Design with clear boundaries
Define purpose, human ownership, risk, data and tool boundaries, prohibited actions, evidence needs, and review paths before deployment.
AI Worker Control Plane
Scaled Agents helps GRC, security, data, technology, and AI leaders define who owns each AI worker, what it is allowed to do, what requires review, and what evidence supports its current status before AI-supported work reaches production or broader operating use.
Use this page when you need the product-level answer: what Scaled Agents is, what it governs, and how Passport, Toll Gates, Runtime Permits, Action Broker, Human Review, Policy, Stamps, and Lifecycle Analytics fit together.
Vision & Mission
Scaled Agents is designed to help enterprises keep purpose, ownership, bounded authority, security and policy controls, human oversight, monitoring, evidence, response, recovery, renewal, and retirement visible from design through operation.
Define purpose, human ownership, risk, data and tool boundaries, prohibited actions, evidence needs, and review paths before deployment.
Evaluate specific actions through current Passport scope, Toll Gates, Human Review, Runtime Permits, Action Broker mediation, monitoring, and evidence.
Preserve incident, remediation, rollback, suspension, revocation, renewal, retirement, and audit context as part of the same governed lifecycle.
This is the product direction and governance model. It does not mean every control is implemented, deployed, activated, security-authorized, or operating in a customer environment, and it does not certify security or compliance.
Problem
Enterprise teams can usually explain what an AI worker should do. The harder question is whether the organization can prove who owns it, which data and tools it may touch, what action is blocked until review, and how decisions can be reconstructed later.
AI worker work often starts before business owner, technical owner, risk owner, data owner, reviewer, and pause authority are explicit.
Agent instructions, data access, tool use, external communication, and production-adjacent actions can expand faster than the review path.
Approvals, denials, exceptions, lifecycle changes, and operating decisions need traceable records instead of scattered messages or assumptions.
When owner, approved scope, required evidence, or current authority is missing, the safer path is to pause, block, require proof, or route the request to Human Review.
Governance Proof Stories
These public-safe examples use existing Scaled Agents samples and local fixtures. They demonstrate the intended record chain without claiming live connectors, production enforcement, customer outcomes, or production authorization.
A Procurement Intake AI Worker has a named owner and approved purpose in its Passport. A proposed destination falls outside the reviewed boundary, so the Toll Gate blocks the request and routes it to Human Review. No Runtime Permit advances, the Action Broker has no basis to route the action, and the evidence trail records what stopped and what proof is needed next.
Inspect the sample PassportA proposed sensitive-tool action remains in review while required evidence and Human Review are incomplete. The Runtime Permit stays in a requires-review state, the Action Broker path remains blocked, and the linked Passport, Toll Gate, review item, and evidence records preserve the decision context.
Review the governed workflowA read-only connector request is evaluated as a specific action, not blanket integration approval. The Passport defines purpose and data scope; the Toll Gate checks the requested resource, evidence, and review posture before a scoped Runtime Permit or Action Broker path can be considered.
Open the provider-agnostic guideA coding AI Worker may inspect an approved synthetic repository after independent review. A proposed protected-branch or deployment action remains blocked until the exact repository, commit, environment, evidence, and Human Review support a short-lived Runtime Permit. Changed context, Permit replay, or Passport revocation prevents the mock Action Broker path from advancing.
Review the Control Plane previewGoverned Execution Boundary. These synthetic and fixture-backed examples show where an AI Worker action must stop, obtain current authority, or route to review before crossing into a controlled system or consequential action. They do not configure live runtimes or connectors, access repositories, issue credentials, process customer data, call live tools, deploy changes, or demonstrate production enforcement.
Solution
The control plane keeps AI worker identity, authority, evidence, and review paths visible through Passport Studio, Control Plane Preview views, registry records, review gates, evidence records, and lifecycle status. Customers retain control over hosting, identity, data, configurations, integrations, monitoring, and production-readiness decisions.
Create and review Passport planning records that identify owner, purpose, approved scope, lifecycle state, authority limits, evidence needs, and open review gaps.
Review AI worker inventory, lifecycle status, evidence posture, open review items, risk signals, Runtime Permit posture, and operating context without treating a preview record as production approval.
Plan how AI worker ideas move from intake to ownership, risk review, evidence, Passport scope, review gates, and implementation handoff boundaries.
Public portal and Studio references remain preview materials unless separately implemented, tested, activated, and approved under the appropriate customer-controlled path.
Two Entry Paths, One Governance Model
Organizations do not need to rebuild their existing AI estate to use the Scaled Agents governance model. Both entry paths converge on the same ownership, Passport, review, action-control, evidence, and lifecycle records.
Identify the use case, assign an owner, draft the Blueprint and Passport, classify risk, define data and tool boundaries, complete required review, establish Registry standing, and govern action requests.
Discover or register the worker, assign accountable owners, document current authority and dependencies, identify gaps, apply provisional restrictions where needed, remediate, review standing, and govern future action requests.
Identify, own, define, review, authorize actions, capture evidence, monitor, renew, constrain, suspend, revoke, or retire through shared governance records.
Current Product Maturity
Scaled Agents includes repository-validated implementations, deployed non-production proofs, and separately identified production-capable components. Customer-production operational status is determined separately for each authorized customer-managed deployment and scope. None of the first three states alone evidences customer production orchestration, live enterprise connectors, production MCP operation, customer tenant isolation, production evidence custody, or production runtime enforcement.
Capability Layers
Reusable AI Worker patterns and templates help teams start from known governance expectations instead of unmanaged prompt or tool sprawl.
Versioned questions, contextual answers, evidence expectations, review state, assessments, and scoped reuse help teams stop answering the same enterprise questions from scratch.
Explore the interactive previewToll Gates, Runtime Permits, Action Broker routing, Human Review, and Stamps provide a planning model for action-time control and evidence.
Human ownership, review rights, escalation paths, and lifecycle responsibilities remain part of the platform design, not an afterthought.