We govern the agents your organisation builds.
An agent is not another model.
That is an identity, permissions and accountability problem wearing an AI costume. It is also the problem that gets discovered late, because an agent that works looks fine right up until the moment it does something nobody authorised.
Fourteen questions, asked of every agent.
Every agent, named and owned. Most organisations cannot produce this list, which is the finding.
Autonomy tier and consequence tier, assessed separately.
What each agent is permitted to decide, written down, and who granted it.
Agents authenticate as something. Whether that is a service account, a delegated human identity or a machine credential changes who is accountable.
Tool access and data access scoped to the task, not to the platform. Standing access is the exposure.
What the agent may read, retain, transmit and infer, and what it must never see.
Which actions require a named human before execution, and whether the gate is enforced or advisory.
The tools and integrations an agent can invoke, and who stands behind each one.
Behavioural baselines, drift detection and the alert that fires when an agent acts outside its envelope.
Kill-switch authority, rollback, notification, and who is permitted to pull it at 2am.
What proves each control operated on each cycle, rather than existing in a policy.
Whether an internal auditor can follow one agent action end to end without a walkthrough.
Approval to deploy, revalidation on change, and periodic reauthorisation.
How an agent is retired, and how its credentials, access and records are dealt with when it is.
Before an agent acts, who authorised it?
Mycelium has built and run agents on this architecture internally, on synthetic data, across banking operations, project management, legal intake, supplier assurance and energy operations. They are how we know where the gates belong and what the evidence has to capture. They are not for sale.
We do not need to have built it to govern it.
Built internally
Assessed against the same fourteen questions as anything bought.
Bought or embedded
Including agents arriving inside platforms you already licence, which is where inventories usually break.
Commissioned
Vendor-built agents, assessed with the same vendor governance test as any material service provider.
Independence, made structural.
No agent we assess is one we were engaged to construct.
No assessment of work we would then be engaged to remediate.
No platform licence and no referral arrangement, with anyone, at any point.
The rule runs both ways, for twelve months either side of a Health Check.
The record is yours. Every register, assessment and evidence pack is delivered in a form you can keep current without Mycelium and without the platform.
Start with the inventory.
Most agent-governance conversations stall on the first question, which is how many you have. The diagnostic answers it.