Open to everyone
Anyone can create agents for themselves. Broad enablement, with controls so it does not turn into chaos. Detailed below.
Curated use cases
Only selected, prioritized use cases are built and rolled out. Tighter, slower, and easier to govern. Follow the use-case lifecycle for each.
Open without chaos
The open strategy works only with guardrails. The goal: let everyone experiment, but keep sharing, publishing, and sensitive data under control.1
Default: create, do not share
Everyone can create agents for themselves, but no one can share or publish by default. This is enforced with tool permissions and sharing settings.
2
Train and raise awareness
Start with training and AI Act awareness. People govern themselves better when they understand the rules. See compliance.
3
4
Validate compliance, then publish or share
When an agent proves relevant, the committee validates it against compliance criteria. Only then can it be published or shared to a group or the whole organization, through an access-validation workflow. See creating agents and join rules.
5
Publish common agents centrally
The central team can also publish common agents available to everyone, to the whole organization or to a restricted audience with an access-validation workflow.
6
Activate the guardrails
Committees validate the guardrails to activate. The platform team can force hooks (for example data controls based on classification) and set the runtime safeguards and guardrails required at platform or organization level.
The guardrail model: tighten downward, tightest wins
Every control in the workflow above rides on one model: governance is a cascade of envelopes. Each level can only tighten the one above, on conflict the tightest limit wins, and inside its own envelope each level distributes freely.- Models and tools: restrict which LLMs and tools an agent may call. See model governance and the capabilities catalog.
- Hooks: force data controls based on classification. See hooks.
- Data retention: cap how long conversations, documents, tasks, and artifacts are kept. See data retention.
- Quotas: usage envelopes per organization, agent, and user.
Next steps
Who does what
The committees, champions, and squads behind these controls
Governe
The product that enforces all of the above