The control plane is a category before it is a product.
Forrester opened the market in December 2025. Microsoft put a price on it in May 2026. Almost every claim to own the category is still confined to a single vendor's own agents, the standards that would make governance portable do not yet exist, and the analyst with the sharpest thesis argues that the way most platforms are building it is the reason enterprises will switch their agents off.
An agent control plane is the answer to a question that only appears at the second agent
A single agent needs a prompt, a model and a tool. A fleet of agents needs an answer to who authorised this, what it is allowed to touch, what it did last night, what it cost, and who is accountable when it is wrong. The control plane is the system that holds those answers.
The term borrows from networking, and the borrowed meaning is the useful one
In network infrastructure the data plane moves packets and the control plane decides how packets should be moved. Applied to agents, the data path is the agent doing its work: reasoning, calling tools, writing to systems of record. The control plane is everything that decides what that agent may do, records what it actually did, and changes the rules without changing the agent.
Forrester's definition, published on 4 December 2025, is the closest thing the market has to a formal one: an enterprise control plane that inventories, governs, orchestrates and assures heterogeneous AI agents across vendors and domains. IBM defines it as the system that deploys, operates, monitors and governs agents across an organisation. The two differ on scope, which matters commercially and is covered in section 03.
Six questions define the job
The reason it is being bought now is that agents write, not read
Assistants that summarise and draft carry review risk. Agents that send, purchase, refund, escalate and update records carry action risk, and action risk is what security teams, auditors and regulators price. The Cloud Security Alliance and Zenity found that 53 % of organisations have already seen agents exceed intended permissions, while only 31 % had formally adopted policies for agents at all. That distance between capability and control is the market.
Adoption is real, narrow, and measured three different waysPublished agent-adoption figures range from 16 % to 91 % of enterprises. The spread is definitional rather than empirical, and reconciling it is the first thing any governance argument has to do.
The defensible band for agents doing real multi-step work in production is 16 % to 20 %
Four independent sources converge once the word agent is defined tightly. Menlo Ventures placed 16 % of enterprise deployments in the true-agent category, where a model plans, executes, observes and adapts, against 27 % for startups, and described the remainder as fixed-sequence or routing workflows wrapped around a single model call. Gartner reported 17 % deployed. McKinsey put roughly 20 % of organisations at the scaling stage for agents, against 47 % for conversational assistants.
Figures above 50 % are counting assistants and copilots. Okta's Businesses at Work 2026 found 91 % of organisations already using AI agents on a sample screened for AI use, and in the same study only 10 % reported a well-developed strategy for managing them.
Growth is in scaling, not in attributed profit
McKinsey's 2026 survey of 1,719 respondents across 97 countries found 40 % of large organisations scaling AI agents, up from 27 % the year before. In the same survey the share attributing any EBIT impact to AI held flat at 37 %, and the share qualifying as high performers held flat at about 6 %. Adoption moved and measured profit did not, which is the strongest evidence behind unclear business value as a cancellation driver.
The agent platform market is small, and the governance layer inside it is smaller
Menlo measured $37 billion of enterprise generative AI spend in 2025, 3.2 times the prior year. Agent platforms took roughly $750 million of the $8.4 billion horizontal category, about 10 %, against 86 % for copilots. Forecasts placing agentic AI at $1.3 trillion by 2029, published by IDC, count total IT spending influenced by agentic AI rather than agent software licences, and the two figures should never appear in the same argument.
"Most deployments remain narrowly scoped, and fully autonomous agents are not ready for the majority of enterprise use cases."
GARTNER, HYPE CYCLE FOR AGENTIC AI, 15 APRIL 2026
Five analysts have defined the category and no two definitions agreeThe phrase agent control plane is under a year old as a market term and is already attached to four different kinds of product.
Forrester opened the market and drew the boundary tightly
Leslie Joseph announced Forrester's evaluation of the Agent Control Plane market on 4 December 2025, with five in-scope areas: agent inventory and identity, policies and guardrails, monitoring and insight, control and coordination, and risk, compliance and auditing. Development environments and orchestration fabrics sit explicitly outside it. Forrester expects 12 to 24 months before the market resolves into comparable offerings, so no Wave and no vendor ranking exists today.
