You are accountable for
- One front door: catalog, gateway, guardrails inherited by default
- Making the governed path measurably faster than the shadow path
- Fleet operations for models and agents: versions, budgets, kill switches
What keeps you up at night
- Teams bypassing the platform with raw API keys
- A model retirement forcing a fleet migration nobody planned
- Agent sprawl: hundreds of agents, no registry, no owners
Decisions you own
- Operate the model catalog and allowlist as a product
- Enforce guardrail attachment platform-side so bypass is impossible, not discouraged
- Stand up the agent registry, identity, and gateway before the fleet grows
Your layers of the stack
3Model GovernanceWhich models do we trust — and how do we know?5Agent GovernanceWhat may AI do on its own — and who can stop it?6Runtime Security & ObservabilityWhat is happening right now — and would we notice?4Application GovernanceDoes the system behave — and can we prove it?
Where to go first
Questions you should be asking
- What percentage of AI traffic flows through the governed gateway?
- Which controls are defaults versus opt-in — and why?
- What is our model-migration runbook for the next retirement?