Governance & Trust

2026

Principles and Operating Model

A practical governance foundation for agent ownership, policy, lifecycle control and independent challenge.

The mesh needs one coherent governance model, even when its agents are developed by different teams and use different technologies.

Core principles

  • Accountability stays human. Every outcome, decision and accepted risk has a named owner.
  • Authority is least-privilege. Access and action rights match the defined task.
  • Evidence travels with the output. Material conclusions retain sources, versions and limitations.
  • Autonomy is earned. It increases through demonstrated performance and effective controls.
  • Controls are risk-based. Higher impact and lower reversibility require stronger approval and monitoring.
  • Separation of duties applies. Creation, approval, execution and assurance should not collapse into one unchallenged agent path.
  • Failure is assumed. Override, rollback, containment and learning are designed before operation.

Three lines of responsibility

The first line owns the agent and its operational outcomes. This includes transformation product owners, workstream owners and platform teams.

The second line defines policy and provides challenge: AI governance, information security, data privacy, enterprise architecture, risk and internal controls.

The third line provides independent assurance where required. Internal audit or an equivalent function evaluates whether governance and controls work in practice.

This structure should adapt to the organization. The important point is that an agent should not be its own owner, risk authority and independent assessor.

Lifecycle governance

Each agent passes through defined states: concept, design, evaluation, pilot, approved operation, material change, suspension and retirement. Entry and exit criteria should reflect the risk class.

An inventory records purpose, owner, model, skills, tools, data, permissions, evaluations, incidents and current status. Without an inventory, governance quickly becomes presentation rather than control.

Governance close to the work

Central standards are necessary, but every policy cannot wait for a committee. The mesh should enforce routine controls automatically and route exceptions to the appropriate person. This keeps governance visible without making it a separate bureaucracy.