AI Agent Allowlist
Home Page-Types Database Agent Guardrails 2026 Incidents API Docs Pricing
Resources
Use Cases (15) Industries & Buyers (12) Learn: Core Concepts (12) Implementation Guides (15) Comparisons (8) Schema & Data Reference (6) FAQ Glossary
Why It Matters
2026 Agent Incidents Category Targeting Database Refreshes Contact Customer Login
Download Free Sample
for risk, compliance and AI platform leaders

AI Agent Governance Platforms Compared

Governance platforms keep the register of agents, their owners and their approvals. Five kinds of vendors now sell them.

This page compares the five, lists what to require, and shows the gap between a written policy and an enforced one, where an AI agent allow list does the enforcing on the web.

5Platform types
6Lifecycle stages
16Requirements to check
1Gap: policy to enforcement
What governance covers

The six stages of an agent's life

A governance platform should follow every agent from idea to shutdown. Most buyers underestimate stages 5 and 6.

1RegisterName, purpose, owner
2AssessRisk, data, agency scope
3ApproveWho signed off, on what
4EnforceTools, identity, web pages
5MonitorBehaviour, incidents, drift
6RetireRevoke access, keep records

Stage 4 is where governance meets real systems. A register entry that says "may not create accounts" does nothing unless something blocks signup pages.

Stage 6 is the other weak point. Retired agents often keep working keys for months.

The market

Five types of AI agent governance platforms

Each type grew out of a different product. That origin decides its strengths.

AI governance and GRC specialists

  • Deep mapping to laws and frameworks
  • Risk assessments and model cards
  • Evidence packs for auditors
  • Rarely enforce anything at runtime
  • Depend on other tools for data
Examples: Credo AI, Holistic AI, OneTrust, IBM watsonx.governance

IT workflow platforms

  • Approvals and tickets built in
  • Links agents to services and owners
  • Familiar to IT and risk teams
  • Best for agents inside the same platform
  • Runtime control is limited
Examples: ServiceNow AI Control Tower

Data governance platforms

  • Strong on data lineage and access
  • Catalog of models, datasets and agents
  • Policies tied to data classes
  • Agent actions outside data are less covered
  • Web activity is out of scope
Examples: Collibra, Databricks Unity Catalog

Cloud and agent platforms

  • Governance for agents built on the platform
  • Identity and logging built in
  • No extra vendor to buy
  • Covers only that platform's agents
  • Mixed estates need a second tool
Examples: agent registries in Microsoft, Google Cloud and AWS offerings

Security-led agent governance

  • Discovers agents you did not register
  • Finds risky permissions and connections
  • Often includes runtime controls
  • Lighter on legal and framework mapping
  • Web navigation control still needs data
Examples: Zenity, Noma Security, AI-SPM features from cloud security vendors

The enforcement data layer

  • Turns "no signups, no purchases" into a per-URL deny
  • Works with any of the five types
  • Logs each decision for the register
This site: page-type data for 40M+ domains

Vendors are examples of each type, based on their own product descriptions. Capabilities change quickly, so verify before shortlisting.

The gap

Where written policy stops and enforcement must start

What the governance platform records

  • Agent: supplier-research-bot
  • Owner: procurement lead
  • Scope: supervised
  • Rule: "May read vendor sites. May not sign up, buy or post."
nothing connects these by default

What must happen on each request

  • URL arrives: vendor.com/start-trial
  • Lookup: page type = signup
  • Decision: deny, log, notify owner
  • Evidence flows back to the register

Without the right-hand box, the register holds promises. With it, the register holds proof.

1. Write the rule once

  • In the governance platform
  • As page types, not as a list of sites

2. Sync it to enforcement

  • Gateway, proxy or fetch tool
  • Same rule wherever the agent runs

3. Return the evidence

  • Every deny logged against the agent
  • Reviewed by its owner each month
# Governance rule, written once, enforced per request agent: supplier-research-bot owner: procurement-lead web: allow: [pricing, documentation, about, legal, security, case_studies] deny: [signup, checkout, cart, subscribe, upload, post_create, comment] unclassified: deny on_deny: notify(owner)
Requirements

Sixteen things to require from a governance platform

Agent register with purpose, owner and status.
Discovery of agents nobody registered.
Risk assessment templates per agent type.
Agency scope field, reviewed on every change.
Approval workflow with named approvers.
Tool inventory per agent, including MCP servers.
Credential link to the identity platform.
Web policy per agent: allowed and denied page types.
Enforcement hooks to gateways, proxies and browsers.
Decision logs fed back from enforcement points.
Incident records linked to the agent.
Framework mapping to NIST, OWASP and the EU AI Act.
Vendor agents recorded, not only in-house ones.
Periodic review reminders per agent.
Retirement steps that revoke all access.
Export of the full register for auditors.
Side by side

