
Kurt FischmanFounder, Marshal
Kurt is the CEO of Marshal, the Managed Agent Operations company.

AI agent governance is the written rules and the runtime controls that together decide what an AI agent may do on its own, what it must stop and ask permission for, and who answers when it gets something wrong. A governance policy template turns those rules into clauses with numbers in them: autonomy ceilings, named data sources, approved tools, approval triggers, and a retention period.
An AI agent governance policy template is a document with numbers in it: dollar ceilings, named systems, named tools, one named approver, and a retention period. An AI agent, for the purposes of that document, is software that does not merely answer a question but takes an action inside a live system. It writes to your CRM, sends the email, issues the refund, moves the record. That one difference is the whole reason a policy exists. A chatbot that says something wrong embarrasses you. An agent that does something wrong has already done it.
Four sources at the top of this search result converge on the same definition, which is unusual enough to be worth noticing. Google's AI Overview calls AI agent governance a matter of runtime controls, identity boundaries, and explicit oversight, where a runtime control means a rule the software checks at the instant the agent tries to act rather than in a review three weeks later. Perplexity, asked the same question that day, returned five areas: authorization, identity and access, monitoring, data governance, and lifecycle. Microsoft's cloud adoption framework lists four policy domains, Dataiku lists five components, and no two of the lists use the same nouns.
Strip the branding off all four and you get one sentence. Write down what the agent may do, wire those rules into the system so they hold at the moment of action, log every action it takes, and put one human's name on the outcome. A framework tells you which of those things to have. A policy is the thing itself, and the difference matters because only one of the two can be signed. Marshal keeps the enforcement half of this on its agent governance surface. The clauses further down are the paper half.
Marshal read the top of that result page on August 30, 2026: across the AI Overview, the page-one organic results, and the three guides worth scraping, exactly one sentence of paste-ready policy language existed, and it was Dataiku's bracketed boundary statement. Published three days before that probe, it reads: "[Agent name] is authorized to [permitted actions] using [permitted data sources] within [permitted systems]. It is prohibited from [restricted actions]. Decisions involving [escalation criteria] require human approval before execution."
Dataiku's clause is a good sentence and also the only one of its kind in the pool, and it sits inside a guide whose headline deliverable is a ten-item deployment gate about registries, sign-offs, and drift baselines. The rest of the pool runs the same substitution. Zenity's page is titled a governance checklist for enterprise CISOs and its ten items are instructions to a security department: map every agent, accept that you will run many agent platforms, track every integration surface. Microsoft's governance and security baseline, updated June 26, 2026, is four policy domains and roughly forty best-practice verbs. The Microsoft AI Agent Governance Toolkit repository on GitHub ranks on the first page too, and it ships policy-enforcement code rather than policy text. All three are competent. None of them contains a clause.
The gap that leaves is measurable, and the same guide measures it. A Dataiku and Harris Poll survey of more than 800 global data leaders found only five percent say AI output is traceable 100 percent of the time, and 55 percent fear agents could expose sensitive data to unauthorized parties. McKinsey's State of AI survey, quoted in the same place, puts 62 percent of organizations at least experimenting with agents against 23 percent that report scaling one. Dataiku's diagnosis is blunter than the category usually prints: governance programs fail at enforcement, because companies draft the checklist and the agents ship anyway, since nothing existed to stop them. Zenity says the short version. Logging alone is not governance.
Governance advice in this category is addressed to ten different people, and a $3M business employs one of them. Count the roles the published pool hands governance to: the CISO, the CIO, security architecture, identity governance, the cloud and SaaS platform teams, an AI enablement group, an AI governance committee, the agent owner, a compliance lead, and a business sponsor. Zenity spreads operational ownership across five functions. Dataiku's deployment decision requires three separate signatures before an agent reaches production. Microsoft's advice is to assign agent governance to the same leaders who already run cloud governance, security, and compliance, which quietly assumes those leaders exist.
A $1M-$10M business has no such leaders. The founder is the compliance lead, the business sponsor, the agent owner, and the person who notices the invoice looks wrong. Copy an enterprise policy into that structure and every approval clause routes back to one signature, which is arithmetically the same as having no approval clause at all. The document survives an audit and stops nothing.
A governance policy written for a business with one approver has to replace separation of duties with reversibility, because the person who authorizes the action is the same person who would have to catch the mistake. Large companies buy safety with friction between departments. You cannot buy that, and faking it with a fictional review committee is worse than admitting it. What you can buy is the guarantee that anything the agent does without asking can be undone before Friday.
We published the framework side of this in June 2026, and the thing a framework cannot do is the thing a policy has to do: put a number in a clause and hand it to one person to sign. If you want the reasoning before the paperwork, start with the governance framework for a business without a CISO.