The definitional fault lines are commercially material
Gartner's tiered-autonomy thesis is the most useful analytic asset in the category
Gartner predicts that by 2027, 40 % of enterprises will demote or decommission autonomous AI agents "due to governance gaps identified only after production incidents occur", and attributes the cause to binary treatment of governance. Its remedy is four autonomy tiers, each carrying its own control set: Observe, with read-only access to defined sources; Advise, producing recommendations under human review; Act with Approval, executing only after explicit human sign-off; and Act Autonomously, executing independently inside guardrails.
"Enterprises are treating AI agent governance as binary, either locked down or fully trusted, and that is the root cause of failure."
SHIVA VARMA, SENIOR DIRECTOR ANALYST, GARTNER, 26 MAY 2026
The category is forming faster than the standards beneath it
In a February 2026 poll of vendors, Forrester found 92 % had assigned a named product manager or team to agent governance or control plane functionality, 79 % recognised the category, and 40 % reported active requests for proposal. The same analysis lists three blocking gaps: OpenTelemetry has not published a stable version of the generative AI semantic conventions, no portable agent identity and policy-propagation standard exists at enterprise maturity, and there are no cross-plane governance schemas. Vendor-neutral governance is therefore a claim no product can currently substantiate in full.
Fourteen layers, four settled, six contested, and one that is entirely unsolvedReference models from Futurum, BCG, IBM, Salesforce and the hyperscalers cover broadly the same ground under different names. The table reconciles them and marks where the market has actually converged.
| LAYER | NAMES IN USE | STATUS |
|---|---|---|
| Registry and inventory | Agent Registry and Agent Card (AWS), Agent 365 Registry and identity blueprint (Microsoft), Agent Registry (Google), agent catalogue (IBM) | CONCEPT SETTLED, SCHEMA CONTESTED |
| Agent identity and credentials | Entra Agent ID, Agent Identity, AgentCore Identity, workload identity | CONVERGING |
| Authorisation and delegation | Policy and Cedar (AWS), on-behalf-of execution (Databricks), user-proxy against autonomous agents (Salesforce), token exchange and actor claims (IETF) | UNSOLVED BEYOND ONE HOP |
| Policy engine and guardrails | Guardrails, Model Armor, deny / steer / warn / log / allow, judge-model guardrails, behaviour guardrails | CONTESTED |
| Tool and MCP gateway | agentgateway, AgentCore Gateway, Agent Gateway, Unity AI Gateway, Omni Gateway | COMMODITISED |
| Orchestration and runtime | Runtime and Harness, Agent Runtime and Agent Sandbox, Agent Server, execution environment | COMMODITISED |
| Memory and context governance | AgentCore Memory, Agent Memory Bank and Memory Profiles, knowledge authority, semantic layer | LEAST CONVERGED |
| Evaluation and testing | Evaluations, Agent Simulation, continuous evaluation on production traffic, red-teaming agent | SHAPE AGREED, METRICS NOT |
| Observability, tracing, audit | OpenTelemetry generative AI conventions against OpenInference span kinds; unified audit log | TRANSPORT SETTLED, SEMANTICS NOT |
| Cost and token budget | FinOps on dollar cost, run-scoped budgets with steer and halt, spend caps and failover | EMERGING |
| Human approval and intervention | Interrupt and resume, pause / escalate / narrow / modify / defer / rollback, approval per action against per plan | NO CONTROL-PLANE STANDARD |
| Lifecycle and kill switch | Draft to pending approval to published, agent lifecycle management, quarantine of unsanctioned agents | CONTESTED |
| Drift and quality scoring | Agent Anomaly Detection, Optimisation, alerts, semantic anomalies | NEWEST, NO AGREED METRIC |
| Inter-agent accountability | A2A signed agent cards, coordination layer, typed provenance, signed action receipts | PROTOCOL EXISTS, ACCOUNTABILITY DOES NOT |
Delegation across more than one hop is the genuine hole in the stack
The Model Context Protocol authorisation specification makes an MCP server an OAuth 2.1 resource server, requires resource indicators, and bans token pass-through, which closes the confused-deputy problem for a single hop. Nothing standardises what happens next: cross-organisational, multi-hop delegation in which authority narrows at every step, each hop is cryptographically bound to the last, and a downstream service can verify the chain without calling a central authority. IETF work on identity assertion authorisation grants reached an adopted OAuth working group draft in May 2026 with an explicit AI-agent use case, but the nested-actor claim is informational and unenforced. Workload identity proves which process holds a credential, not what authority it holds.
