3.4 The governance layer that does not exist yet

Book 2 · The Delegation ContractChapter 3 · section 4 of 5

No system today manages the full lifecycle of delegation across system boundaries, and the easiest way to feel the gap is to imagine auditing one.

Walk into a company running Gas Town — the multi-agent coding system from the toolkit chapter — and try to answer a few questions. Could you find a record of what they were using it for? Who decided to use it? What permissions were granted, when, and on what date? Could you determine what operational decisions the agents made at four in the morning on a Saturday that resulted in a change to a production system? Could you trace who authorized those agents, what scope of authority they were given, and whether that authority was still valid at the moment the decision was made?

The answer is: not really. You can find Git worktrees, Beads state, and agent logs, and from those you can reconstruct what the agents did. What you cannot find is a delegation record saying who authorized this, under what conditions, for what duration, and with what mechanism for review or revocation — because the system does not create one.

A word before the Gas Town users write in, because I am not picking on Gas Town. Say the fair version of the objection out loud. It is a developer tool, the stakes are low, and demanding delegated-authority records and decision provenance for every action is overkill. That objection is correct as long as a strong safety envelope exists. When agents are confined to branches, isolated environments, least-privilege credentials, tests, review, and release gates, a coding agent that writes a bad function ends at a rejected pull request. Without that envelope the same agent can expose secrets, alter CI, or introduce a vulnerable dependency. Inside the envelope, the consequences stay in the development workflow, nobody gets hurt, nobody sues, and no regulator shows up. The development workflow comes with safety valves already installed — pull requests, code review, CI, testing, rollback — and those valves are the reason the missing governance layer is tolerable. The trouble is that these systems are not going to stay in the development workflow. There is no pull request for a decision about rerouting a medical supply chain. There is no code review for a real-time decision to throttle power to a substation. There is no CI pipeline that catches a bad decision about approving or denying a loan application.

To be fair to the current tools, they do have governance-adjacent features. Gas Town has Beads preserving structured work state, plus Witnesses and a Deacon monitoring agents. LangGraph has checkpointing and human-in-the-loop approval gates. CrewAI Enterprise has added compliance logging and audit trails, and Microsoft Agent Framework has telemetry and session management. All of that exists and all of it is useful.

None of it is a governance layer. What those features provide is internal observability — logs, traces, state checkpoints, health checks — which tells you what the system did without telling you whether it was authorized to do it, who authorized it, under what authority, with what review, and with what mechanism for revocation. When a regulator asks who delegated this decision and when that delegation was last reviewed, “check the Beads database” is not an answer.

Authority is the answer to: who allowed this system to act, and in what range? A delegation record for authority would name the person or role that granted permission, the specific actions permitted, the resources those actions may touch, the conditions under which the grant is valid, and how it can be revoked.

Provenance is the answer to: why did it do that? A provenance record for a decision would capture what information the system had at the moment of the decision, what alternatives it considered, what evidence supported the choice, and who reviewed it. Current systems produce logs and traces, which are debug artifacts; a governance-grade provenance record would be structured, queryable, and retained according to policy rather than according to log rotation.

Lifecycle is the answer to: is that grant still valid? Authority is not granted once; it is granted, reviewed, reaffirmed, modified, and sometimes revoked. A lifecycle system would track that arc from initial authorization through periodic review to revocation, because permissions set at deployment time and forgotten are survivable in a coding workflow and not survivable where delegated intelligence manages power grids and medical logistics.

Medicine has already built a version of this for device software. The FDA’s predetermined change control plan, finalized in December 2024, lets a manufacturer specify in its marketing submission which modifications it may make to an AI-enabled device, the methods it will use to develop and validate them, and its assessment of the benefits and risks; modifications inside the approved plan can be implemented without a new submission, and anything outside the plan requires one.45 That is reconfirmation designed in from the start — authority granted in advance for a defined envelope of change, with the burden of new approval placed on exactly what falls outside it.

Two more needs have no tidy product name. Audit and review infrastructure means a third party — a regulator, an auditor, a citizen, a patient — can ask to see the decision chain for a specific action and receive a clear, human-readable answer rather than a dump of API calls. Governance-grade evaluation means measuring whether the system made the right decision, not just whether the model produced the right output — whether the change was authorized, evidence-based, and safe to deploy, which is a different question from whether it compiles.

One exception to the low-stakes picture is already visible. Copyright disputes over AI training inputs and AI-generated code are in the courts now, and future cases may make run-time lineage — the prompt, the retrieved context, the tool inputs, the model and version, the generated output, the human who accepted it — into discovery evidence.46 When that happens, the questions become legal questions, and the split that matters is this: run-time lineage is what the operator controls and can preserve; training-data provenance is usually the model vendor’s record, not the operator’s. An orchestrator should preserve what the system controls and contract explicitly for the evidence it must obtain from vendors. Current tools do not record either half.

