Who owns it?
Passport and Registry records connect every AI Worker to a human owner, business purpose, approved scope, and lifecycle state.
Scaled Agents Control Plane
Connect who owns the AI Worker, what it may do, when Human Review is required, whether the exact action is permitted, and what evidence must be retained—all within a customer-managed control plane.
One Governed View
The Control Plane brings the records needed to govern AI Worker activity into one accountable operating view.
Passport and Registry records connect every AI Worker to a human owner, business purpose, approved scope, and lifecycle state.
Toll Gates, Human Review, policy, and short-lived Runtime Permits determine whether the exact requested action may proceed.
Action Broker receipts, Evidence Records, Workflow Events, and audit exports preserve the decision and outcome.
Governance Compilation
Policies, standards, review decisions, and owner directives have to become records the runtime path can evaluate: identity and context, canonical action, policy constraints, authorization artifacts, and lifecycle evidence.
Passport, Purpose Binding, Tool/API/Connector Registry, Toll Gate, and Evidence Records translate governance intent into structured review inputs.
Runtime Permit and Action Broker posture show whether the current identity, purpose, action, approval, evidence, policy version, and lifecycle state still support the requested consequence.
If authority, evidence, scope, owner, policy, connector status, or revocation path is missing or stale, the path should deny, block, require evidence, or route to Human Review.
Capability boundary: Public product materials, schemas, fixtures, tests, and evidence examples can demonstrate the governed model. They do not by themselves create live policy enforcement, credential issuance, connector authority, customer deployment, production approval, or formal legal, compliance, security, or audit conclusions.
Action Authority
Enterprise control requires more than knowing which AI Worker acted or whether it had access. The Control Plane connects identity and access context to approved business purpose, accountable ownership, review requirements, exact-action authority, controlled execution, and reconstructable evidence.
Resolve its Registry record, Passport, tenant, environment, lifecycle state, and customer-managed workload-identity reference.
Review the approved tools, systems, agents, data classes, resources, and destinations in its governed scope.
Distinguish permitted action requests from restricted and prohibited actions. Registration or access alone is not action authority.
Resolve current Purpose Binding, Toll Gate, Human Review, policy, evidence, and short-lived Runtime Permit conditions for the exact request.
Keep a named human owner accountable for the workflow, approval path, operational decision, exception, and outcome.
Use Action Broker, Evidence, Workflow Event, and Audit Export records to reconstruct the decision, execution, exception, and outcome.
Customer-control boundary: Customers retain control of workflow definitions, business rules, approval paths, delegation limits, operating knowledge, evidence requirements, and production decisions. These governance records remain provider-neutral across customer-selected identity, model, cloud, connector, and orchestration components.
This framework is a read-only projection over existing governance records. It does not create credentials, grant access, issue production authority, guarantee an outcome, or replace accountable customer review.
Customer Managed
Scaled Agents provides the control-plane software and governed record model. Customers retain control of deployment, identity, data, integrations, operating policy, and formal decisions.
Hosting, access, data handling, monitoring, recovery, and operational procedures remain within the customer’s environment and authority.
Models, clouds, SaaS tools, APIs, MCP servers, and orchestration platforms connect around the Control Plane as governed execution components.
Accountable owners and qualified reviewers retain legal, privacy, security, compliance, audit, risk, and production decisions.
This public page explains the product model. It does not expose customer records, grant authority, approve production use, or replace accountable review.