top of page

Agentic AI Governance
Design and Build

We design and implement the guardrails for the AI agents you are already running.

Every agent registered and tiered within 90 days, with the control set designed and proven on the agents that matter most.

Governance is behind the agents

Organisations deploying AI agents are shipping them faster than they are reviewing them. That is not a discipline problem. It is what happens when the tooling matures faster than the oversight around it.

Three things follow. Nobody can produce a current, complete list of agents in production. Agents hold broad standing permissions, because scoping them precisely was harder than granting them. And the first real test of the controls is an incident.

An assessment tells you this. It does not fix it.

Who this is for

Organisations running AI agents in production across business and technical processes: monitoring, data analysis, signal and event processing, advice generation, and workflow execution.

 

Either you have enough agents that nobody can list them from memory, or you have a few that sit in processes you cannot afford to have go wrong. Both need governing. Neither is served by a compliance assessment.

This service is a good fit where:

  • Agents are being built and shipped faster than they are being reviewed.

  • Nobody can produce a current, complete list of agents in production.

  • Agents hold broad standing permissions because scoping them precisely was harder than granting them.

  • An ISO-style management system feels premature, disproportionate, or simply the wrong instrument.

  • A customer, regulator, insurer or board has started asking how agents are controlled.

  • A small number of agents in expensive-to-fail processes.

What we deliver

A governance framework built around individual agents, not the organisation. The agent is the unit that gets registered, tiered, bounded, reviewed, and retired.

Agent Registry

A complete inventory of agents in production, in build, and in unmanaged use.

Exposure Map

Every agent plotted on autonomy against action-space. One page.

Risk Tiering Model

Tiers that drive approval path, human involvement, testing depth and review cadence.

Control Catalogue

The control set for each tier, marked platform, process or agent.

See the Catalogue

Agent Charter template

Two pages per agent. Purpose, permitted and prohibited actions, escalation triggers, owner.

Intake and approval workflow

A front door for new agents, inside your existing change process.

How we work

The same five stages, in one of two orders. You choose where the value lands first.

Agents first

Best when

You know which agents matter and need controls around them

Scoping (1 week)

Control design on 2–4 named agents (3 weeks)

Agent census and exposure map (2 weeks)

Tiering extended across the estate (2 weeks)

Framework design and hand over (4 weeks)

Total

12 weeks

Checkpoint

After control design. Fixed fee, complete in itself.

Estate first

Best when

You cannot list the agents you are running

Scoping (1 week)

Agent census and exposure map (2 weeks)

Tiering and control design, estate-wide (3 weeks)

Framework and pilot (3 weeks)

Operationalise and hand over (2 weeks)

Total

11 weeks

Checkpoint

After the census. Fixed fee, complete in itself

We write the framework last. Writing it first would describe an organisation that does not exist.

 

Either path can stop at its first milestone. Neither commits you to the rest.

What it is built on

We do not start from a blank page, and we do not adopt a single framework.

The IMDA Model AI Governance Framework for Agentic AI provides the structure; today, it's the only mainstream framework built for agents rather than models. The OWASP Agentic Security Initiative provides the threat and control layer. Five Eyes guidance on agentic AI informs blast-radius and least-privilege design. NIST AI RMF and ISO/IEC 42001 are held as a mapping layer, so future audit and procurement questions are answered from work already done.

On ISO/IEC 42001. Certification can be a later step, and a cheaper one once the registry, tiers, and control catalogue exist. We do not deliver a management system when what is needed is a set of working guardrails.

Start small

Both paths have a natural stopping point three to four weeks in, at a fixed fee, complete in itself.

What we need from you

Confirmed in Phase 0. Where any of these is missing, we say so before the engagement starts rather than discovering it in week six:

  • Executive owner. A named sponsor with budget authority.

  • Engineering counterpart. A named person who can change the platform. Without this, the engagement produces documents rather than controls.

  • Access. Repositories, model provider consoles, identity systems and logging, sufficient to verify the agent inventory rather than rely on what is reported.
  • Interview time. Around twelve sessions of forty-five minutes.

  • An existing change process. The intake workflow attaches to it.

Confidence to act. Clarity to decide.

 

Get a clear view of the agents you are running, and what it would take to govern them.

bottom of page