AI agent governance:
permissions, approvals, records and evals.

AI agent governance is the set of controls that decide what an AI agent can reach, what it may do without a person, how each action is recorded and how you know it still does the work to the agreed standard. In practice that comes down to four controls: permissions, approvals, an audit trail and evaluations, plus rules for changes and for data.

This page sets out each control, a checklist to run before any agent goes live and where the EU AI Act fits. It is also how we set agents up on the Ortelian platform, which our team deploys on site and which is hosted in the EU.

Why it matters

Agents act, so the controls have to sit where they act.

A chat assistant answers a person, and the person decides what to do next. An agent reads your systems, takes steps and writes back. A policy document can’t reach that layer. The controls that hold are set in the platform the agents run on, per agent and per workflow, before anything goes live.

Company-wide AI governance still matters: which tools are allowed, which model providers you trust, how people are trained. This page covers the part that is specific to agents, where software takes actions on the company’s behalf.

The framework

Six controls, and how we set each one up.

The first four are the core of AI agent governance. The last two are the foundations under them. The right column is how each control works on the Ortelian platform.

OptionThe question it answersHow we set it up on Ortelian
PermissionsWhat can this agent reach, and what can it change?Each agent gets only the tools its job needs, never open computer access. Connecting a system does not grant access by itself.
ApprovalsWhich steps wait for a person?Actions that leave the company, such as an email or an invoice, wait for a person. Approval points are set before a workflow goes live.
Audit trailWhat did the agent do, and on what basis?Every action is recorded with the sources behind it. Each run records the version of the agent or workflow it used.
EvaluationsIs it still doing the work to the standard?Real examples of the work become evaluations for quality, cost, time and human effort. They set the threshold before launch and keep running after it.
Change controlWhat changed, and who agreed to it?Every change to an agent or workflow is shown in full before it goes live.
Data and modelsWhere does the data go, and who can train on it?The platform is hosted in the EU. Agents use models with zero data retention only, and your data is never used to train models.

1 · Permissions

Give each agent only the tools its job needs.

This is least privilege, applied to agents. Set permissions per agent and per job, not per user account. Separate reading from writing, and scope both: one territory, one entity, one set of fields. An agent that prepares meetings needs to read the CRM. It doesn’t need to edit deal stages.

Avoid giving an agent a person’s login or open access to a computer or browser. Once you do, you can no longer say what it is able to do. Instructions in a prompt can be misread. A tool the agent doesn’t have can’t be misused.

A useful test: if this agent gets it wrong in the worst way its tools allow, what happens? If the answer isn’t acceptable, narrow the tools rather than adding another rule to the prompt.

2 · Approvals

Put a person where the consequences are.

Human in the loop works when it is placed by consequence, not spread everywhere. Ask three things of each step. Can it be undone? Does it leave the company? Does it decide something about a person? A step that can be undone, stays inside the company and decides nothing about a person can usually run on its own.

Too many approvals train people to click yes. Put them where a person adds judgement, and show the evidence with the request so the reviewer can check it in a minute.

  • Runs on its own

    Reading, gathering, checking and drafting inside the company. For example, preparing a brief before a sales meeting or matching invoices against orders.

  • Waits for approval

    Anything that leaves the company, such as emails to customers or suppliers, invoices and orders, plus writes to systems of record beyond the fields agreed for the agent.

  • Stays with a person

    Decisions about people, such as hiring, staffing and performance, and changes of direction. Agents can prepare these decisions. People make them.

3 · Audit trail

Record every action, with what it was based on.

For every run, keep the inputs, the sources the agent used, each tool call, the output, the version of the agent or workflow and who approved what. That is what lets you answer the question that always comes up after something goes wrong: what was the agent doing when it did that?

Records also make fixes safe. When a result falls short, you can see which source or rule caused it, change it and check the change against the same cases. On the EU side, deployers of high-risk systems must keep the logs those systems generate for at least six months (Article 26 of the AI Act).

4 · Evaluations

Governance doesn’t stop at go-live.

Agents drift because the company changes under them: sources move, products change, models get updated. Evaluations are how you notice. Build them from real examples of the work with agreed answers, including the messy cases and the ones where the right outcome is to stop and ask a person.

Measure four things on every piece of work an agent takes over: quality, cost, time and human effort. Run the evaluations before every change and keep them running on the work in use. More in agree the standard before you build, and on putting numbers to it in how to measure the ROI of AI agents.

5 · Changes, models and data

Know what changed, and where the data goes.

Treat a change to an agent’s instructions, tools or workflow like a change to code. Show it in full, run the evaluations and only then put it live. Each run should record which version it used, so a result can always be traced to the setup that produced it.

Agree data handling before you start: where the platform is hosted, which model providers are used, what they retain and whether anything is used for training. On Ortelian, the platform is hosted in the EU, agents use models with zero data retention only, and you own your data and world model and can export both.

