Cobalt Giraffe Research
Governable Enterprise
Agentic AI
Agents are not chatbots. Once AI can reason, use tools, delegate work and take consequential actions, enterprise architecture has a different problem to solve.
Working architecture / research in progress
An evolving research model, not a validated universal reference architecture.Open full-resolution diagram (new tab)
Agents change the architecture problem
Generative AI systems largely produce information. Agentic systems can go further: they can interpret objectives, retrieve enterprise knowledge, choose actions, invoke tools, delegate work and alter business systems.
That changes the governance problem. The enterprise no longer needs to control only who can access a system. It must also determine which agent is acting, what it is authorised to do, and how independently it may act.
- Identity
- Who is acting
- Authority
- What it may do
- Autonomy
- How independently it may act
A separate control plane
The emerging architecture separates agent execution from agent governance.
Agents operate in the execution layer. A logically separate Enterprise Agent Control Plane provides common capabilities for:
- Agent registration and identity
- Authority and entitlements
- Autonomy controls
- Risk classification
- Policy decision and enforcement
- Approvals
- Observability
- Audit and evidence
The control plane is logically separate rather than necessarily one central physical platform. Enforcement may occur at distributed points across APIs, tools, data services, agent hand-offs and transaction boundaries.
Control where consequence occurs
Authentication alone is not sufficient. An authenticated agent may legitimately retrieve customer data and still make an inappropriate decision about what to do with it.
Controls therefore need to exist at consequential action boundaries - particularly where agents:
- Change enterprise state
- Invoke privileged tools
- Transmit information externally
- Delegate authority
- Initiate transactions
- Create financial, legal or operational consequences
This leads naturally to a policy model in which a Policy Decision Point (PDP) determines whether an action is permitted and a Policy Enforcement Point (PEP) prevents or allows execution.
Different agents require different controls
A knowledge-retrieval agent and a payments agent should not carry the same governance burden.
A simple starting distinction is:
Read Update Action / Transact
But enterprise risk is richer than a single tier. Data sensitivity, criticality, reversibility, financial value, regulatory exposure and permitted autonomy all influence the controls an agent should operate under.
The emerging principle
Do not rely on agents to govern themselves.
Enterprise agentic AI needs an architectural layer capable of observing, constraining and reconstructing agent behaviour across the lifecycle.
The current working hypothesis is:
Enterprise agentic AI requires a logically separate control plane governing identity, authority, autonomy, policy, risk and evidence, with enforcement concentrated at consequential trust and action boundaries.
This architecture is an evolving Cobalt Giraffe research model rather than a claimed universal reference architecture.