The market now offers important pieces of the governance layer: the agent-identity and policy products surveyed in the toolkit chapter and the trace platforms Chapter 8 names, plus agent registries, evaluation, lifecycle controls, and enterprise control towers such as the one ServiceNow sells for AI agents an organization did not build.47 The gap is no longer absence — it is fragmentation. September 2026 added a piece with unusual weight: NVIDIA’s Open Agent Safety Platform, launched with more than a hundred partners, puts a verified policy boundary and an out-of-band enforcement layer beneath the agent itself — the first time envelope enforcement has arrived as silicon-backed infrastructure rather than as each team’s hand-assembled sandbox.[^ch07_oasp] It is real progress on the credential half of the envelope, and it is not yet a governance layer: the launch ships enforcement and audit, but the delegation record — who granted what, reviewed when, revocable how — remains the operator’s to build, and authority still does not travel between organizations, which is Chapter 17’s subject. The table below shows the pieces that exist and the part of each that is still open — capabilities for governing agents are arriving, but the authority and the evidence do not travel cleanly when work crosses vendors, runtimes, organizations, or protocol boundaries:

Control need Current examples What remains open
Agent identity and lifecycle Microsoft Entra Agent ID; Google Agent Identity; AWS AgentCore Identity Portable identity and lifecycle semantics across vendors, organizations, and runtimes
Authorization and policy Entra access governance; Google IAM / Agent Gateway; AgentCore Policy; OPA; Cedar A task-bound delegation object with attenuation, expiry, budget, revocation, and downstream proof
Runtime evidence Langfuse; Phoenix; OpenTelemetry; platform observability A common evidence schema, retention policy, integrity guarantees, and correlation across system boundaries
Evaluation Inspect AI; platform evaluation services; agent-framework eval tools Connection from measured behavior to release gates, risk acceptance, control owners, and accountable decisions
Durable work state Temporal; Restate; LangGraph; platform runtimes Portable work identity, migration, replay semantics, and lifecycle control across execution engines
Enterprise inventory and governance ServiceNow AI Control Tower; Microsoft, Google, and AWS platform consoles Vendor-neutral inventory and governance across third-party agents, models, tools, and protocols

3.4.1 The operational layer carries the audit burden

There is an important asymmetry underneath all of this. The operational layer — the part running in production, making real-time decisions, touching live data and live customers — carries far heavier audit and regulatory requirements than the development phase does.

The reason needs stating carefully, because a human is not an audit trail either. Human decisions are attributable through organizational identity and the records around them: approvals, messages, meeting notes, transaction logs, and testimony. An investigator connects those records to a responsible principal. A system decision needs the machine equivalent — identity, inputs, retrieved evidence, model and policy versions, tool calls, approvals, state transitions, outputs, and the controls that allowed or stopped the action — and when a system produces none of that, there is no principal to depose and no record to subpoena. A system that cannot produce a record of its decision has made an unauditable decision, which means that as more decisions move into systems, more decisions become unauditable unless somebody builds the infrastructure to audit them. And the operational layer does not carry the whole record even in regulated industries today — financial model-risk guidance, medical-device oversight, the NIST AI Risk Management Framework, and the EU AI Act all require evidence from design, validation, change management, and post-market monitoring as well.48 Operations carries the most immediate burden because it produces the live decisions and the consequences; the defensible system connects build-time lineage to run-time decisions.

3.4.2 When the system must hand the decision to a human

If a system is operating itself and it is about to make a decision that could have an impact on a human life, the system has to know to stop and bring the decision to a person. The mechanism for that exists and ships today, and it is worth being precise about which half of it still has to be designed by hand.

Half of that requirement is already written into law. The EU AI Act’s oversight requirements for high-risk systems — due originally in August 2026, and deferred to December 2027 for most high-risk systems by the 2026 Digital Omnibus amendment — state that the people assigned to oversee a system must be able, in the regulation’s words, to “disregard, override or reverse the output” of the system, and to “interrupt the system through a ‘stop’ button or a similar procedure that allows the system to come to a halt in a safe state.”49 The law gives the human the right to grab the controls.

The other half — the part that fires before a person knows there is something to grab — is the automatic trigger, and here the industry has real, shipping examples worth studying. Amazon shipped one in 2020: Amazon Augmented AI lets a developer set a confidence threshold, and “predictions below that threshold” are routed to human reviewers automatically.50 Salesforce’s Agentforce escalates a conversation to a human agent when its confidence thresholds are not met or a customer asks for a person.51 Hermes Agent checks every terminal command against a curated list of dangerous patterns, and uncertain cases “escalate to a manual prompt” rather than executing — with a circuit breaker that halts an agent that keeps retrying a denied command.52 Claude Code’s permission system does the same shape of work with explicit rules, evaluating deny rules first, then ask rules, then allow rules.

