
Kurt FischmanFounder, Marshal
Kurt is the CEO of Marshal, the Managed Agent Operations company.

An AI agent governance committee charter is the one page that names who decides what about the AI agents a business runs: the seats, the rights each seat holds, the money and reversibility ceilings that force a human signature, and the interval at which somebody rereads the log. A governance framework lists controls. A charter assigns signatures.
Google's first page for AI agent governance describes controls in exhaustive detail and dates almost none of them. An AI agent, for this purpose, is software that takes actions inside your real systems: it updates the CRM record, sends the follow up, issues the refund, moves the money. Governance is the set of rules and controls deciding which of those actions it may take, and who answers for the ones it takes badly.
A probe on August 30, 2026 pulled the top twenty results for that phrase and read the three deepest pages end to end: Microsoft's cloud adoption guidance for governing agents, updated June 26, 2026; Kovrr's enterprise guide, August 4, 2026; and Zenity's ten step checklist for security chiefs, March 12, 2026. They agree on nearly everything. Inventory every agent. Give each one its own identity. Scope permissions tightly. Log every action. Keep a human in the loop, meaning a person approves before the agent acts, on anything consequential.
Then the counting gets awkward. Across the three deepest pages in that pool, 9,428 words from Microsoft, Kovrr, and Zenity, the words regular, continuous, periodic, and ongoing appear 27 times and a named review interval appears zero times. Not one weekly, monthly, or quarterly. The phrase decision rights appears exactly once in those 9,428 words, in Microsoft's line that central ownership "requires clear decision rights," followed by no list of what the rights are. The word charter appears once, inside a link to a different article. Seats, quorum, standing agenda, minutes: zero. Of the nineteen organic results on that page, not one mentions a committee, a charter, or a cadence in its title or description.
Neither source is wrong; both write for a company you do not run. Microsoft writes for a company that already has a cloud governance forum on the calendar, and Kovrr writes for a company that already has an audit committee. Run a $1M-$10M business and you have neither, so the controls list hands you homework with no due date. The controls are the framework, and the governance framework for a business without a CISO covers that half. Missing is the page that says who signs.
A governance committee is five seats before it is five people, and a company doing $4M in revenue fills all five with three. Seats are jobs, not headcount. Write the five jobs into the charter, then pencil names beside them, and the only structural rule is that every job has a person and no job has two.
Hat math for a real company: the founder takes chair and money, the operations lead takes operator and access, and accountable owner rotates to whoever's workflow the agent runs inside. Three people, five seats, and nobody sitting on a committee of one. One pairing stays forbidden. The accountable owner and the access seat are never the same person for the same agent, because that pairing lets one person widen an agent's reach and approve the widening in the same afternoon. Marshal's agent governance work is mostly this: seats, ceilings, and a log that proves both.
Decision rights are the whole content of a charter, and six of them cover an agent program at this size. A decision right is one sentence naming who may say yes, who has to be asked first, and how fast the answer has to arrive. Published charter language tends to hand all six to the committee, which is how governance becomes a queue of things waiting for Thursday.
The six decision rights an agent program needs, the seat that holds each one, and the clock each one runs on.
| Decision | Who says yes | Who is consulted | When |
|---|---|---|---|
| Set the ceilings | Committee, simple majority of filled seats | Accountable owner for each live agent | Quarterly, and on any change of scope |
| Launch a new agent | Accountable owner for that one agent | Access seat and the chair | Before the first live run |
| Clear one exception | Operator on duty that week | Nobody, while it stays under the hard cap | Same day, or it expires |
| Connect a tool or data source | Access seat, in writing | Accountable owner for the affected agent | Before connection, never retrofitted |
| Pause or revoke an agent | Any seat, acting alone, no quorum | Nobody first; tell the chair after | Immediately, and the pause holds |
| Read the log | Chair, out loud, with the log open | Whole committee plus the operator | Monthly, as agenda item one |
Notice where the committee does not appear: launching an agent and clearing a single exception each belong to one named person, on the clock the work actually runs on.