Autonomy is described four incompatible ways
No source defines human-on-the-loop normatively. The vocabulary remains open.
Every incumbent is bundling governance into a platform it already sellsThe competitive shape matters more than the feature lists. Governance is arriving as an attached module on platforms enterprises already own, and the data-path layer is being given away.
Microsoft sets the price and the reference implementation
Agent 365 reached general availability on 1 May 2026 at $15 per user per month, or inside Microsoft 365 E7. It ships registry sync with AWS Bedrock and Google Cloud in public preview, the only shipped cross-hyperscaler agent inventory. Entra Agent ID supplies identity blueprints, parent and child agent relationships and conditional access. Purview logs agent to human, human to agent, agent to tool and agent to agent interactions.
Google and AWS compete on runtime primitives
Google's Gemini Enterprise Agent Platform, announced 22 April 2026, is organised as build, scale, govern and optimise, with cryptographic agent identity, a registry, a gateway, anomaly detection using a judge model, and pre-deployment simulation.
AWS released Dogwood on 6 August 2026: an Apache 2.0 governance language, a superset of Cedar, that evaluates policies over sequences of agent actions rather than single calls, with policy support inside AgentCore.
ServiceNow and IBM sell governance over other vendors' agents
ServiceNow's AI Control Tower positions to discover, secure, govern, observe and measure any AI across the enterprise, auto-discovering agents, models, assistants, MCP servers and datasets, and absorbed Traceloop's observability team in March 2026. IBM announced an agentic control plane in watsonx Orchestrate on 2 July 2026, with policy management, credential health, an agent catalogue and versioning, arguing that the value lies in not standardising the build stack.
The chokepoint layer is now open source
Solo.io contributed agentgateway to the Linux Foundation in August 2025, covering LLM, MCP and agent-to-agent traffic with authorisation, rate limits, budgets and tamper-evident audit trails. Kong added agent-to-agent traffic to its AI Gateway in April 2026. Galileo released Agent Control under Apache 2.0 on 11 March 2026, and Cisco announced its acquisition of Galileo on 9 April 2026. Policy enforcement and MCP mediation are being commoditised towards zero.
Identity vendors hold the strongest cross-vendor claim
Okta expanded AI agent security on 14 May 2026 across Amazon Bedrock AgentCore, Salesforce Agentforce and the ServiceNow AI Platform, with unsanctioned-agent discovery by monitoring new OAuth consent grants in managed browsers, and brought Okta for AI Agents Core into regulated environments on 25 June 2026. SailPoint shipped agent-discovery connectors across eight platforms in March 2026. CyberArk, Zenity, Palo Alto Networks and Zscaler are all pushing from the security side.
The compliance pure-plays are being outflanked on enforcement
Drata announced AI agent governance on 10 June 2026 with inline sensors, real-time policy evaluation and tamper-evident logging, moving to limited availability in August. Vanta, Credo AI and Holistic AI remain framework and evidence tools rather than runtime enforcement. The distinction buyers are starting to draw is between evidencing a control and enforcing one.
Consolidation is being driven by security buyers, not operations buyers
| DATE | DEAL | REPORTED VALUE |
|---|---|---|
| 25 Aug 2025 | Solo.io contributes agentgateway to the Linux Foundation | Donation |
| 9 Dec 2025 | Anthropic donates the Model Context Protocol to the Linux Foundation's Agentic AI Foundation | Donation |
| Mar 2026 | ServiceNow acquires Traceloop, folded into AI Control Tower | Undisclosed |
| 9 Apr 2026 | Cisco announces acquisition of Galileo | Undisclosed |
| Apr to Jun 2026 | Palo Alto Networks acquires Portkey, folded into Prisma AIRS | Undisclosed |
| 4 May 2026 | Cisco acquires Astrix Security | Undisclosed |
| 28 Jul 2026 | Cyera agrees to acquire Oasis Security | Around $1bn per press reports, undisclosed by both parties |
| 30 Jul 2026 | Okta agrees to acquire Permiso Security, closed 26 Aug 2026 | Undisclosed |
| Aug 2026 | Zenity Series C led by Norwest | $125m |
The acquirers are identity and security platforms. The targets are gateways, non-human identity, observability and guardrails. No acquirer has yet bought a horizontal registry-and-policy company, which is the open slot in the consolidation map.