Reversibility is the one field in an agent policy a founder can score alone, with no security team and no lawyer in the room. Ask a single question about any action the agent might take. If it goes wrong, how hard is it to put back? Three answers exist. Reversible in a day means a record gets corrected, a draft gets deleted, an internal message gets retracted, and nobody outside the company ever knew. Reversible with effort means a customer already received something and a human now has to apologize. Irreversible means money left the building, data left the building, or a contract exists.
That score sets the autonomy ceiling. Autonomy here is not a personality trait, it is a permission: the list of things the agent completes without stopping to ask. Score the action, attach the ceiling, and the rest of the policy hangs off that one decision rather than off anyone's job title.
Three reversibility classes, and the controls a single-approver business attaches to each one, from the autonomy ceiling down to how long the log is kept.
| Control | Reversible in a day | Reversible with effort | Irreversible |
|---|---|---|---|
| Example action | Updates a CRM field or drafts an internal reply | Emails a customer or issues a small credit | Sends money, signs, deletes, or changes a price |
| Autonomy ceiling | Agent works alone up to the stated volume cap | Agent works alone below the stated dollar cap | Agent never acts alone, with no exceptions |
| Approval | None needed, reviewed in batch afterwards | Named approver signs the same business day | Named approver signs before the action runs |
| Monitoring duty | Weekly sample of the action log | Daily review of the exception queue | Every instance reviewed and countersigned |
| Log retention | Ninety days | One year | Seven years or the contract term |
Reversibility does the job an org chart does in a large company. It decides how much rope the agent gets when nobody senior is in the room.
Borderline actions exist, and arguing about them is a waste of an afternoon: route them instead. Anything you cannot classify in ten seconds goes to the exception queue, which is a list the agent writes to when a rule stops it. Skip the queue and you end up with a policy that only covers the easy cases, and the easy cases were never the problem.
Nine clauses cover what this policy has to govern: autonomy, data access, tools, approvals, and monitoring, plus the four fields that make the first five enforceable. Fill every bracket before the policy means anything. Keep the whole thing on one page, because the founder who enforces it is the same person who has to read it.
Nine filled brackets per agent, one page, one signature. Use the list as its own checklist, with a rule that survives no argument: every clause has to contain a name, a number, or a date. A clause with none of the three is a sentiment, and sentiments do not stop an agent from wiring money. Store the signed page wherever your insurance certificates live, because that is the drawer someone opens on the bad day.
A nine-clause policy fails in three specific places, and naming them costs less than discovering them. First, paper does not enforce itself. A clause becomes real only when a system refuses the action, which means the dollar ceiling in clause 2 has to exist as a hard limit in the agent's permissions and not only in the document. Zenity and Dataiku both land on this, and it is how a governance program turns decorative.
Second, no clause survives prompt injection. An agent reads text from outside your company, an email, a web page, an attached invoice, and it cannot reliably separate instructions from information, so hostile text hidden in that input can redirect what the agent does next. Your policy does not fix that flaw. Narrow scope and a low ceiling limit what the flaw can cost, which is why scoring each workflow before you deploy it matters more than the wording of any clause. Marshal's risk assessment framework is the scoring step that belongs upstream of this document.
Third, scope creeps one exception at a time. Dataiku names the pattern precisely: agents accumulate authority beyond their original boundaries as edge cases prompt additional permission grants. Every widening feels reasonable in the moment, and eighteen months of reasonable moments produces an agent nobody scoped. Clause 9 exists for exactly that, and it works only if the review date sits in a calendar rather than in a document. Governance is not the paperwork. Governance is the paperwork plus somebody who reads the log.
AI agent governance controls what a system does, while model governance evaluates what a system says. Dataiku draws the same line: a model produces an output a human then acts on, and an agent produces a change of state in the world directly. Your existing model policy can stay as it is. Your agent policy needs the autonomy ceiling, the named approver, and the kill switch, because no human stands between the output and the consequence.
An AI agent governance tool earns its price at the point where you can no longer read the log yourself. Below that point the enforcement lives in the agent's own permissions: a named account, a short approved-tool list, and a hard stop above your dollar cap. Vendors ranking for this term sell central registries and real-time interception built for fleets of agents, which is a genuine problem at fifty agents and an expensive answer at two.
An AI agent governance framework names the categories of control you ought to have, and a policy states your actual limits inside those categories. "Maintain an agent registry" is framework language. "Every agent operates under its own named account, and the owner approves any change to its data access in writing" is policy language. Reports such as the Institute for AI Policy and Strategy paper AI Agent Governance: A Field Guide help you decide what to worry about, and they are not the document you sign.
The founder signs it, and the single signature is a feature rather than a gap. One name in the approver field slows an enterprise down and speeds a $4M company up, because escalation costs no meetings. Delegate the monitoring duty in clause 7 if you have someone to delegate it to, then keep the approval in clause 6 and the kill switch in clause 8. Handing those two to anyone else makes the policy unenforceable.
Reimagine your business with Marshal on the team.