Cobalt Giraffe Research

Enterprise Agent Control Plane

A supervisory architecture for governing identity, authority, autonomy, policy and evidence across enterprise agentic AI.

Working architecture / research in progress

Agentic AI introduces a different kind of architecture problem.

A conventional application follows predefined flows and permissions.

An enterprise agent may interpret objectives, retrieve knowledge, decide what steps are required, invoke tools, delegate work and take actions with operational, financial or legal consequences.

That means governance cannot sit only inside the agent.

The enterprise needs a logically separate supervisory architecture capable of determining who is acting, what they are allowed to do, how independently they may act, which policies apply, and what evidence must be retained.

This architecture is described here as the Enterprise Agent Control Plane.

Enterprise Agent Control Plane. Business interaction and agent execution are separated from supervisory governance. Common policy decisions support distributed enforcement at knowledge, data, tools and enterprise-system boundaries, with observability, evidence and assurance across the lifecycle.
Enterprise Agent Control Plane
Working architecture / research in progress
Enlarge SVG (new tab) ↗PNG export (new tab) ↗

Why a separate control plane?

If every agent implements its own governance, policy and audit logic, control becomes inconsistent, duplicated and difficult to assure.

A control plane separates agent execution from agent governance.

Agents remain responsible for completing tasks.

The control plane is responsible for applying common rules around identity, authority, autonomy, risk, policy and evidence.

This does not imply one giant central runtime bottleneck.

The control plane can be logically central while using distributed enforcement points across enterprise systems.

Three core control dimensions

The control plane must distinguish between three different questions.

Identity: Who is acting?

Authority: What is the agent allowed to do?

Autonomy: How independently may it act?

A valid identity does not imply unlimited authority.

Authority does not imply unlimited autonomy.

All three must be evaluated together before consequential action is allowed.

Policy must become executable

Enterprise governance cannot remain only in documents, standards and approval boards.

For agentic systems, policy must increasingly be enforced at runtime.

A Policy Decision Point evaluates whether an action should be allowed.

A Policy Enforcement Point ensures that the decision is actually applied.

Possible outcomes may include:

  • allow
  • deny
  • allow within limits
  • require approval
  • escalate

Enforcement may occur at data gateways, APIs, tool invocation points, agent hand-offs, transaction systems and external communication boundaries.

Control consequential action boundaries

Authentication and data access controls are necessary, but not sufficient.

An authenticated agent may legitimately retrieve customer data and still make an inappropriate decision about what to do with it.

Controls therefore need to exist where consequence occurs.

Examples include:

  • sending information externally
  • modifying enterprise records
  • invoking privileged tools
  • delegating authority
  • making payments
  • initiating legal or operational commitments

Observe, constrain and reconstruct

A governable agentic system must be able to reconstruct consequential behaviour.

That may require evidence of:

  • who initiated the request
  • which agent acted
  • which runtime instance executed
  • what data was accessed
  • which tools were called
  • which agents were delegated to
  • which policies were evaluated
  • which approvals occurred
  • what actions were taken

The goal is not necessarily to retain every internal model token.

The goal is to retain sufficient decision and execution evidence to support accountability, investigation and assurance.

Logically central, physically distributed

The control plane should be understood as a logical architecture.

Identity, policy, authority and governance may be managed consistently at enterprise level, while enforcement occurs across distributed technical boundaries.

That makes the control plane less like a single product and more like a coordinated governance architecture.

The emerging principle

The current working hypothesis is:

Enterprise agentic AI requires a logically separate control plane governing identity, authority, autonomy, policy, risk and evidence across the agent lifecycle, with enforcement concentrated at consequential trust and action boundaries.

This is an evolving Cobalt Giraffe research model rather than a claimed universal reference architecture.