Governance and trust

AI agent governance: autonomy with controls attached

Governance for AI agents in finance and operations means every agent can be explained to your board, your auditor and your team.

Five levels of autonomy, chosen per decision

Before an agent is built, each decision it touches is assigned a level.

Level 1

Assist

The agent prepares material. A person does the work and makes every decision.

Position on the scale from person decides to agent decides within limits: 1 / 5

Who decides
The person, always.
What is logged
The request, the sources the agent consulted and the output shown to the person.
Typical use
Drafting a reply to a vendor, summarizing a contract, searching internal policy.

Controls designed in before production

Read our security practices
  • Access and data

    • Least privilege
    • Credentials in your vault
    • Data residency
  • Decision control

    • Human review thresholds
    • Escalation
    • Autonomy limits
  • Evidence

    • Audit trail per action
    • Versioned prompts and models
    • Evaluation sets
  • Operations

    • Monitoring
    • Drift and cost tracking
    • Incident runbook

What we will not do

  • Put an agent in production without an evaluation set.

  • Give an agent write access it does not need.

  • Hide an automated decision from the people accountable for it.

  • Let a prompt or model change reach production untested.

Frequently asked questions

How do you govern AI agents in finance and operations?

Each decision an agent touches is assigned one of five autonomy levels before the agent is built: assist, recommend, act with approval, act and report, or act within bounds. Before production the agent gets the controls described on this page: least-privilege access, an evaluation set of real cases, human review thresholds, an audit trail per action, pinned prompt and model versions and a kill switch. After go-live it is monitored and changed only through a test gate.

Do you hold ISO 27001, SOC 2 or ISO 42001 certifications?

No. We do not hold ISO 27001, SOC 2 or ISO 42001 certifications, and we do not claim to. What we do instead is design controls that support your own compliance program: we relate agent controls to the internal controls and audit evidence your team already uses, produce the logs, versions and approval records a reviewer asks for, and agree access, data handling and change control with you before go-live. Certifying your environment stays with your own auditors.

Who is accountable when an agent acts?

A named person, agreed before the agent is built. Each autonomy level says who decides: the person at Assist and Recommend, a named approver at Act with approval, and, at the two levels where the agent acts on its own, the process owner who set the limits and the people who review exceptions and samples. Every action is logged with its inputs, decision and versions, so owners can see what the agent decided and why.

How do model providers use our data?

Model providers are configured so your data is not used for training, subject to each provider's terms. The hosting region, data flows and approved subprocessors are documented and reflected in the agreement. Personal data is identified in design and minimized, masked or excluded before it reaches a model, where the process allows.

Start with one process and its controls

Bring one finance or operations process. We will discuss where an agent fits, what level of autonomy is appropriate and which controls it needs.