far with the agents and SDKs running in our hosted pilot environment; no vendor is certified or endorsed.

Give your agents a green light — safely.

Start in shadow mode on non-production traffic. See every decision GREENLIGHT would have made — before you let it make one.