Buyers are blocked on data, trust and cost, in that orderThe blockers that appear in the top three of independent surveys are consistent, and the incidents that reset procurement requirements are traceable to specific dates.
Confidence is running ahead of control
Okta's Businesses at Work 2026 found 91 % of organisations already using AI agents, fewer than a third at 32 % securing agents with the same rigour applied to human employees, 58 % naming AI governance and oversight as their top security concern, and only 10 % with a well-developed strategy for managing agents. The Cloud Security Alliance and Zenity study of 445 organisations found 53 % had seen agents exceed intended permissions, 47 % had an agent-involving security incident in the past year, only 31 % had formally adopted agent policies, and only 15 % had defined ownership for most of their agents.
Cost has become a first-order governance requirement
KPMG's second-quarter 2026 pulse of 204 US C-suite leaders at firms above $1 billion in revenue reported only 26 % with real-time visibility into AI operating costs and 36 % with token or usage controls deployed, against average planned AI investment of $202 million over the following twelve months. Gartner named escalating cost as the first of three cancellation drivers and added FinOps for agentic AI to the 2026 Hype Cycle. Run-scoped budgets, per-action cost prediction, loop-depth caps and circuit breakers are moving from engineering hygiene into the control set buyers ask about by name.
Four incidents set the current procurement questionnaire
Two structural headwinds face every independent governance vendor
First, incumbency: a16z's January 2026 survey of 100 verified senior buyers at Global 2000 firms found 65 % prefer incumbent solutions where available, citing integration and procurement simplicity. Second, provider-native defaults: buyers rely heavily on the agent security shipped by their model and platform providers rather than a third-party control layer. Independent positioning has to be earned on something a platform incumbent cannot do, which in practice means heterogeneity, exportable evidence and regulated-industry depth.
The compliance cliff moved, and the liability cliff did notThe most common error in current market positioning is urgency built on an EU deadline that no longer exists. The obligations that actually bite this year are transparency, general-purpose model enforcement and product liability.
There is no agent-specific law in the EU, and the Commission says none is needed
Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and deferred standalone high-risk obligations under Annex III to 2 December 2027 and embedded high-risk obligations under Annex I to 2 August 2028. Article 12 logging, Article 14 human oversight, Article 26 deployer duties and Article 73 incident reporting travel with those dates. The Commission's position is that the existing definitions of an AI system and a general-purpose model already cover AI agents.
What did apply on 2 August 2026 is Article 50 transparency, which catches any user-facing agent regardless of risk tier: disclosure that a person is dealing with an AI system, and machine-readable marking of synthetic output, with a four-month transitional period for systems already on the market. Enforcement powers over general-purpose models went live on the same date. No harmonised standard has yet been cited in the Official Journal, so no presumption of conformity is available to anyone, which is a large part of why the high-risk date moved.
Product liability is the near-term exposure, and it lands in December
The EU withdrew the AI Liability Directive in October 2025. Directive (EU) 2024/2853 fills the gap and applies to products placed on the market after 9 December 2026. It expressly treats software as a product, names AI system providers as manufacturers, adds liability for failure to supply security updates, extends recoverable damage to destruction of data, and creates rebuttable presumptions of defect and causation where technical complexity makes proof excessively difficult or the defendant fails to disclose evidence. The disclosure-triggered presumption is the sharp edge for an agent vendor: a platform that cannot produce decision traces stands in a worse position than one that can.
