DW Agent Governance
Governance, sovereignty and security
A practical governance system for production agents: accountable owners, risk-based autonomy, explicit permissions, versioned controls, continuous evaluation and evidence that survives audit.
Control objective
Agentic AI without uncontrolled autonomy
Explicit authorisation
Risk-based autonomy
Continuous oversight
Lifecycle governance
Govern the system from use-case assessment to retirement
- 01
Assess
Define purpose, affected people, data, decision impact, autonomy, legal obligations and measurable benefit.
- 02
Design
Select architecture controls, model policy, identities, tools, approval points and evidence requirements.
- 03
Assure
Threat model, privacy assessment, security testing, evaluation and business acceptance before release.
- 04
Authorise
Record accountable decisions, conditions, known limitations, residual risk and operational ownership.
- 05
Operate
Monitor behaviour, access, cost, quality and incidents while controlling changes to models and tools.
- 06
Review or retire
Reassess on material change, revoke access, preserve required records and decommission safely.
Threat-informed design
Controls for the failure modes that matter
Agent threat-to-control map
DW Data reference patternPrompt and indirect injection
Content isolation, source trust, injection detection and tool separation
Excessive agency or permissions
Autonomy classification, least privilege and operation allow-lists
Sensitive data disclosure
Classification, minimisation, security trimming and model routing
Unsafe parameters or actions
Schemas, deterministic validation, transaction limits and approval gates
Compromised tools or supply chain
Tool registry, signed delivery, scanning, monitoring and kill switch
Hallucinated outcomes
Grounding, evaluation datasets, validation and human oversight
Threat modelling is tailored to the agent's actual data, tools, operating environment and autonomy. Controls are tested with adversarial inputs and realistic end-to-end scenarios rather than prompt checks alone.
Governance artefacts
Registers make control ownership visible
Agent register
Data source register
Tool register
Model register
Instruction register
Evaluation register
DW Agent Card
A readable control record for each agent
- Business owner and intended purpose
- Autonomy level and approval rules
- Models, data sources and tools
- Permitted and prohibited actions
- Evaluation status and known limitations
- Audit coverage and review dates
DW Agent Card
Procurement Contract Agent
- Owner
- Procurement Operations
- Model
- Approved enterprise model
- Data
- Contract and supplier information
- Tools
- Fabric Query API, Procurement API, Document Search
Can
- Search contracts and supplier information
- Analyse obligations, spend and expiry risk
- Generate recommendations and sourcing briefs
Cannot
- Approve purchases
- Change supplier master data
- Create or release payments
Human approval: Purchase recommendation release
Audit: 100% tool invocation logging
Human oversight
Approval is an architectural control
A2 - approval required
DW Data reference patternAgent
Prepares action
Proposed transaction
Structured and validated
Human review
Approve or reject
Security Gateway
Revalidates policy
Enterprise system
Executes authorised action
Authorised reviewer
Approvals are restricted to people with the right role, delegated authority and separation from incompatible duties.
Decision context
The review includes source evidence, proposed parameters, risk flags, model output and downstream effect.
Fresh validation
Approval does not bypass control. Identity, policy and parameters are checked again immediately before execution.
Continuous evaluation
Test quality, safety and control effectiveness
Task quality
Accuracy, completeness, usefulness and outcome-specific benchmarks
Groundedness
Claim support, citation quality, source currency and unsupported assertions
Retrieval
Precision, recall, permission filtering and malicious-document resistance
Tool use
Tool selection, parameter safety, idempotency and approval enforcement
Security
Prompt injection, indirect injection, data leakage and privilege escalation
Operations
Latency, availability, token use, cost, failure recovery and trace completeness
Operational resilience
Detect, contain, recover and learn
Detect
Alert on abnormal tool calls, data access, model behaviour, cost, latency and control failures.
Contain
Pause the agent, revoke credentials, disable a tool route or restrict the model catalogue.
Recover
Roll back agent, prompt, tool or model versions and validate the last known safe configuration.
Learn
Preserve traces, assess impact, update controls and add the scenario to regression evaluation.
Assurance context
Designed around Australian security expectations
Australian Government
Queensland
Microsoft assurance
Put governance around the agent before it reaches production
DW Data can assess the use case, define its autonomy and control model, prepare the governance artefacts and build the evidence needed for an informed authorisation decision.