Layer 05/08
Access & Governance
Control who can see, use, build, and change every agent — down to the action.
The problem
As agent fleets grow, the real risk is not a single bad model but the absence of control: no one knows which agents exist, who owns them, what they can touch, or who changed them.
agent inventory
Agent
Owner
access
last changed
agent-prod-07
customer-bot-v2
internal-tool-3
unnamed-agent-1
4 of 4 agents shown
0 with a known ownerWhat it does
Role-based and attribute-based access control over agents, workflows, tools, data, and models.
A central registry of every agent — owner, purpose, data access, and status.
Policy engine for what agents may do: which tools, which data, which regions, which spend limits.
SSO, SCIM, and approval workflows for promoting agents to production.
How it connects
Governance policies are enforced by the AI Firewall at runtime, surfaced in Deep Observability, and every access decision is written to Audit & Compliance.