Skip to main content
Once the structure is set, you decide how widely to open agent creation. There are two strategies, and the choice is yours.

Open to everyone

Anyone can create agents for themselves. Broad enablement, with controls so it does not turn into chaos. Detailed below.

Curated use cases

Only selected, prioritized use cases are built and rolled out. Tighter, slower, and easier to govern. Follow the use-case lifecycle for each.

Open without chaos

The open strategy works only with guardrails. The goal: let everyone experiment, but keep sharing, publishing, and sensitive data under control.
1

Default: create, do not share

Everyone can create agents for themselves, but no one can share or publish by default. This is enforced with tool permissions and sharing settings.
2

Train and raise awareness

Start with training and AI Act awareness. People govern themselves better when they understand the rules. See compliance.
3

Identify the agents that matter

Use Insights and Governe to spot the most used and most relevant agents. Internal committees select the AI champions who earn the right to share.
4

Validate compliance, then publish or share

When an agent proves relevant, the committee validates it against compliance criteria. Only then can it be published or shared to a group or the whole organization, through an access-validation workflow. See creating agents and join rules.
5

Publish common agents centrally

The central team can also publish common agents available to everyone, to the whole organization or to a restricted audience with an access-validation workflow.
6

Activate the guardrails

Committees validate the guardrails to activate. The platform team can force hooks (for example data controls based on classification) and set the runtime safeguards and guardrails required at platform or organization level.

The guardrail model: tighten downward, tightest wins

Every control in the workflow above rides on one model: governance is a cascade of envelopes. Each level can only tighten the one above, on conflict the tightest limit wins, and inside its own envelope each level distributes freely.
Governance as nested envelopes: platform plan, then organization, then agent, then the effective user limit. Each level can only tighten the one above, the tightest limit wins on conflict, and each level distributes freely within its envelope.
This is where the central controls live:
  • Models and tools: restrict which LLMs and tools an agent may call. See model governance and the capabilities catalog.
  • Hooks: force data controls based on classification. See hooks.
  • Data retention: cap how long conversations, documents, tasks, and artifacts are kept. See data retention.
  • Quotas: usage envelopes per organization, agent, and user.

Next steps

Who does what

The committees, champions, and squads behind these controls

Governe

The product that enforces all of the above