Home · Services · Agentic AI Governance
A governance specialism within Govern

We govern the agents your organisation builds.

Mycelium does not build agents. Your engineers, your platform vendors and your integrators do that, and they are good at it. The question nobody owns is what happens once dozens of them are running: who authorised this one, what can it reach, what does it need a human for, and what proves any of that held.
01 · Why this is separate

An agent is not another model.

A model produces an output that a human then acts on. An agent acts. It holds credentials, calls tools, writes to systems and chains its own steps, which means the governance questions change shape: not “is this output right” but “what was this thing allowed to do, on whose authority, and what stopped it going further”.

That is an identity, permissions and accountability problem wearing an AI costume. It is also the problem that gets discovered late, because an agent that works looks fine right up until the moment it does something nobody authorised.

02 · Scope

Fourteen questions, asked of every agent.

Each one is assessed against an existing dimension of the framework. Agentic AI is a cross-cutting concern, not a fifteenth dimension, a single agent typically touches seven at once.
01
Inventory

Every agent, named and owned. Most organisations cannot produce this list, which is the finding.

02
Classification

Autonomy tier and consequence tier, assessed separately.

03
Authority

What each agent is permitted to decide, written down, and who granted it.

04
Identity

Agents authenticate as something. Whether that is a service account, a delegated human identity or a machine credential changes who is accountable.

05
Permissions

Tool access and data access scoped to the task, not to the platform. Standing access is the exposure.

06
Data boundaries

What the agent may read, retain, transmit and infer, and what it must never see.

07
Human approval

Which actions require a named human before execution, and whether the gate is enforced or advisory.

08
Third-party tools

The tools and integrations an agent can invoke, and who stands behind each one.

09
Monitoring

Behavioural baselines, drift detection and the alert that fires when an agent acts outside its envelope.

10
Incidents

Kill-switch authority, rollback, notification, and who is permitted to pull it at 2am.

11
Evidence

What proves each control operated on each cycle, rather than existing in a policy.

12
Auditability

Whether an internal auditor can follow one agent action end to end without a walkthrough.

13
Lifecycle

Approval to deploy, revalidation on change, and periodic reauthorisation.

14
Decommissioning

How an agent is retired, and how its credentials, access and records are dealt with when it is.

03 · The gate

Before an agent acts, who authorised it?

The architecture below is the one Mycelium assesses against. It is not a product on offer. It is the shape a governed agent takes, whoever builds it, and the point at which most agent estates have nothing to show.
audit_log> 2026-06-07T14:22Z · agent=[agent] · action=[action] · approver=[approver] · evidence=[ref]

Mycelium has built and run agents on this architecture internally, on synthetic data, across banking operations, project management, legal intake, supplier assurance and energy operations. They are how we know where the gates belong and what the evidence has to capture. They are not for sale.

04 · Technology-agnostic

We do not need to have built it to govern it.

Your agents may come from an internal engineering team, a hyperscaler, a low-code platform, a SaaS vendor shipping agents inside a product you already own, or a system integrator. The governance architecture sits above that choice, which is the point: an organisation running agents from four sources needs one accountability model, not four.
01

Built internally

Assessed against the same fourteen questions as anything bought.

02

Bought or embedded

Including agents arriving inside platforms you already licence, which is where inventories usually break.

03

Commissioned

Vendor-built agents, assessed with the same vendor governance test as any material service provider.

05 · The boundary

Independence, made structural.

Mycelium does not build agents, does not licence agent platforms, does not integrate them and holds no interest in anyone who does. There is no version of an assessment where we are also the party being assessed.
01We do not build for clients

No agent we assess is one we were engaged to construct.

02We do not integrate

No assessment of work we would then be engaged to remediate.

03We do not resell

No platform licence and no referral arrangement, with anyone, at any point.

04We do not assess into our own subscription

The rule runs both ways, for twelve months either side of a Health Check.

The record is yours. Every register, assessment and evidence pack is delivered in a form you can keep current without Mycelium and without the platform.

06 · Start here

Start with the inventory.

Most agent-governance conversations stall on the first question, which is how many you have. The diagnostic answers it.