So the honest state of the art is narrower than “the mechanism does not exist.” The mechanism — detect a condition, pause, surface the decision to a person — is shipped and boring. What those shipping triggers have in common is the condition they detect: the model’s own uncertainty (a low confidence score), or a pattern match on the command. What none of them computes is the consequence of the decision itself. A2I escalates when the model is unsure; it has no way to ask “this prediction looks clean, but does it touch a human life?” An agent can be confidently wrong about a routing that delays care, and every uncertainty gate in this paragraph will wave it through. That is the missing half, stated precisely: not the gate, but the trigger that fires on the class of decision — a routing that delays care, a shutoff that removes power, an approval that withholds money — regardless of how confident the system feels. Defining which decisions count, and attaching the shipped gate mechanism to that consequence-based trigger, is part of the orchestrator’s job today.


  1. U.S. Food and Drug Administration, “Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions,” final guidance issued December 4, 2024, https://www.fda.gov/media/166704/download. A PCCP comprises a Description of Modifications, a Modification Protocol, and an Impact Assessment; modifications covered by an approved plan “can be implemented without a new marketing submission,” while changes outside the plan require a new submission.↩︎

  2. Copyright disputes over AI training and generated code include Doe v. GitHub (N.D. Cal., docket at https://www.courtlistener.com/docket/65695606/doe-1-v-github-inc/); U.S. Copyright Office, “Copyright and Artificial Intelligence,” https://www.copyright.gov/ai/ (verified August 29, 2026). These establish that training-input and generated-code litigation exists; the claim that run-time lineage will become discovery evidence is this book’s forecast, and the distinction between operator-controlled run-time lineage and vendor-controlled training provenance is the point of the passage.↩︎

  3. Microsoft Entra Agent ID governance overview, https://learn.microsoft.com/en-us/entra/id-governance/agent-id-governance-overview; Google Agent Identity, https://docs.cloud.google.com/gemini-enterprise-agent-platform/govern/agent-identity-overview; AWS Bedrock AgentCore, https://aws.amazon.com/bedrock/agentcore/; ServiceNow AI Control Tower, https://www.servicenow.com/products/ai-control-tower.html. All verified August 29, 2026. Vendor documentation establishes documented capability, not cross-vendor portability or independent adoption — which is precisely the gap the text claims.↩︎

  4. NIST AI Risk Management Framework, https://www.nist.gov/itl/ai-risk-management-framework (govern, map, measure, manage functions spanning design through deployment and monitoring); Federal Reserve SR 26-2 on model risk management, https://www.federalreserve.gov/supervisionreg/srletters/SR2602.htm (development, validation, and ongoing governance of models); FDA, artificial intelligence-enabled medical devices, https://www.fda.gov/medical-devices/software-medical-device-samd/artificial-intelligence-software-medical-device (design, validation, and post-market monitoring); EU AI Act consolidated text, https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02024R1689-20260727 (lifecycle obligations for higher-risk systems). All verified August 29, 2026.↩︎

  5. EU AI Act, Regulation (EU) 2024/1689, Article 14(4)(d)–(e), https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng. Oversight personnel must be able to disregard, override, reverse, intervene in, or safely stop a high-risk system. Regulation (EU) 2026/1744 deferred Annex III obligations to December 2, 2027 and Annex I product-embedded obligations to August 2, 2028.↩︎

  6. Amazon Augmented AI (A2I), generally available April 2020: AWS press release, “AWS Announces General Availability of Amazon Augmented Artificial Intelligence (A2I),” April 24, 2020, https://press.aboutamazon.com/2020/4/aws-announces-general-availability-of-amazon-augmented-artificial-intelligence-a2i (“After setting a confidence threshold for model predictions, developers can choose to have predictions below that threshold reviewed” by human reviewers); Amazon SageMaker AI documentation, “Using Amazon Augmented AI for Human Review,” https://docs.aws.amazon.com/sagemaker/latest/dg/a2i-use-augmented-ai-a2i-human-review-loops.html (“allow human reviewers to step in when a model is unable to make a high-confidence prediction”). A2I is no longer open to new customers; the pattern it pioneered — threshold-triggered human review — is now standard across the industry.↩︎

  7. Salesforce Agentforce escalation: the pre-built Escalation topic hands a conversation off to human agents via Omni-Channel routing, triggered by confidence thresholds not being met or a customer explicitly requesting a person. See https://www.salesforce.com/agentforce (“handling service issues proactively within set guardrails… escalate to human agents”) and https://www.salesforce.com/blog/agent-handoff (“escalation is treated as a standard, automatic action triggered at the topic level”).↩︎

  8. Hermes Agent dangerous-command approval: “Before executing any command, Hermes checks it against a curated list of dangerous patterns. If a match is found, the user must explicitly approve it,” with smart mode using an auxiliary model to score risk and “uncertain cases escalate to a manual prompt,” plus a denial circuit breaker (approvals.denial_breaker_threshold, default 3) that hard-stops an agent after repeated denials. Hermes Agent documentation, “Security,” https://hermes-agent.nousresearch.com/docs/user-guide/security, and “Configuration,” https://hermes-agent.nousresearch.com/docs/user-guide/configuration.↩︎