The United States is moving the other way, and courts are allocating agent liability directly
Executive Order 14365 of December 2025 established a Justice Department task force to challenge state AI laws, and Colorado repealed its AI Act, replacing it in May 2026 with a disclosure-and-fault regime effective January 2027. California SB 53 is in force, with transparency reports, a published frontier framework, 15-day critical-incident reporting and penalties to $1 million per violation. On 4 August 2026 the Ninth Circuit held in Amazon against Perplexity that under the Computer Fraud and Abuse Act it is the user who accesses a site with the help of an assistant, and that the assistant "is a tool, not a person for statutory purposes". The holding turns on architecture: browser-mediated agents are protected in a way server-to-server designs are not, and tort, contract and copyright theories were left open.
Financial regulators have split, and the Indian bar is currently the higher one
US interagency guidance SR 26-2 of 17 April 2026 superseded SR 11-7 and SR 21-8, applies to banks above $30 billion in assets, states that it sets no enforceable standards, and excludes generative and agentic AI from scope as novel and rapidly evolving. The Reserve Bank of India moved in the opposite direction, issuing draft Guidance on Regulatory Principles for Model Risk Management on 24 June 2026, covering all models used by regulated entities including third-party and machine-learning models across the lifecycle. Law-firm analyses of the draft report board-approved frameworks, independent validation of third-party models by the regulated entity before and after deployment, kill-switch and override arrangements, long retention of decommissioned model records, and contractual audit rights.
The most operationally specific government guidance on agents is Singapore's
Singapore's IMDA published a Model AI Governance Framework for Agentic AI on 22 January 2026: bound the agent through use-case selection and constrained autonomy, tool access and data permissions; define human accountability with checkpoints requiring approval and mitigation of automation bias; apply baseline testing, access control and lifecycle management; and provide end-user transparency and training. Paired with the NSA's 2026 information sheet on MCP security, which names absent access control, optional authorisation, weak re-approval on capability change and inadequate logging as systemic, these are the two most citable control checklists in existence, and both are free.
EU general-purpose model obligations and penalties apply; code of practice in effect
California SB 53, AB 2013 and SB 243; Texas TRAIGA; Illinois HB 3773; California removes the autonomous-AI defence
Singapore IMDA agentic AI governance framework; Korea AI Basic Act with a one-year enforcement grace
UK Data (Use and Access) Act automated decision-making safeguards
China's interim measures on anthropomorphic interaction services, the first binding regime aimed at human-like agents
Regulation (EU) 2026/1744 in force, deferring the high-risk regime
EU Article 50 transparency applies; AI Office enforcement powers over general-purpose models go live
Ninth Circuit rules on agent access under the Computer Fraud and Abuse Act
EU synthetic-content marking grace ends for systems already on the market
EU product liability applies to products placed on the market, software and AI included
Colorado's replacement AI law takes effect
EU standardisation request expires; harmonised standards must land or the 2027 date is at risk
India DPDP Rules reach full applicability (phased from the November 2025 notification)
EU legacy general-purpose models must comply; regulatory sandboxes operational
EU Annex III high-risk obligations: logging, human oversight, deployer duties, incident reporting
EU Annex I embedded high-risk obligations
India regulates agents through sectoral regulators, and that changes what a platform must ship
MeitY's India AI Governance Guidelines of 5 November 2025 explicitly favour amending existing law over new AI legislation, and hand enforcement to sectoral regulators, with an AI Governance Group, a technology and policy expert committee and an AI Safety Institute as the institutional machinery.
The practical consequence is that for financial services the binding authority is the Reserve Bank of India rather than MeitY. The RBI's FREE-AI committee report of August 2025 set two commercially decisive principles: final decision-making vests with humans rather than models, and the regulated entity remains accountable regardless of the level of autonomy. The June 2026 draft on model risk management extends this to third-party and machine-learning models across the lifecycle.
For personal data, the DPDP Rules notified in November 2025 phase in over eighteen months to roughly May 2027, require breach notification to the Data Protection Board and to affected individuals with no materiality threshold, and require consent managers to be companies incorporated in India. An agent that touches personal data and acts without a human in the path is a notification liability under that regime.
The design consequence: an Indian buyer in banking or insurance cannot accept a model card as evidence, because the regulated entity is required to validate independently. A platform built to that bar, with model and agent inventory export, per-agent documentation, drift monitoring, an auditable override and complete action-chain logs held for long periods, is already over-compliant for a US bank operating under SR 26-2, which excludes agents from scope entirely. Building to the harder regime first turns compliance depth into an export asset.
