Agent Governance Readiness: Who Decides What AI Can Do?
Insights

Agent Governance Readiness: Who Decides What AI Can Do?

Chris KetchuckSep 23, 20263 min read

If an agent joined your team tomorrow, who decides what it’s allowed to see and do? Not what it can do, what it’s allowed to do. For most organizations, the honest answer is nobody’s thought about it yet.

What is governance readiness?

Governance readiness means your organization has written the rules an agent operates under. Which records it can see, which actions it can take on its own, which require a human sign-off, and how its activity gets reviewed. It’s standard enterprise AI governance, your policies, your boundaries, your approval gates.

Why this homework is brand new

Every other kind of readiness has a precedent. You’ve cleaned data before. You’ve integrated systems before. But your organization has never had a non-human colleague before, and it shows. The employee handbook covers people. The security policy covers software. An agent is neither.

That’s why this dimension trips up otherwise sophisticated teams. The gap isn’t technical capability, it’s that the policies simply haven’t been written, because there was never a reason to write them.

The four questions to answer before an agent arrives

  1. Who owns the decision? A named person decides what agents can see and do, not “IT would figure it out,” which in practice means improvising under pressure.
  2. What can it touch? Access defined deliberately, which objects, which fields, which customers. The principle is the same one you’d apply to a new contractor, least privilege, expanded with trust.
  3. What needs a human first? Defined approval gates for consequential actions, sending external communications, changing prices, touching money. Write the list before the agent exists, not after the first surprise.
  4. How would you know? Agent activity is logged and reviewable. I’ve seen what happens when nobody’s watching that activity. On one engagement, an automation on the client’s side was calling into a shared system far more than it was built to handle, and it pushed the connection past its limits. Our own integration got taken down right along with it, and neither side could reliably move data until the volume came back under control. We didn’t catch it from a dashboard, we caught it because things broke. If something goes wrong, you find out from your own monitoring, not from your systems failing around you.

Boring is the point

None of this is glamorous, and that’s exactly why it’s a competitive edge. Most teams skip it, deploy something impressive, hit one uncomfortable surprise, and freeze their program for two quarters while they write the policies they could have written up front. The teams that do the boring work first get to move fast later, safely, and with the confidence to hand agents progressively bigger work.

We’ve been running something like Claudeforce since Feb 2026, and our rule from day one has been simple. The agent earns scope the way a new hire does. Defined boundaries, human review on what matters, trust expanded on evidence.

Where to start

Write the four answers above for one workflow, just one, and you’re ahead of most of the market. Governance is one of five dimensions in the Claudeforce Readiness Framework. The Claudeforce Readiness Quiz will tell you in a few minutes whether you’d be improvising.