Governing AI agents: the agent, not only the model.

An agent acts under delegated authority: it calls tools, keeps memory and hands work to other agents. This page is the way in: the control plane that bounds an agent, the patterns that build it and the threats it has to hold against, each linked to its section of chapter 23.

Four properties make an agent a different object.

OWASP’s agentic list names the first principle least agency: avoid autonomy the task does not need. The cheapest agent control is the agent you did not build.

Autonomy levels and minimum controls in chapter 23

The agent control plane, component by component.

Ten components sit around every agent in production. Each one leaves evidence, and each links to its section in chapter 23.

The agent control plane One tool call through the agent control plane: registry, identity, gateway, guardrail, checkpoint and breaker, with telemetry kept as evidence. One tool call through the control plane Agent registry owner, scope, expiry no entry, no credential Identity issuer short-lived credential Agent proposes a tool call Tool gateway deny by default Runtime guardrail policy check, every call fails closed for pay, delete, send, execute Human checkpoint where stakes demand it Circuit breaker per agent stop levels task scope breaker identity class degrade stops trips Tool, MCP server or remote agent your boundary: revoke what you issued Telemetry and evidence identity, tool calls, verdicts, approvals Layer 02 Inventory & Transparency Layer 04 Runtime Controls & Observability Layer 05 Assurance & Continuous Compliance
The agent control plane One tool call through the agent control plane: a registry entry gates the credential, the gateway and the guardrail check the call, a checkpoint fires where the stakes demand it and a per-agent breaker can stop it, while every step leaves telemetry kept as evidence. Check that each agent in your registry has all of them and that its stop has been drilled. Illustrative, not a claim of conformity. Drawn from chapter 23. Permalink, downloads and citation
Text description

The control plane in the order a tool call meets it. The agent registry (Layer 02 Inventory & Transparency) holds every agent with an owner, a purpose, an autonomy level, its tools, pinned versions, stop handles and an expiry: no registry entry, no credential. The identity issuer (Layer 04 Runtime Controls & Observability) gives the agent a short-lived, attested workload credential, with delegation that names the agent, never impersonation of the user. The agent proposes a tool call. The tool gateway denies by default, with pinned tool definitions, scopes, rates and egress per tool, and admitted MCP servers only. The runtime guardrail checks every call before it runs (identity against a live registry entry, the allow-list and definition hash, parameters within policy, instruction provenance, the output and egress filter, execution budgets) and fails closed for pay, delete, send and execute, open with an alert only for reads. A human checkpoint approves where the stakes or irreversibility demand it, showing the raw call. The per-agent circuit breaker has six stop levels: pause a task, narrow the scope, trip the breaker, revoke the identity, stop a class and degrade; exhausted budgets trip it, and a tripped breaker makes the gateway reject every call from the agent. Past your boundary sit the tool, the MCP server or a remote agent: you cannot stop someone else's agent, only stop calling it and revoke what you issued to it. Every step leaves telemetry that carries identity, tool calls, verdicts and approvals, kept as evidence (Layer 05 Assurance & Continuous Compliance). Memory controls, delegation across hops and prompt change control complete the plane in chapter 23.

Chapter 23 sets out 31 agent controls across these components. The agent control profile tool picks the ones one agent needs; the agent runtime control profile states each as a draft reference control with the evidence it must leave, open for technical review.

Write down one agent’s control profile in the toolkit

Ten agentic threats, and the control for each.

The OWASP Top 10 for Agentic Applications 2026, each threat mapped to the control that contains it and the pattern that implements the control.

OWASP agentic threats ASI01 to ASI10 with the control and the pattern for each
Threat Control Pattern
ASI01 Agent Goal Hijack Instruction provenance; checkpoints before writes; trajectory evals Runtime Guardrail
ASI02 Tool Misuse and Exploitation Tool allow-list; per-tool rate, egress and budgets Runtime Guardrail
ASI03 Identity and Privilege Abuse Workload identity; short-lived delegated tokens; audience checks Agent Identity & Scoped Credentials
ASI04 Agentic Supply Chain Vulnerabilities MCP server admission; pinned tool definitions AIBOM
ASI05 Unexpected Code Execution (RCE) Sandboxed execution; deny by default Runtime Guardrail
ASI06 Memory & Context Poisoning Memory write gate; isolation; rollback Runtime Guardrail
ASI07 Insecure Inter-Agent Communication Mutual authentication; signed Agent Cards; peer allow-list Agent Identity & Scoped Credentials
ASI08 Cascading Failures Depth and fan-out limits; per-agent breakers Kill Switch / Circuit Breaker
ASI09 Human-Agent Trust Exploitation Approvals that show the raw call; oversight metrics Human-in-the-loop Gate
ASI10 Rogue Agents Registry with expiry; discovery; drilled kill switch Agent Registry

The full threat-to-control table

Tool categories for the control plane.

The categories that fill the runtime layer for agents, with the examples the Body of Knowledge names. The category is the substance; the brands are illustrative, not an endorsement.

Tool categories for agent governance, with illustrative examples and their stack layer
Category Examples (illustrative) Layer
Agent-discovery tools Zenity L2
Guardrail frameworks NVIDIA NeMo Guardrails · Meta LlamaFirewall · Lakera · Guardrails AI · Llama Guard L4
Observability Langfuse · Arize Phoenix · OpenTelemetry (GenAI semantic conventions) L4
MCP / tool-call security MCP Inspector · Snyk Agent Scan · mcp-context-protector L4
Kill switch / circuit breaker Unleash · Envoy · Resilience4j L4
Agent workload identity SPIFFE/SPIRE · Microsoft Entra Agent ID · Okta Agent SSO L4

Every tool category, by layer

Read the whole chapter.

Chapter 23 sets out autonomy levels, identity and MCP authorisation, checkpoints, memory, delegation chains and the EU AI Act hooks, with every source.