Many teams are shipping agents. One place decides what they may do.
A company your size runs agents from several teams, and buys more inside the software it already licenses. The person accountable for what they do is not the person who built them, so the control belongs outside the agents.
One control plane, as many rulesets as you have agents
A support agent, a trading agent and a claims agent decide different things and need different rules. What they share is where those rules live: one engine, where every version is promoted and every decision is recorded.
Today each team writes its guardrails into its own code, in its own style, and when the person who wrote them leaves nobody can read them. Here a ruleset is a declared artifact with an owner, a version and a history.
The people who own the policy change it themselves
At your size the policy belongs to security, risk and compliance, and they cannot wait on an engineering release to change a threshold.
So the person who owns the policy writes, tests and promotes the rule without a ticket to engineering. Who may do each step is declared too, so the role that writes a rule can be different from the role that promotes it.
What your security review is going to ask for
All of it is in the deployment on day one, on your own infrastructure.
Which of those your reviewers can verify themselves is on the security page.
You have bought this before, and it was a dashboard
A prompt-injection or jailbreak detector returns a number, and the number is an input to a decision. Buy the number and a dashboard, and the decision stays inside the agent, with no version to point at and no way to answer for it later.
Here your rule decides what the number means, and the rule is versioned like every other one. How a detector plugs in.
An acquisition cannot move your control plane
Larger security companies keep buying AI security vendors. A control plane running in someone else's cloud can be sold, repriced, moved into a bigger suite you did not buy, or shut down.
This one runs in your data center. There is no sub-processor list to review, because there are no sub-processors.
Where to start
- The inventory comes first, because every other control needs a list of what you run.
- Who may call what.
- What arrives from outside.
- What must not leave.
- What it may spend.
- The record that proves it.