Identity and scope
Passport and registry records identify the AI Worker, owner, purpose, lifecycle status, approved scope, authority limits, data boundaries, and open review items.
Control Plane Preview
The Scaled Agents Control Plane is the customer-managed AI Worker Control Plane for reviewing identity, ownership, approved scope, Toll Gate posture, Runtime Permit decisions, Human Review items, evidence, and lifecycle signals. As the broader governance and action-control layer, it uses current records to determine whether a proposed action should proceed, pause, be denied, or require more evidence.
This public page is a deployed non-production proof. The related repository-validated implementation is synthetic, fixture-backed, and mock; neither state provides production runtime enforcement, live enterprise connectors, production MCP operation, or customer-production operational status.
Its core operating posture is fail-closed: when owner, scope, approval, evidence, or current authority cannot be proven, the request should pause, block, require proof, or route to Human Review.
Context
Teams use the Control Plane concept to make ownership, authority, review status, evidence needs, permitted tools, blocked actions, lifecycle posture, and escalation paths visible before higher-risk AI Worker activity proceeds.
Passport and registry records identify the AI Worker, owner, purpose, lifecycle status, approved scope, authority limits, data boundaries, and open review items.
Policy goals, framework guidance, and operating standards become useful only when mapped to owners, records, review gates, runtime decisions, evidence, and closure paths.
When a requested action lacks owner proof, approved destination, current evidence, or review state, the control path should block, pause, require evidence, or escalate.
Stamps, evidence records, workflow events, and audit export packages preserve what was reviewed, what was missing, what was blocked, and what requires owner action.
Persuasive or impersonation-like requests should still resolve through Passport scope, verification evidence, Human Review, Toll Gates, and Runtime Permit state before action.
Governance Compilation
Policies, standards, review decisions, and owner directives have to become records the runtime path can evaluate: identity and context, canonical action, policy constraints, authorization artifacts, and lifecycle evidence.
Passport, Purpose Binding, Tool/API/Connector Registry, Toll Gate, and Evidence Records translate governance intent into structured review inputs.
Runtime Permit and Action Broker posture show whether the current identity, purpose, action, approval, evidence, policy version, and lifecycle state still support the requested consequence.
If authority, evidence, scope, owner, policy, connector status, or revocation path is missing or stale, the path should deny, block, require evidence, or route to Human Review.
Repository-validated implementation boundary: Current deterministic proof slices validate stated behavior, but they do not by themselves create live PDP/PEP enforcement, credential issuance, live connector access, legal conclusions, compliance conclusions, security authorization, audit opinions, customer deployment, or production approval.
Action Authority
Enterprise control requires more than knowing which AI Worker acted or whether it had access. The Control Plane connects identity and access context to approved business purpose, accountable ownership, review requirements, exact-action authority, controlled execution, and reconstructable evidence.
Resolve its Registry record, Passport, tenant, environment, lifecycle state, and customer-managed workload-identity reference.
Review the approved tools, systems, agents, data classes, resources, and destinations in its governed scope.
Distinguish permitted action requests from restricted and prohibited actions. Registration or access alone is not action authority.
Resolve current Purpose Binding, Toll Gate, Human Review, policy, evidence, and short-lived Runtime Permit conditions for the exact request.
Keep a named human owner accountable for the workflow, approval path, operational decision, exception, and outcome.
Use Action Broker, Evidence, Workflow Event, and Audit Export records to reconstruct the decision, execution, exception, and outcome.
Customer-control boundary: Customers retain control of workflow definitions, business rules, approval paths, delegation limits, operating knowledge, evidence requirements, and production decisions. These governance records remain provider-neutral across customer-selected identity, model, cloud, connector, and orchestration components.
This framework is a read-only projection over existing governance records. It does not create credentials, grant access, issue production authority, guarantee an outcome, or replace accountable customer review.
Control Plane Preview
Control Plane Preview is the public buyer-facing view of the customer-managed control-plane concept: a way to understand which AI workers exist, who owns them, what scope has been approved, which review gates apply, what evidence exists, and where lifecycle or human-review attention is needed.
Review the responsible owner, business purpose, permitted work, restricted actions, data boundaries, tool boundaries, and lifecycle posture for each AI worker.
Track which review gates, human decisions, evidence records, exceptions, and open questions must be addressed before higher-risk work proceeds.
Connect runtime decisions and activity signals back to the same governed records, without treating a dashboard signal as approval by itself.
This public page explains the product concept. Customer records, permissions, evidence, and operational decisions belong inside an authorized customer-managed workspace.
Advisory governance boundary: Control Plane material supports review preparation and oversight. It does not authorize production use, live runtime enforcement, live connector configuration, legal conclusions, compliance conclusions, security authorization, or audit conclusions.
Board Oversight Source
Executive and board views should consume the same Control Plane records used by operators and reviewers: Agent Registry entries, Agent Passports, Behavioral Envelope fields, Toll Gate decisions, Runtime Permit status, Human Review items, Stamp Ledger events, Evidence Records, and Audit Export Packages.
Board views summarize value, lifecycle posture, high-risk AI workers, open exceptions, regulatory exposure, and management actions from governed portfolio records.
Behavioral Envelope and Passport fields show approved purpose, data, tool, system, workflow, autonomy, escalation, monitoring, and renewal boundaries.
Executive and board dashboards support oversight and inquiry. They do not approve their own records, bypass Toll Gates, accept residual risk, or authorize production use.
Use the Board & Executive Oversight page for public context. Use the logged-in Control Plane only when authorized customer-managed access is available.
Customer-Managed Platform
Scaled Agents provides platform patterns and governed records. Customer leaders, reviewers, security teams, privacy teams, legal teams, auditors, and accountable business owners remain responsible for their own environment and formal approval decisions.
Deployment, access control, data handling, monitoring, backup, incident response, and operational procedures are customer-managed responsibilities.
AI providers, SaaS tools, MCP servers, APIs, and cloud platforms connect around the control plane as approved tools or execution environments.
Control Plane records support readiness and oversight. They do not create legal conclusions, compliance approvals, security authorizations, audit opinions, or production approvals.
Customer-safe assurance export summaries should be composed from Passport, Toll Gate, Runtime Permit, Human Review, and evidence records rather than from marketing copy.
The Control Plane can support customer-managed preparation for deployed AI worker assessments without becoming the assessor or certification authority.
Public content does not expose the logged-in Control Plane. Use the login path for authorized workspace access.