Checklist

Before an agent goes live.

Use this on any agent, built by us or anyone else. If you can’t tick a line, that is the next piece of work.

  1. 01An owner

    A named person who owns the work and has the authority to decide how it runs.

  2. 02A tool list

    A written list of the agent’s tools, with reading and writing separated and scoped.

  3. 03A worst case

    A check of what the tools would allow if the agent got it wrong, and whether that is acceptable.

  4. 04Approval points

    Set for anything that leaves the company or changes a system of record beyond the agreed fields.

  5. 05People decisions

    Anything that ranks, scores or allocates people stays with a person and goes to legal review.

  6. 06Records

    Every action logged with its sources, the version used and the approver. Retention period agreed.

  7. 07Evaluations

    Built from real examples, including stop-and-ask cases, with a threshold agreed before launch.

  8. 08Change process

    Every change shown in full and evaluated before it goes live.

  9. 09Data handling

    Hosting, model providers, retention and training agreed in writing.

  10. 10Disclosure and literacy

    Agents that talk to people outside say they are AI. The people who work with the agents know what they do and when to override them.

  11. 11A stop button

    A named person who can pause the agent, and a way to do it quickly.

EU AI Act

Where the EU AI Act fits.

This is not legal advice. For most B2B agent work, such as research, CRM upkeep, meeting prep and planning support, the AI Act asks little. Two duties already apply to everyone. Since 2 August 2026, AI that talks directly to people has to say it is AI unless that is obvious, and generated content has to be marked (Article 50). Companies also have to take measures for the AI literacy of the people who use AI at work (Article 4, softened but not removed by the Omnibus).

The heavy duties are for high-risk uses, and in business work the main one is AI that decides about people at work: recruitment, promotion, task allocation, monitoring. The Digital Omnibus moved the start of those rules for Annex III systems to 2 December 2027, as the European Commission sets out. Deployers of a high-risk system then need, among other things, human oversight by a competent person, logs kept for at least six months and workers informed before rollout.

The controls on this page give you the records, the oversight and the evidence that this work depends on. They don’t make a system compliant by themselves, and they don’t replace a conformity assessment or a lawyer. Our note on what the EU AI Act asks of B2B companies covers the tiers, the dates and what we would do now.

How Ortelian does it

Governance built into the platform, set with your team.

Ortelian is a platform plus a forward-deployed team. We work on site not because our product needs it, but because your company does. Where an approval belongs, and which tools an agent should have, depends on how your work actually runs, and that only shows up when you sit with the people who do it. We set the controls with your team during the audit and the build, before anything goes live.

After launch, your team runs it or we keep running it for you. Either way, we host and operate the platform, and the evaluations keep running on the work in use. Your own agents can use the platform headless through the same scoped tools, and it plugs into ChatGPT Enterprise and Microsoft Copilot over MCP. We set that connection up for your workspace inside the engagement, so the same permissions and records apply.

To see the controls on real work, look at AI agents for sales, where meeting prep runs on its own and anything sent to a customer waits for approval, or AI agents for operations, where matched documents move on and exceptions go to a person with the evidence attached. For how this fits a full engagement, see what an AI-native deployment partner does. For what agents take on in each team, see AI agent examples by function.

Questions

Questions people ask about AI agent governance.

What is AI agent governance?

AI agent governance is the set of controls that decide what an AI agent can reach, what it may do without a person, how each action is recorded and how you know it still meets the agreed standard. The core controls are permissions, approvals, an audit trail and evaluations, with change control and data handling underneath them.

How is AI agent governance different from an AI governance framework?

An AI governance framework covers a company’s use of AI in general: policies, approved tools, risk classification and training. AI agent governance is the part that deals with software taking actions in your systems. It has to be set per agent and per workflow, in the platform the agents run on.

Where should a human be in the loop for AI agents?

Wherever a step can’t be undone, leaves the company or decides something about a person. Reading, gathering, checking and drafting inside the company can usually run on their own. Emails, invoices and orders that go out wait for approval. Decisions about people stay with people.

Do these controls make us compliant with the EU AI Act?

Not by themselves. They give you the records, the human oversight and the evidence that compliance work relies on. Whether a use is high-risk, and what you owe as a provider or a deployer, is a legal question. For anything that decides about people, talk to a lawyer.

Can our own AI tools follow the same rules?

Yes, inside an engagement. Your own agents and tools such as ChatGPT Enterprise or Microsoft Copilot connect to the platform over MCP, which we set up for your workspace. They reach your business only through scoped tools, and their actions are recorded like any other agent’s.


Let’s work out where your agents should stop and ask.

Bring a piece of work you want agents to take on. We’ll go through what they should reach, what should wait for a person and how you would know it works.

Antwerp from across the Scheldt, with the Cathedral of Our Lady and the Boerentoren.