Skip to article
AI node network iconAI Venture X

AI agent governance / A practical framework

Five human decision gates for AI agents.

A practical way to define where an AI agent may prepare work, where a person must decide and what evidence should survive each decision.

What is AI agent governance?

AI agent governance defines who can decide what, which tools and data an agent may use, what evidence must be retained and how the organisation stops or recovers work when conditions change.

Effective governance is designed into the workflow. It separates preparation from permission, makes human decision points visible and prevents one approval from silently becoming authority for a different action.

The five decision gates

Each gate combines an interface signal, an evidence record and a recovery path. The control is incomplete if a reviewer cannot see the proposed action, if the decision is not recorded or if the workflow cannot recover safely.

Accept scope

Define the job and the authority granted.

Interface signal

Show the objective, permitted tools, data sources, limits and accountable owner before work starts.

Evidence record

Retain the scope snapshot, authority owner, expiry and exact permissions active for the run.

Recovery path

Stop and return for re-scoping when the goal, data or required permission changes.

Trust sources

Decide whether the evidence is sufficient.

Interface signal

Show sources, dates, conflicts, gaps and confidence before a conclusion is treated as decision-ready.

Evidence record

Retain citations, retrieval times, provenance, unresolved contradictions and reviewer judgement.

Recovery path

Quarantine the claim, research again or escalate uncertainty instead of silently filling a gap.

Commit money or terms

Reserve commercial authority for people.

Interface signal

Present the exact price, terms, counterparty and proposed commitment in one approval view.

Evidence record

Retain the proposal, named approver, decision, timestamp, expiry and material assumptions.

Recovery path

Return an expired or changed proposal for fresh approval; authority does not carry over implicitly.

Contact or publish

Control every external representation.

Interface signal

Show the exact message, destination, identity, attachment and timing before release.

Evidence record

Retain the approved payload and recipient plus the provider's sent, posted or submitted receipt.

Recovery path

When the outcome is ambiguous, reconcile provider state before retrying to avoid duplicates.

Release to production

Make the live change reversible and inspectable.

Interface signal

Present the validated change, affected surface, rollback and expected behaviour together.

Evidence record

Retain the approved checksum, test results, release identifier and verification of the live state.

Recovery path

Halt or roll back on drift or failed validation, then diagnose before another release.

Download the one-page decision-gates map

A printable A4 landscape reference covering the interface signal, evidence record and recovery path for all five gates.

Download the PDF ↗

How to use the framework

Start with the decision

Identify the consequence that matters, then place the approval before the tool call, commitment or publication that creates it.

Show the exact action

A reviewer should see the recipient, price, terms, data, destination or release candidate they are approving.

Bind approval to evidence

Record the approved payload, who decided, when it expires and which assumptions remain material.

Design reconciliation

When a result is unknown, inspect the destination before retrying. Recovery should avoid duplicate payments, messages or releases.

NIST's AI Risk Management Framework calls for human oversight processes, defined responsibilities and accountable risk decisions. OWASP's excessive-agency guidance recommends limiting permissions and requiring human approval for high-impact actions. The five gates turn those broad principles into an operating pattern for agentic workflows. [1] [2]

Evidence boundary

This is a practical first-party control model. It makes AI Venture X's proposed approach inspectable. It does not establish a client outcome, staffing reduction, quantified saving, production reliability, regulatory compliance or independent assurance result.

The accompanying public engineering reference demonstrates exact-action approval, expiry, revocation, tenant boundaries and lost-response recovery using a simulated agent and mock CRM. It is implementation evidence for those local controls, within its stated limits. [3]

Apply the gates to a real workflow

Bring one process, the outcome you need and the decisions that must remain under accountable human control. We can map the authority boundary, evidence and recovery design before implementation expands.

Discuss a governed agentic workflow

Start with a specific business process and the consequence that matters.

Book a 30-minute scoping call ↗

Sources and further reading

  1. NIST AI Risk Management Framework Core. Governance, responsibility and documented human oversight outcomes.
  2. OWASP, LLM06:2025 Excessive Agency. Guidance on functionality, permissions, autonomy and approval for high-impact actions.
  3. Enterprise Agentic AI: public Python reference. Runnable simulated examples with documented evidence limits.