← Back to articlesGoverned agents

Governance profiles for agents, connectors, approvals, and proof

A governance profile is a versioned policy bundle that turns an organization’s risk decision into visible run controls for context, tools, approvals, budgets, verification, and exceptions.

Three-tier governance profile matrix showing Exploration, Standard Feature Delivery, and Critical Infrastructure policies with permission budgets and gates

Profiles turn policy into a runnable contract

A policy document may say that agents require human oversight and least-privilege access. A governance profile makes that operational for a particular kind of work. It names the allowed agent and provider, context sources, skills, connectors, approval gates, action and token budgets, required proof, retention behavior, and people allowed to accept risk.

Profiles should be specific enough to govern a run and broad enough to reuse. "All software work" is usually too broad. "Draft a change from an accepted card spec in this repository, open a pull request, and require independent QA plus code-owner review" is concrete enough to evaluate.

The profile anatomy

Profile areaDecision recordedFailure it prevents
Purpose and scopeEligible work types, rooms, repositories, and environmentsUsing a safe profile for unrelated or higher-risk work
Identity and providerApproved provider, model class, agent role, and credential ownerUnknown agents or unmanaged credentials
Context policyAllowed sources, exclusions, sensitivity, and reusable-context rulesHidden or excessive context
Tools and connectorsRead and write operations, resource allow-lists, and approval levelA connector becoming an open pipe
Human gatesWho accepts specs, approves plans, handles exceptions, and accepts outcomesCeremonial approval without accountable authority
Proof profileRequired tests, reviewers, artifacts, and unresolved-limit handlingPassing a run with insufficient evidence
Budgets and stop rulesToken, cost, time, revision, and connector-call limitsRunaway execution or endless revision
Retention and auditWhat is recorded, redacted, retained, exported, and revokedAn audit trail that leaks secrets or cannot explain a decision

Version profiles without rewriting history

Every material run should record the exact profile version it used. If a manager later adds a required security scan, that change governs future runs. It should not make the historical record falsely appear as if the old run had passed the new rule. Active work that must adopt a new version should return to review, show what changed, and obtain the required approval.

Use graduated trust, not one autonomy switch

  • Observe: the agent reads approved context and offers no action.
  • Suggest: the agent drafts a spec, plan, or next action for a person to decide.
  • Prepare: the agent may assemble a change in isolation but cannot publish or merge it.
  • Execute with approval: the agent performs approved actions after a named human gate.
  • Execute within bounded policy: selected low-risk actions may run automatically, while exceptions and consequential changes return to people.

Trust should grow from evidence about a specific profile and work type, not from general confidence in a model brand. A profile that is safe for formatting documentation may be unsafe for changing infrastructure, sending customer messages, or modifying production data.

Profiles support review; they do not create compliance

Profiles can make controls and evidence easier to inspect, but they do not certify an organization against NIST, ISO, legal, contractual, or sector requirements. Enterprise buyers should map the profile to their own control owners, provider terms, data classifications, incident process, access model, and approval authority.

Key terms

Governance profile
A versioned bundle of context, tool, approval, budget, proof, and retention rules for a defined class of agent work.
Graduated trust
Increasing agent authority in bounded steps based on observed evidence and risk, rather than enabling one global autonomy setting.
Accepted risk
A disclosed proof gap or exception explicitly accepted by an authorized person and retained on the record.

Sources and standards context

  • NIST AI Risk Management Framework CoreNIST describes governance as a continuous, cross-cutting function and calls for documented human oversight, roles, testing, and accountability across the AI lifecycle.
  • ISO/IEC 42001:2023 AI management systemsISO describes an organization-wide management system for policies, objectives, processes, risk, transparency, and continual improvement in the responsible use of AI.