Governance
Agent governance assigns ownership and policy across instructions, models, tools, data, evaluation, permissions, releases, incidents, and vendors. It should make authority and evidence visible without turning every low-risk improvement into a centralized bottleneck.
Questions to answer
Resolve these before adding tools, frameworks, or automation.
- Who owns behavior, data, tools, releases, incidents, and user recourse?
- Which evidence is required before a capability or change can ship?
- How are exceptions, expiry, audits, and policy updates managed?
Implementation lifecycle
Build the evidence in this order
- 01
Classify
Tier systems by data sensitivity, autonomy, reach, reversibility, and consequence.
- 02
Control
Assign owners, evidence gates, access rules, review cadence, and exception paths.
- 03
Audit
Review changes, incidents, stale permissions, vendors, and unresolved exceptions.
Artifacts to maintain
- ownership matrix
- policy set
- change record
- exception register
Continue through AgentAtlas
Evidence ledger
Primary documentation behind this guide
AGENTS.md
AGENTS.md specification
Versioned repository instructions that make build, test, style, and contribution requirements available to agents.
GitHub
GitHub Spec Kit
Governed specification-driven workflows, quality checks, organizational principles, and traceability across delivery artifacts.
OpenAI
Codex security
Operational authority boundaries enforced through sandboxing, permissions, approvals, and network controls.
Next topic
Agent commerce