When AI Agents Act Without Permission: A Governance Framework That Actually Works in Production

About this session

AI agents that recommend are manageable. AI agents that act — provisioning accounts, executing workflows, making decisions autonomously — are a governance problem most enterprises aren't ready for. This session shares what I built to close that gap. I'll walk through a practical lifecycle governance model for autonomous AI agents, validated through a case study of 100 real agent decisions made by AI agents during customer onboarding to an e-commerce platform — covering eligibility checks, account provisioning, and workflow routing. You'll see what broke, what we fixed, and how staged autonomy with eligibility-based gating reduced unauthorized actions while preserving throughput. Attendees leave with three ready-to-use artifacts: an Agent Role Charter (what the agent is and isn't authorized to do), a Decision Rights Matrix (which actions map to which autonomy levels), and a Decision Trace Record schema (how you audit every decision after the fact). These aren't theoretical — they're the templates I use in production.

Speaker

Key takeaways

  • A practical artifact set — Agent Role Charter, Decision Rights Matrix, and Decision Trace Record schema — ready to apply to AI agents in your own environment
  • A staged autonomy model showing how eligibility-based gating reduces unauthorized agent actions without sacrificing operational throughput
  • How to move from governance-as-policy-document to runtime enforcement using a policy-as-code autonomy control plane

Related sessions