Two of those rights do not belong in a meeting. Per-deployment approval belongs to the named owner, because a committee approving each launch duplicates the accountability it just assigned and adds a week to every release. Microsoft's guidance arrives at the same place from the other direction: assign agent oversight to the leaders who already own cloud governance, and avoid building a parallel governance model beside it. Exception clearing belongs to the operator on duty, because the queue moves in hours and a committee moves in weeks. What the committee keeps is the work a group can actually do well: set the ceilings, read the log, hear the pattern in the exceptions, and revoke.
Review cadence keys to what an agent can break, not to the shape of your quarter. Blast radius is the plain version of that: how much damage the worst plausible action does, and how hard it is to undo. Score the workflow before you schedule anything, which is what the risk assessment framework is for, then take the interval from the tier the score lands in.
Tier one covers read-only work. The agent drafts, summarizes, and routes, and a person sends everything that leaves the building. Read the log monthly, fifteen minutes, and reset ceilings twice a year. No standing meeting.
Tier two writes to internal systems and every write is reversible. The agent updates records, opens tickets, books time. Clear exceptions weekly, read the log monthly with the operator in the room, and reset ceilings quarterly.
Tier three touches money, customers, or anything you cannot unwind. Twenty minutes weekly with the log open, ceilings reviewed monthly, and every exception recorded with the name of whoever approved it. This tier is also where the interval belongs in writing, because verbal cadence is the first thing to slip in a busy quarter.
Then there are the triggers, which override the calendar. Any one of these pulls the next review into this week:
Calendars handle the boring case. The trigger list is what stops a quarterly cadence from becoming a story you tell yourself about oversight.
An AI agent governance committee charter fits on one page, and eleven lines carry all of it. Marshal publishes the charter the August 2026 answer pool skips: five named seats, six decision rights, and a review interval keyed to a dollar ceiling rather than a quarter. Copy the lines, fill the blanks, sign it. A blank means not approved.
Clause language belongs in a separate document, and the paste-ready version of that sits in the policy template. A charter is the shorter thing: the page saying the ceiling is $500, the approver is the operations lead, and the log gets read the first Monday of the month. We operate Managed Agent Operations for founder-led companies, so our agents work inside ceilings a client has already approved, and the charter is where those ceilings get written down.
A charter cannot supervise anything. Signing one is a set of commitments, and commitments decay in five ways worth knowing before you sign.
First, a charter without a log is theater. If nobody can pull a list of what the agents did last week, every line about ceilings is unenforceable and everybody knows it by month two. Second, a committee that meets to approve individual actions has become the bottleneck the agent was bought to remove, and the business routes around it fast. Third, one person holding all five seats is a diary rather than a charter, so two readers is the practical minimum, which often means the outside bookkeeper or IT provider takes a seat. Fourth, regulated work needs more than a page: Kovrr's guide names the EU AI Act, the NIST AI Risk Management Framework, and ISO/IEC 42001 as regimes that apply to agent deployments, and each wants documentation this charter only points at. Fifth, governance caps the damage an agent does; it never improves the work the agent produces.
A charter earns its page the day an agent can spend money, message a customer, or change a record you would have to explain to somebody. Before that day, line 1 and line 8 cover you honestly. After it, the answer pool will still be advising you to review agent behavior regularly, and you will still be the person who has to pick the day.
A framework and a charter answer different questions. The framework lists the controls: inventory, identity, scoped permissions, guardrails, logging, which is what Microsoft's cloud adoption guidance and the category's field guides publish. The charter names the people holding those controls and the dates they check them. Most businesses read four frameworks and never write the one page that makes any of them operable.
An AI agent governance tool is optional below roughly ten agents. A shared document, your existing ticket queue, and an exported log will run this charter for a $1M-$10M business. Buy a platform when the log stops being readable by a person, not when a vendor announces the category.
One agent triggers the charter if it can spend money or talk to customers. Below that line the practical trigger is three or four agents, because that is the point where nobody remembers who approved what. Seat count does not move with agent count; the review interval does.
The founder chairs it, and hands the seat only to someone able to say no to a revenue team. A chief information security officer is the enterprise answer, and most $1M-$10M businesses do not employ one. The chair owns the agenda, the ceilings, and reading the log, not the technical work.
Reimagine your business with Marshal on the team.