Cobalt Giraffe Research

Governable Enterprise
Agentic AI

Agents are not chatbots. Once AI can reason, use tools, delegate work and take consequential actions, enterprise architecture has a different problem to solve.

Working architecture / research in progress

Five-layer model: business and human interaction; agent execution; a separate enterprise agent control plane for identity, authority, autonomy, policy and evidence; knowledge, data and context; and tools and enterprise systems. Controls apply at request, delegation, data access and action boundaries.
Governable Enterprise Agentic AI Pattern
An evolving research model, not a validated universal reference architecture.
Open full-resolution diagram (new tab)

Agents change the architecture problem

Generative AI systems largely produce information. Agentic systems can go further: they can interpret objectives, retrieve enterprise knowledge, choose actions, invoke tools, delegate work and alter business systems.

That changes the governance problem. The enterprise no longer needs to control only who can access a system. It must also determine which agent is acting, what it is authorised to do, and how independently it may act.

Identity
Who is acting
Authority
What it may do
Autonomy
How independently it may act

A separate control plane

The emerging architecture separates agent execution from agent governance.

Agents operate in the execution layer. A logically separate Enterprise Agent Control Plane provides common capabilities for:

  • Agent registration and identity
  • Authority and entitlements
  • Autonomy controls
  • Risk classification
  • Policy decision and enforcement
  • Approvals
  • Observability
  • Audit and evidence

The control plane is logically separate rather than necessarily one central physical platform. Enforcement may occur at distributed points across APIs, tools, data services, agent hand-offs and transaction boundaries.

Control where consequence occurs

Authentication alone is not sufficient. An authenticated agent may legitimately retrieve customer data and still make an inappropriate decision about what to do with it.

Controls therefore need to exist at consequential action boundaries - particularly where agents:

  • Change enterprise state
  • Invoke privileged tools
  • Transmit information externally
  • Delegate authority
  • Initiate transactions
  • Create financial, legal or operational consequences

This leads naturally to a policy model in which a Policy Decision Point (PDP) determines whether an action is permitted and a Policy Enforcement Point (PEP) prevents or allows execution.

Different agents require different controls

A knowledge-retrieval agent and a payments agent should not carry the same governance burden.

A simple starting distinction is:

Read Update Action / Transact

But enterprise risk is richer than a single tier. Data sensitivity, criticality, reversibility, financial value, regulatory exposure and permitted autonomy all influence the controls an agent should operate under.

The emerging principle

Do not rely on agents to govern themselves.

Enterprise agentic AI needs an architectural layer capable of observing, constraining and reconstructing agent behaviour across the lifecycle.

The current working hypothesis is:

Enterprise agentic AI requires a logically separate control plane governing identity, authority, autonomy, policy, risk and evidence, with enforcement concentrated at consequential trust and action boundaries.

This architecture is an evolving Cobalt Giraffe research model rather than a claimed universal reference architecture.