Demand-side signal: EY's 2025 GCC pulse reported 58 % of India global capability centres investing in agentic AI and 29 % planning to scale within the year, while only 7 % had a fully embedded cybersecurity centre of excellence and 60 % now monitor third-party data access, up from 44 % a year earlier. Buying intent is running well ahead of governance maturity, and third-party scrutiny is tightening quickly.
Six problems the market has named and not yet solvedThese are the places where the analyst literature says control should exist and the shipped product landscape says it does not.
Autonomy tiers as the organising unit of policy
Gartner names uniform governance as the root cause of agent failure and prescribes four tiers with distinct control sets. Most shipping products market one policy layer with autonomy as an attribute of an agent rather than as the structure that determines which controls apply.
Governed paved roads, not enforcement alone
BCG's model is the only one treating pre-governed deployment templates, with identity, registration, monitoring and policy embedded by default, as a first-class control-plane component, and reports order-of-magnitude reductions in time to deploy. Enforcement stops unsafe agents. Paved roads are what make safe agents cheap.
Inventory that genuinely crosses vendors
Forrester's definition requires heterogeneity, and Forrester's own assessment is that offerings remain platform-specific. Only Microsoft's registry sync and SailPoint's connector set currently reach beyond their own estate. Cross-vendor inventory is the capability the category is named after and the one least often delivered.
Memory governance
Memory poisoning has a live attack literature and its own entry in the OWASP agentic top ten, yet no major vendor memory product publishes a write-admission policy, a provenance tag or an expiry model for learned experience. This is the layer where product maturity lags published attack research by the widest margin.
Evidence a regulated buyer can export
Standard contracts confer no right to logs, decision traces or explainability. The product answer is an export: agent inventory, approval-gate evidence with approver identity, full action chains, evaluation records and model-change history, in a form an auditor or a regulated customer can lift without vendor assistance.
Multi-hop accountability
Agent-to-agent protocols exist and are governed by the Linux Foundation. Accountability semantics across a delegation chain do not. Any platform running agent teams with reporting lines is already generating the artefact the standards bodies are still specifying.
How Nagent approaches the control plane
Nagent is a vendor in the market described above, and the disclosure belongs at the top rather than the bottom. What follows is an account of the design choices, set against the six problems in section 09, so that they can be judged rather than taken on trust.
Autonomy is the organising unit, not an attribute
Every agent on the platform carries an autonomy level alongside a risk level, on a five-rung ladder. The level determines which controls apply, which actions can fire without a human, and what the approval queue looks like. This is the tiered structure Gartner prescribes, implemented as the primary construct of the system rather than as a setting inside a uniform policy layer.
A human acts on every output. Nothing executes.
Drafts are visible and never sent. Read-only actions may fire; anything with a side effect queues.
The agent runs automatically once a human has signed off on the action.
The agent runs autonomously and every action is logged for review after the fact.
Unrestricted within the agent's guardrails, policies and budget.
Trust is earned and can be lost without anyone intervening
Each agent carries a trust score from 0 to 100 that moves with observed behaviour. Governance is scored twice: per agent in the workbench, where autonomy, risk, guardrails, policies and budget are configured, and across the fleet on a governance surface that ranks agents by a composite score, bands them, and names the weakest dimension for each. Drift beyond a threshold raises a warning, and an agent can be downgraded automatically rather than waiting for a human to notice. The same surface scores operator decisions alongside agent behaviour, on the view that approval quality is part of the control system rather than outside it.
Guardrails, policies and budgets are separate objects with separate enforcement
Tool authority is scoped, and blast radius is shown before anything ships
Whitelisting an action makes it available to an agent as a runtime tool, and the autonomy level then decides whether it fires or queues: read-only actions execute from L1 upwards, actions with side effects queue for approval below L3. Every action carries a scope, and narrowing an action to named agents prevents any other agent in the tenant from reaching it regardless of its own tool list. In the workflow builder, a blast radius panel flags conditions such as calling a third party at design time rather than at run time.
