Governance platforms keep the register of agents, their owners and their approvals. Five kinds of vendors now sell them.
This page compares the five, lists what to require, and shows the gap between a written policy and an enforced one, where an AI agent allow list does the enforcing on the web.
A governance platform should follow every agent from idea to shutdown. Most buyers underestimate stages 5 and 6.
Stage 4 is where governance meets real systems. A register entry that says "may not create accounts" does nothing unless something blocks signup pages.
Stage 6 is the other weak point. Retired agents often keep working keys for months.
Each type grew out of a different product. That origin decides its strengths.
Vendors are examples of each type, based on their own product descriptions. Capabilities change quickly, so verify before shortlisting.
Without the right-hand box, the register holds promises. With it, the register holds proof.
| Requirement | GRC specialist | IT workflow | Data governance | Cloud platform | Security-led |
|---|---|---|---|---|---|
| Agent register | Strong | Strong | Strong | Own agents | Strong |
| Discovery of unknown agents | Weak | Partial | Partial | Own platform | Strong |
| Framework mapping | Strong | Partial | Partial | Weak | Partial |
| Approval workflow | Strong | Strong | Partial | Partial | Partial |
| Identity link | Partial | Partial | Partial | Strong | Strong |
| Runtime enforcement | Weak | Weak | Data only | Own agents | Partial |
| Web page policy | Needs data | Needs data | Needs data | Needs data | Needs data |
Scores describe the typical product of each type, not any single vendor. The last row is the same everywhere, because page-type data is a separate asset.
Two of the six come straight from page-policy decision logs. That is why the enforcement layer belongs in the governance design from day one.
Report them per agent and per owner. A single company-wide number hides the one agent that keeps trying to sign up for things.
Trend lines matter more than totals. A rising count of blocked attempts after a model upgrade is an early warning worth investigating.
| Your situation | Lead with | Pair with |
|---|---|---|
| Regulator or board is asking for an AI register | GRC specialist | Security-led discovery |
| Everything runs through ServiceNow already | IT workflow platform | Page policy data at the proxy |
| Agents mostly work on internal data | Data governance platform | Identity platform |
| All agents built on one cloud | That cloud's registry | Page policy data in the fetch tools |
| Nobody knows how many agents exist | Security-led governance | GRC specialist later |
| Agents browse and act on the web | Any of the above | AI agent allow list for enforcement |
R = responsible, A = accountable, C = consulted, I = informed. Adapt the roles to your own organisation.
| Activity | Agent owner | AI platform team | Security | Risk and legal |
|---|---|---|---|---|
| Register a new agent | R | C | I | A |
| Set agency scope | R | C | C | A |
| Approve tools and MCP servers | C | R | A | I |
| Set web page policy | C | R | A | C |
| Review denied action attempts | R | I | A | I |
| Handle an agent incident | C | R | A | C |
| Retire an agent | A | R | C | I |
Keep the table short and visible. Security usually owns the web page policy because it sits next to existing URL filtering. The agent owner reads the denials, because only they know if a denial was right.
Questions 2 and 3 separate a register from a governance system. If policy cannot reach an enforcement point, it stays a document.
Ask for a live demo of question 4: a denied request appearing in the agent record within minutes.
The EU AI Act entered into force in 2024 and applies in phases. It does not define "agent", but its duties still reach agents that fall into regulated uses.
Whether a given agent is high-risk depends on its use. Legal teams should make that call, and the register should record it.
This is general information, not legal advice.
| Field | Example | Why it matters |
|---|---|---|
| Purpose | Compare vendor pricing for procurement | Limits what counts as normal behaviour |
| Owner | Head of procurement | Someone answers for every action |
| Agency scope | Supervised | Sets the strength of controls |
| Tools and MCP servers | CRM read, browse | Defines what the agent can touch |
| Credentials | Service identity, 8-hour tokens | Links to the identity platform |
| Web policy | Read pages allowed, 8 action types denied | Makes web rules enforceable |
| Data classes | Supplier contracts, no personal data | Connects to data protection duties |
| Review date | Every 90 days | Catches scope creep |
| Decision log link | Proxy log stream for this agent | Evidence that the rules ran |
CRM, support and office suites now ship their own agents. They act for your staff, on your data, under your name.
Our sibling guides on which agents train on your data help with the contract questions.
The honest fine print — the same two assumptions we publish, plus two operational ones
Page-type data turns web rules in the register into a deny on every request.