← All insights

Field noteLens: United States4 min read

Agents need what employees already have: an ID, a manager, a budget and a file

Gateways, agent identity, cross-platform inventories and AI activity in the SIEM, all in one week. Our view: the control layer is forming above the models.

Listen to this article · 6 min

AI-generated narration of the full article.

A row of office binders on a shelf, in La Madre duotone, beside the words The agent file
Photo: rawpixel (CC0)

When a company hires someone, five things happen before that person touches a customer. They get an identity. They get a manager. They get a role that defines what they can reach. They get a budget or spending limit. And a file opens that records what they were given and what they did with it. Nobody debates this. It is how organizations make people accountable.

Most enterprise AI agents running today have none of the five, or have them only by accident, borrowed from whoever built the agent.

Look at this week’s announcements together and a pattern appears. C1 launched a gateway that routes each model call by identity and data rules and charges the cost to an owner, as we covered in our analysis of AI gateways as policy enforcement points. HENNGE created a subsidiary run by two directors and a network of agents, with a roadmap to authenticate non-human identities, discussed in our piece on agent identity. Dataiku and Classie started selling cross-platform inventories and supervision for agents built anywhere, examined in our look at agent control planes. Exabeam began pulling AI activity logs into the SIEM. And Microsoft’s Entra Agent ID, now generally available, already gives agents identities with sponsors and lifecycle workflows.

Different vendors, different products. The same idea underneath.

Our thesis

Here is our view, and it is a view rather than a fact: the enterprise AI control layer is forming above the models, and it is organized around the agent as a non-human worker. Not around the model, which changes every quarter. Not around the platform, since most enterprises run several. Around the agent, because the agent is what acts, spends and touches data.

This refines two positions we have held since September. We argued that providers now run the agent loop, but ownership stays with the enterprise. And we argued that the vendor-neutral layers, identity, evaluation, the agent registry, should be owned once across vendors, in our piece on what to build once. This week shows what “owned once” looks like in practice: a file per agent.

The five records

The agent file: five records every production agent needs01Identity: who isacting02Sponsor: whoanswers for it03Route: whichmodels and datait may reach04Budget: what itmay spend05Record: what itdidEach record shipped this week in at least one product
  1. Identity: who is acting
  2. Sponsor: who answers for it
  3. Route: which models and data it may reach
  4. Budget: what it may spend
  5. Record: what it did

Each record shipped this week in at least one product

The analogy to an employee file is deliberate: the controls exist for people already, and agents need their own version.

1. Identity. The agent has its own identity, distinct from its builder and its users, and the logs distinguish when it acts on someone’s behalf from when it acts on its own. Entra Agent ID is the Microsoft-native way to get there; HENNGE and C1 are approaching it from identity governance.

2. Sponsor. A named person answers for the agent, and the sponsorship transfers when that person changes jobs or leaves. This is the accountability we asked for in our analysis of Copilot Autopilot. Without it, every other record has nobody to read it.

3. Route. Policy defines which models, deployments and data the agent may reach, outside its code. This is what an identity-aware gateway enforces. It is also where data residency and contractual limits become operational.

4. Budget. The agent has a spending envelope, alerts before the limit and a defined behavior at the limit. We laid out the design choices in our piece on AI spend guardrails. The gateway’s cost attribution is what makes the budget enforceable per agent instead of per subscription.

5. Record. What the agent did, with which identity, under which policy, is kept as evidence. That record feeds three readers: engineers debugging behavior, security teams baselining activity and auditors reconstructing a decision.

Why this matters more in regulated companies

In a public company, an agent with access to a financial system falls under the same user access reviews that SOX testing already covers. In healthcare, the route record is how you prove protected data only reached deployments under a business associate agreement. In banking, model risk teams already keep inventories; agents are the obvious next entry. Regulated enterprises have most of the muscle for this already. What they lack is the habit of applying it to software that acts.

What we expect next, and what would prove us wrong

Our expectation, again a view: within a year, buyers will ask agent vendors for these five records the way they ask SaaS vendors for SSO and audit logs today, and “can it show me the agent’s file?” becomes a standard procurement question.

What would prove us wrong: if agent platforms converge so strongly that one vendor’s registry covers everything, a separate layer becomes unnecessary; or if agents stay mostly inside single applications, where the application’s own permissions are enough. We will track both.

What to do on Monday

  1. Pick your ten most-used agents and try to fill the five records for each. The blanks are your backlog.
  2. Start with sponsor and identity. They are cheap and they make everything else possible.
  3. Decide where the file lives. Your main identity platform, a cross-platform control plane, or both. Do not let it live only inside each agent builder.
  4. Make the file a gate. No agent reaches production without all five records filled.

The model will keep changing. The agent’s file is what makes it safe to change it.

Have an AI use case stuck between prototype and production?

Tell us what you’re trying to ship. We’ll reply with honest next steps.

Discuss a use case