Memory is governed in two layers and every turn is replayable
Agent memory separates a creator layer, holding operator-authored hard rules and brand voice, from a user layer holding the agent's own observed tendencies, recent successes and recent failures. Every agent turn persists the context that was assembled for it, so a decision can be inspected and replayed rather than reconstructed. Against problem 04, this is a write-admission boundary and a provenance record at the point where most platforms hold an undifferentiated store.
Agent teams carry reporting lines, and the record is the deliverable
Agents have a reports-to relationship and a tier, and handoff targets are derived from the reporting line rather than configured separately, routing to parent, children, root or sideways to a specialist. Teams mix people and agents under a lead, and team membership is the access boundary for the team's thread, documents and decisions. The workspace is a shared thread where humans and agents post together, feedback is captured on each agent turn, and a decision can be recorded as such. Each team keeps a repository holding its charter, roster, memory, tasks, pending decisions, decision log and run records, which is the exportable evidence described in problem 05.
The deployment path is governed by default
Agents are created from a one-line description through a three-step flow that assembles skills, tools, triggers and guardrails together, so a new agent arrives registered, scoped and constrained rather than being retrofitted afterwards. Workflows are versioned with draft and published states, and the builder states plainly that nothing goes live without an explicit accept. This is the paved road in problem 02, implemented as the default route rather than an optional template.
One honest limit, stated plainly
Under Forrester's strict definition, a control plane governs agents it did not build. Nagent spans build, orchestration and control in a single platform, which means governance is enforced as a property of the runtime rather than inferred from outside it. The gain is that policy, memory, autonomy and evidence share one model, so an approval is bound to the exact context that produced the proposal. The trade-off is that agents built elsewhere are governed through integration rather than natively, and no vendor in this market, including those claiming vendor-neutrality, currently delivers full cross-vendor governance in the way the category definition implies.
The argument in one line
Agents fail in production not because models are weak but because authority is undefined, and authority is a product decision rather than a policy document. A control plane earns its place when the level of autonomy an agent holds is visible, evidenced, reversible and earned.
How to read the numbers in this marketEvery figure in this brief was checked against a primary source. These are widely repeated claims that did not survive that check, with the defensible substitute in each case.
"Only 21 % of organisations have a mature agentic governance model."
Circulated with an attribution to a large April 2026 consultancy study. No such publication could be located on the named firm's own properties. The defensible substitutes are the Cloud Security Alliance ownership and policy figures, and Okta's 10 % with a well-developed agent management strategy.
"Okta, AI Agents at Work 2026: 92 % widespread use, 34 % same controls, 58 % had an incident."
No report of that name or date exists. The correct source is Businesses at Work 2026, published 30 April 2026: 91 % using agents, 32 % securing agents with the same rigour as employees, and 58 % naming governance and oversight as their top security concern, which is a concern figure rather than an incident rate.
"92 % of enterprises have named an owner for agent governance."
Forrester's 92 % is a poll of vendors, not enterprises. Cited as an enterprise statistic it inverts the meaning: it is evidence of supply-side crowding rather than buyer maturity.
"AWS AgentCore shipped Dogwood."
Dogwood is a standalone Apache 2.0 governance language for agents and tools, released on 6 August 2026, with policy support additionally available inside AgentCore. Describing it as a product feature understates the strategic move, which is an open language other platforms can adopt.
Reported prices for the Cyera and Oasis, and Okta and Permiso, transactions.
Both deals are confirmed and neither price is disclosed by the parties. One figure comes from press reporting and the other has no primary support. The deals are citable; the numbers are not.
"EU AI Act high-risk obligations apply from 2 August 2026."
Deferred to 2 December 2027 and 2 August 2028 by Regulation (EU) 2026/1744. Urgency framing built on the old date is now wrong, and buyers who have read the omnibus will notice. Article 50 transparency is the live obligation.
"95 % of AI projects fail" and "ISO 42001 is a procurement requirement".
The first measures attributable profit from generative AI pilots on a small, non-probability sample and says nothing about agents. For the second, no primary survey quantifies buyer demand; the frameworks buyers actually name are HIPAA, the NIST AI Risk Management Framework, and SOC 2 or ISO 27001.
"Machine identities outnumber humans 45 to 1."
Publishers report 45, 80 and 109 to one for different populations counted in different ways. Cite one publisher with its date, or drop the ratio.
