Architecture · plane 6

Governance: policy before action

Trust in an agentic platform is not a feeling about the model — it is a property of the guardrails. The governance plane codifies what agents may do, validates decisions before anything mutates, and decides which actions require a human.

The short answer

Governance is policy-as-code plus approval workflows: machine-readable rules that every proposed action is validated against before execution, and a routing model that sends consequential actions to humans. Policy precedes action — always.

What does the governance plane govern?

  • →Permitted actions: which action classes exist, which agent identities may execute them, in which environments.
  • →Constraints: residency, security posture, cost ceilings, naming, labeling — the non-negotiables encoded as checks, not documents.
  • →Autonomy levels: the read → recommend → propose → execute → remediate ladder, set per action class and revisable with evidence.
  • →Escalation and approval: which actions pause for a human, who approves, how fast, and what happens on timeout.
  • →Exception handling: how overrides work — with a record, an owner, and an expiry, never a quiet side door.

Why policy-as-code instead of prompting?

A system prompt is a suggestion; a policy engine is a gate. When rules live in prompts, they are advisory (the model can ignore them), unverifiable (nobody can enumerate the rules in force), and unauditable (no record of which rule version judged which action). When rules live in policy-as-code — OPA/Rego, Kyverno, cloud policy engines — they are deterministic, testable, versioned artifacts: violations fail closed, exceptions are reviewable diffs, and compliance is a query. In our demo, the same model output that applied cleanly to a cluster failed 42 real policy checks — that gap is exactly what prompting cannot see and policy does.

How do humans stay in the loop without becoming the bottleneck?

The failure modes run both directions: no human gate and you eventually ship an autonomous incident; every action gated and the agents are decorative. The workable model is risk-tiered routing — reversible, low-blast-radius actions proceed autonomously with full traces; consequential or irreversible actions (production deploys, deletions, spend above threshold, anything touching regulated data) wait for human approval. Approval targets narrow, well-contextualized decisions ("this diff, against these checks, with this rollback"), not vague "the AI wants to do something." Humans approve decisions, not vibes.

What does the governance plane emit?

Decisions and evidence: every validation verdict (pass, fail, which rules), every autonomy-level change (who raised it, on what evidence), every approval (approver, time, scope), every exception (owner, expiry, justification). These records feed observability and audit — governance you cannot query after the fact is theater.

Ready for the leap?

Partner with Adventure On The Wave to build governed, agentic platform capability — architecture, guardrails, and the human authority model to match.

A strategic initiative by Adventure On The Wave