AI GOVERNANCE · PRACTICAL GUIDE

AI agent governance: permissions, approvals and audit

AI agent governance is the set of controls that define what an AI agent may do on its own, what requires human approval, which systems and data it can reach, how much it may commit or spend, and how every action is recorded so it can be reviewed and reversed. It is the difference between an agent you can put in front of customers and a demo.

Forth Systems engineering team · Last reviewed September 2026

The authority matrix

Governance becomes concrete when you write it as a matrix: person or agent, system, action, value limit, approval requirement. A Procurement Agent might request supplier prices and draft purchase orders freely, order up to £250 from an approved supplier on its own, and be unable to add a supplier, change bank details or exceed that value under any circumstances.

Written this way, the controls are testable. You can point at a row and ask whether the system actually enforces it.

The approval centre

Everything waiting on a human belongs on one screen, with enough context to decide in seconds: what the agent proposes, why, what it used, and the options to approve, edit or reject. Approvals scattered across email are how governance quietly stops happening.

Over time a business can retire approvals it no longer needs — deliberately, one action type at a time, based on the agent's track record.

The audit trail

For every action, record and make visible:

  • Who or what initiated it, and which agent performed it
  • The information and knowledge sources it used
  • The model and prompt version that ran
  • The tools and systems it touched
  • The decision it reached and the action it executed
  • Whether human approval was obtained, and by whom
  • What it cost, and what the result was

Controls that must exist from day one

Tenant isolation, role-based access, row-level security, managed secrets, encryption, spend limits, rate limits, defined failure states, rollback, human override and a kill switch for every agent. No agent should get unrestricted access to a company simply because that was easier to build.

Common questions

What should never be automated?
Changing bank or payment details, entering contracts, pricing outside agreed rules, handling complaints and anything covered by regulation. Those escalate by design.
How do we set a sensible financial limit?
Start at the value where a mistake would be annoying rather than damaging, and raise it deliberately once the agent's record supports it.
Is an audit trail enough for compliance?
It is the foundation, not the whole answer. You also need retention rules, access control over the log itself, and a person accountable for reviewing it.
What happens when an agent fails?
It should stop, hand the work to a named human with its reasoning attached, and leave the record intact. Silent failure is the one behaviour that cannot be tolerated.

Related

NEXT STEP

Find out how autonomous your business is today, and what the realistic 90-day target looks like.

Get your Autonomy Score