How the five types score on the requirements

RequirementGRC specialistIT workflowData governanceCloud platformSecurity-led
Agent registerStrongStrongStrongOwn agentsStrong
Discovery of unknown agentsWeakPartialPartialOwn platformStrong
Framework mappingStrongPartialPartialWeakPartial
Approval workflowStrongStrongPartialPartialPartial
Identity linkPartialPartialPartialStrongStrong
Runtime enforcementWeakWeakData onlyOwn agentsPartial
Web page policyNeeds dataNeeds dataNeeds dataNeeds dataNeeds data

Scores describe the typical product of each type, not any single vendor. The last row is the same everywhere, because page-type data is a separate asset.

Proving governance works

Metrics a board or regulator will understand

Share of agents registeredRegistered agents divided by discovered agents.
Agents with a named ownerTarget: every one of them.
Blocked action attemptsSignup, checkout and upload denials per month, per agent.
Unclassified destinationsRequests to hosts nobody has classified, trending down.
Time to retireDays from "retire" decision to all access revoked.
Review coverageAgents reviewed within their review period.

Two of the six come straight from page-policy decision logs. That is why the enforcement layer belongs in the governance design from day one.

Report them per agent and per owner. A single company-wide number hides the one agent that keeps trying to sign up for things.

Trend lines matter more than totals. A rising count of blocked attempts after a model upgrade is an early warning worth investigating.

Selection by situation

Which type fits your organisation

Your situationLead withPair with
Regulator or board is asking for an AI registerGRC specialistSecurity-led discovery
Everything runs through ServiceNow alreadyIT workflow platformPage policy data at the proxy
Agents mostly work on internal dataData governance platformIdentity platform
All agents built on one cloudThat cloud's registryPage policy data in the fetch tools
Nobody knows how many agents existSecurity-led governanceGRC specialist later
Agents browse and act on the webAny of the aboveAI agent allow list for enforcement
Rollout

A governance rollout in four phases

Phase 1: inventory

  • Discover agents and tools
  • Name an owner for each
  • Freeze new agents without a register entry

Phase 2: policy

  • Set agency scope per agent
  • Write tool and web rules
  • Agree approval paths

Phase 3: enforcement

  • Connect identity, MCP gateway and web policy
  • Deny action pages by default
  • Send decisions back to the register

Phase 4: assurance

  • Report the six metrics monthly
  • Test controls with red teams
  • Review each agent on schedule
Roles

Who does what in agent governance

R = responsible, A = accountable, C = consulted, I = informed. Adapt the roles to your own organisation.

ActivityAgent ownerAI platform teamSecurityRisk and legal
Register a new agentRCIA
Set agency scopeRCCA
Approve tools and MCP serversCRAI
Set web page policyCRAC
Review denied action attemptsRIAI
Handle an agent incidentCRAC
Retire an agentARCI

Keep the table short and visible. Security usually owns the web page policy because it sits next to existing URL filtering. The agent owner reads the denials, because only they know if a denial was right.

Vendor questions

Eight questions for governance vendors

How do you find agents that nobody registered?
Which enforcement points can you push policy to?
Can you store web rules as page types, not just domains?
Do decision logs flow back into the agent record?
How are vendor agents recorded and reviewed?
What happens when an agent changes tools or scope?
Which frameworks and laws are mapped out of the box?
Can the register be exported in a format auditors accept?

Questions 2 and 3 separate a register from a governance system. If policy cannot reach an enforcement point, it stays a document.

Ask for a live demo of question 4: a denied request appearing in the agent record within minutes.

Regulation

Agent governance and the EU AI Act

The EU AI Act entered into force in 2024 and applies in phases. It does not define "agent", but its duties still reach agents that fall into regulated uses.

Risk management

  • High-risk systems need a risk process across their life
  • An agent register with risk fields supports it

Record keeping

  • High-risk systems must log events automatically
  • Per-request decision logs are that record for web actions

Human oversight

  • People must be able to oversee and stop the system
  • Denying action pages with an approval step is one way to show it

Whether a given agent is high-risk depends on its use. Legal teams should make that call, and the register should record it.

This is general information, not legal advice.

