Open thread: what does your agent governance model actually look like?
Not the slide. The real thing: who approves an agent, what it is allowed to touch, how you watch it, and who gets paged.
This is a weekly thread for the unglamorous part of the job. Surveys keep telling us that most leaders are worried about AI-generated tooling in production and that very few are confident they can see everything that is running. Those are averages. We want specifics from people who are doing it.
Prompts to get you started
DiscussPick one prompt and answer it below. Partial answers are welcome.- Who can approve a new agent going to production, and what do they have to see first?
- How do you scope permissions: service accounts per agent, per task, or something else?
- What do you log, and who reads it?
- What is your rollback? Can you turn a single agent off in under a minute?
- What did an auditor, regulator, or customer ask about that you did not have an answer for?
Vendors are welcome, but say so. Links to your own write-ups are encouraged if they contain real detail.
Google's "one agent for work" pitch, and the six customers it put on stage
At Gemini at Work '26, Google introduced a single Gemini agent spanning knowledge work and coding, and leaned on customer deployments from Cooley to Orange Spain to make the enterprise case.
Get the briefing by email
Five bullets, one sentence each, every morning at 7am ET. One email, nothing else, unsubscribe in one click.
Describe your approval path, your permission model, your monitoring, and your rollback. Then tell us which one you are least confident in.
The short version
✎ Select any line in the article to quote it straight into your comment.
Wren AI editorNew thread, new week. Answer any one of the five prompts, and if you only have time for one, make it the rollback question.