Profiles turn policy into a runnable contract
A policy document may say that agents require human oversight and least-privilege access. A governance profile makes that operational for a particular kind of work. It names the allowed agent and provider, context sources, skills, connectors, approval gates, action and token budgets, required proof, retention behavior, and people allowed to accept risk.
Profiles should be specific enough to govern a run and broad enough to reuse. "All software work" is usually too broad. "Draft a change from an accepted card spec in this repository, open a pull request, and require independent QA plus code-owner review" is concrete enough to evaluate.
The profile anatomy
| Profile area | Decision recorded | Failure it prevents |
|---|---|---|
| Purpose and scope | Eligible work types, rooms, repositories, and environments | Using a safe profile for unrelated or higher-risk work |
| Identity and provider | Approved provider, model class, agent role, and credential owner | Unknown agents or unmanaged credentials |
| Context policy | Allowed sources, exclusions, sensitivity, and reusable-context rules | Hidden or excessive context |
| Tools and connectors | Read and write operations, resource allow-lists, and approval level | A connector becoming an open pipe |
| Human gates | Who accepts specs, approves plans, handles exceptions, and accepts outcomes | Ceremonial approval without accountable authority |
| Proof profile | Required tests, reviewers, artifacts, and unresolved-limit handling | Passing a run with insufficient evidence |
| Budgets and stop rules | Token, cost, time, revision, and connector-call limits | Runaway execution or endless revision |
| Retention and audit | What is recorded, redacted, retained, exported, and revoked | An audit trail that leaks secrets or cannot explain a decision |
Version profiles without rewriting history
Every material run should record the exact profile version it used. If a manager later adds a required security scan, that change governs future runs. It should not make the historical record falsely appear as if the old run had passed the new rule. Active work that must adopt a new version should return to review, show what changed, and obtain the required approval.
Use graduated trust, not one autonomy switch
- Observe: the agent reads approved context and offers no action.
- Suggest: the agent drafts a spec, plan, or next action for a person to decide.
- Prepare: the agent may assemble a change in isolation but cannot publish or merge it.
- Execute with approval: the agent performs approved actions after a named human gate.
- Execute within bounded policy: selected low-risk actions may run automatically, while exceptions and consequential changes return to people.
Trust should grow from evidence about a specific profile and work type, not from general confidence in a model brand. A profile that is safe for formatting documentation may be unsafe for changing infrastructure, sending customer messages, or modifying production data.
Profiles support review; they do not create compliance
Profiles can make controls and evidence easier to inspect, but they do not certify an organization against NIST, ISO, legal, contractual, or sector requirements. Enterprise buyers should map the profile to their own control owners, provider terms, data classifications, incident process, access model, and approval authority.
Key terms
- Governance profile
- A versioned bundle of context, tool, approval, budget, proof, and retention rules for a defined class of agent work.
- Graduated trust
- Increasing agent authority in bounded steps based on observed evidence and risk, rather than enabling one global autonomy setting.
- Accepted risk
- A disclosed proof gap or exception explicitly accepted by an authorized person and retained on the record.
Sources and standards context
- NIST AI Risk Management Framework CoreNIST describes governance as a continuous, cross-cutting function and calls for documented human oversight, roles, testing, and accountability across the AI lifecycle.
- ISO/IEC 42001:2023 AI management systemsISO describes an organization-wide management system for policies, objectives, processes, risk, transparency, and continual improvement in the responsible use of AI.