Failure patterns

Six ways agent governance goes wrong

Register without teeth

  • Rules are written but no system applies them
  • Fix: connect at least one enforcement point per rule

Shadow agents

  • Teams build agents outside the register
  • Fix: discovery plus a default-deny egress rule

Scope creep

  • Agents gain tools without a new review
  • Fix: any tool change reopens the approval

Vendor agents ignored

  • SaaS agents act for staff with no record
  • Fix: add them to the register and the contract

Domain-only web rules

  • "Allow vendor.com" also allows its signup page
  • Fix: rules by page type, not by domain

Agents never retired

  • Old agents keep keys and access
  • Fix: review dates and automatic revocation
The agent record

Fields every agent entry should hold

FieldExampleWhy it matters
PurposeCompare vendor pricing for procurementLimits what counts as normal behaviour
OwnerHead of procurementSomeone answers for every action
Agency scopeSupervisedSets the strength of controls
Tools and MCP serversCRM read, browseDefines what the agent can touch
CredentialsService identity, 8-hour tokensLinks to the identity platform
Web policyRead pages allowed, 8 action types deniedMakes web rules enforceable
Data classesSupplier contracts, no personal dataConnects to data protection duties
Review dateEvery 90 daysCatches scope creep
Decision log linkProxy log stream for this agentEvidence that the rules ran
Vendor agents

Governing agents you do not host

CRM, support and office suites now ship their own agents. They act for your staff, on your data, under your name.

Contract

  • Ask what the agent may do on the web
  • Ask whether it can create accounts or buy
  • Ask for its logs on request

Configuration

  • Switch off browsing where not needed
  • Use the vendor's own allowlists
  • Limit which staff may enable agents

Network

  • Agents running in your browser pass your proxy
  • Apply the same page policy there
  • Vendor-cloud agents need contract controls instead

Our sibling guides on which agents train on your data help with the contract questions.

Governance on paper did not stop the 2026 incidents

  • The agents involved were known, owned systems running approved tasks.
  • What failed was enforcement: nothing stopped wiki edits, plugin installs or dataset uploads.
  • In our replay, page-type data plus egress rules would have stopped almost all of them.
The 2026 agent incidents, prevented The sandbox escape case

The honest fine print — the same two assumptions we publish, plus two operational ones

  1. The policy engine must see every request — an agent with raw socket access or a second network path bypasses everything; enforcement belongs at the egress proxy/network layer, not only in an SDK hook.
  2. Default-deny must be on. In flag-only mode these become alerts within minutes rather than prevention — still a large improvement on a timeline measured in weeks (the DseWiki edits ran from late May to late June 2026, per the researchers), but not a block.
  3. For full URL+method matching on HTTPS you need to be the proxy or in-process hook — SNI alone shows only the host, which still catches the entire host-list layer.
  4. Policy can’t read intent inside a legitimately allowed action: an agent whose job is publishing packages keeps registry access. In our replay of the 2026 incidents, no crossing fits any plausible allowlist for the agents’ documented tasks.
Related

Keep reading

FAQ

Governance platform questions

What is an AI agent governance platform?
Software that keeps a register of AI agents with their owners, risks, approvals and reviews, and links them to the controls that enforce their rules.
Which AI agent governance tools are there?
Five types: GRC specialists (Credo AI, Holistic AI, OneTrust, IBM watsonx.governance), IT workflow (ServiceNow), data governance (Collibra, Databricks), cloud platform registries, and security-led tools (Zenity, Noma Security).
Does a governance platform block risky agent actions?
Usually not by itself. It records rules and approvals. Blocking happens in identity systems, gateways, proxies and browsers, using data such as page types for the web.
How do I enforce "agents may not sign up or buy" on the web?
Check every URL before the agent opens it and deny the signup, cart, checkout and subscribe page types. An AI agent allow list provides those page types for 40M+ domains.
Should vendor SaaS agents be in the register?
Yes. Agents that act for your staff inside vendor products carry your data and your name, even though you do not host them.
Does the EU AI Act regulate AI agents?
It regulates AI systems by use and risk, not by the word agent. An agent used in a high-risk area carries the same duties, including risk management, logging and human oversight.
Who should own web page policy for agents?
Usually the security team, next to existing URL filtering, with the agent owner reviewing denials. The governance platform records the rule and receives the decision logs.
How many AI agents does a typical enterprise have?
There is no reliable public figure, and counts grow quickly once vendor agents are included. Run discovery before estimating; most teams find more agents than they expected.
Can we start governance without buying a platform?
Yes. A spreadsheet register with owners, scopes and web policies, plus page-level enforcement at the proxy, covers the essentials while you choose a platform.
How can I test page-level enforcement?
Download the free sample of 100 domains, or start the lookup API from $99 a month. See pricing for on-premise licenses.

Give your governance rules a way to say no

Page-type data turns web rules in the register into a deny on every request.

Download the sample