The agent control plane

One tool call through the agent control plane: registry, identity, gateway, guardrail, checkpoint and breaker, with telemetry kept as evidence.

The agent control plane One tool call through the agent control plane: registry, identity, gateway, guardrail, checkpoint and breaker, with telemetry kept as evidence. One tool call through the control plane Agent registry owner, scope, expiry no entry, no credential Identity issuer short-lived credential Agent proposes a tool call Tool gateway deny by default Runtime guardrail policy check, every call fails closed for pay, delete, send, execute Human checkpoint where stakes demand it Circuit breaker per agent stop levels task scope breaker identity class degrade stops trips Tool, MCP server or remote agent your boundary: revoke what you issued Telemetry and evidence identity, tool calls, verdicts, approvals Layer 02 Inventory & Transparency Layer 04 Runtime Controls & Observability Layer 05 Assurance & Continuous Compliance
The agent control plane One tool call through the agent control plane: a registry entry gates the credential, the gateway and the guardrail check the call, a checkpoint fires where the stakes demand it and a per-agent breaker can stop it, while every step leaves telemetry kept as evidence. Check that each agent in your registry has all of them and that its stop has been drilled. Illustrative, not a claim of conformity. Drawn from chapter 23.

Text alternative

The control plane in the order a tool call meets it. The agent registry (Layer 02 Inventory & Transparency) holds every agent with an owner, a purpose, an autonomy level, its tools, pinned versions, stop handles and an expiry: no registry entry, no credential. The identity issuer (Layer 04 Runtime Controls & Observability) gives the agent a short-lived, attested workload credential, with delegation that names the agent, never impersonation of the user. The agent proposes a tool call. The tool gateway denies by default, with pinned tool definitions, scopes, rates and egress per tool, and admitted MCP servers only. The runtime guardrail checks every call before it runs (identity against a live registry entry, the allow-list and definition hash, parameters within policy, instruction provenance, the output and egress filter, execution budgets) and fails closed for pay, delete, send and execute, open with an alert only for reads. A human checkpoint approves where the stakes or irreversibility demand it, showing the raw call. The per-agent circuit breaker has six stop levels: pause a task, narrow the scope, trip the breaker, revoke the identity, stop a class and degrade; exhausted budgets trip it, and a tripped breaker makes the gateway reject every call from the agent. Past your boundary sit the tool, the MCP server or a remote agent: you cannot stop someone else's agent, only stop calling it and revoke what you issued to it. Every step leaves telemetry that carries identity, tool calls, verdicts and approvals, kept as evidence (Layer 05 Assurance & Continuous Compliance). Memory controls, delegation across hops and prompt change control complete the plane in chapter 23.

Download

Every file carries the attribution band "aigovernanceengineer.com · CC BY 4.0 · v0.5.0" inside the image, and the version is in the file name, so a copy always says where it came from and which edition it shows. The SVGs keep the text live: the first follows the viewer's light or dark setting, the other two fix one theme for slides and print. The PNGs are drawn with the site's own typefaces.

One tool call through the agent control plane: registry, identity, gateway, guardrail, checkpoint and breaker, with telemetry kept as evidence.
The PNG, light, 1600 px wide, as it downloads (shown here as a lighter copy).

Reuse and credit

The figure is published under CC BY 4.0: you may copy, share and adapt it, commercially too, provided you give appropriate credit, link to the licence and say if you changed it. Keep the attribution band in the image. A credit line that covers title, author, source and licence:

“The agent control plane” by Jorge García Aibar, aigovernanceengineer.com (https://aigovernanceengineer.com/figures/agent-control-plane), v0.5.0. Licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/).

Embed with HTML

<figure>
  <img src="https://aigovernanceengineer.com/downloads/figures/agent-control-plane-v0.5.0-light-1600.png" alt="One tool call through the agent control plane: registry, identity, gateway, guardrail, checkpoint and breaker, with telemetry kept as evidence." width="800" height="1431" loading="lazy">
  <figcaption>
    <a href="https://aigovernanceengineer.com/figures/agent-control-plane">The agent control plane</a> by Jorge García Aibar,
    aigovernanceengineer.com, v0.5.0.
    Licensed under <a href="https://creativecommons.org/licenses/by/4.0/">CC BY 4.0</a>.
  </figcaption>
</figure>

Embed with Markdown

![One tool call through the agent control plane: registry, identity, gateway, guardrail, checkpoint and breaker, with telemetry kept as evidence.](https://aigovernanceengineer.com/downloads/figures/agent-control-plane-v0.5.0-light-1600.png)

*[The agent control plane](https://aigovernanceengineer.com/figures/agent-control-plane) by Jorge García Aibar, aigovernanceengineer.com, v0.5.0. Licensed under [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/).*