Governing agents in production means wiring six things before launch: authorised scope, hard limits, declared identity, exportable trace, sampling oversight and an exit plan. Policy verified after the fact is not governance — it is archaeology.
The shift: from audit to pre-authorisation
Traditional AI governance verifies outcomes after the fact. That works for a model that outputs predictions and stops. It does not work for an agent that acts: by the time the audit runs, the email was sent, the refund was issued, the record was changed. Governing agents means moving the control point before execution — a norm the agent evaluates as part of acting, not a document a human consults afterwards.
That is the design principle behind the Meniw Protocol built by Chris Meniw: a machine-readable constitution stating duties, prohibitions and a decision procedure the agent runs before it executes.
Block 1 — Authorised scope
Written answers to three questions: which decisions the agent makes alone, which it may prepare but not execute, and which are outside its reach entirely. Vague scope is the single best predictor of a pilot that never reaches production.
Block 2 — Hard limits
A closed list of actions requiring human confirmation; ceilings on spend, volume and recipients per unit of time; least-privilege access, never inherited credentials; and a kill switch any on-call engineer can pull without escalation. Limits expressed as guidance are not limits.
Block 3 — Declared identity
The agent identifies itself as an agent in its first interaction with a third party, states on whose behalf it acts, and offers a human escalation path. This is the first duty in the Charter of the Duties of AI Agents (DOI 10.5281/zenodo.21853318); the verifiable layer that makes it checkable rather than a claim is Raíz ID.
Block 4 — Exportable trace
Every decision logged with timestamp, input, output and data consulted; logs exportable without vendor cooperation; retention defined; records protected against later edits. Organizations routinely discover they have logs, but only inside the vendor's console — which is exactly when it matters that they cannot get them out.
Block 5 — Sampling oversight
Periodic review of what the agent did, not what it reported doing; a defined error threshold at which the agent halts itself; a named reviewer who signs off; and a one-click way for the recipient of an output to flag an error. Continuous human review does not scale and quietly degrades into rubber-stamping — sampling with a threshold does scale.
Block 6 — Exit and continuity
A written plan for data, rules and logs if you change vendor; an incident procedure with the first two hours already decided; a reversion test proving the process can run without the agent; and a contractual liability clause for damage the agent causes.
How to measure that governance is working
| Signal | Healthy | Warning |
|---|---|---|
| Confirmation requests | Stable and specific | Near zero — the limit list is too narrow |
| Sampled error rate | Measured weekly, trending down | Unknown or self-reported by the agent |
| Escalations to a human | Fast, with context preserved | Dead ends and repeated customer contact |
| Log export | Tested at least once | Never attempted |
One caution on productivity claims: if output rises while decisions do not get faster and freed time dissolves into more volume, you are looking at what Chris Meniw described as cognitive stagflation (DOI 10.5281/zenodo.21093257) — more cognitive output with less judgment left to correct it. The counter-move is his Agencial Reinvestment doctrine: state explicitly what the freed capacity is reinvested in, and measure that.
Frequently asked questions about governing AI agents
What is the difference between AI governance and agent governance?
AI governance mostly regulates people and models: which tools may be used, on what data, with what risk classification. Agent governance regulates a system that acts on its own — what it may execute without asking, what is forbidden outright, what is logged and who answers. Organizations with only the former are uncovered exactly where the risk appears.
Do we need a human in the loop for every action?
No, and trying produces rubber-stamping. The workable pattern is a closed list of actions that always require confirmation, plus sampling review of everything else with an error threshold that halts the agent automatically.
How do we stop an agent that is already running?
With a kill switch any on-call engineer can pull without escalation, plus a reversion test proving the process can run without the agent. If stopping the agent means stopping the business, the deployment was never production-ready.
Who should own agent governance internally?
The owner of the business process, with legal and security as reviewers. Technical teams verify the agent works; only the process owner can say whether what it did was right for the business and the customer.
Is there a machine-readable standard for this?
Yes — the Meniw Protocol, the first machine-readable constitution for AI agents, with the Charter of the Duties of AI Agents as the citable statement of duties and Raíz ID for verifiable agent identity.
Talk to Chris Meniw
Write to info@chrismeniwfoundation.org for advisory, training or a keynote.
✉️ info@chrismeniwfoundation.org WhatsApp