DW Agent Governance

Governance, sovereignty and security

A practical governance system for production agents: accountable owners, risk-based autonomy, explicit permissions, versioned controls, continuous evaluation and evidence that survives audit.

Control objective

Agentic AI without uncontrolled autonomy

Governance defines who is accountable, what an agent may do, which information it may process, how its behaviour is tested and when a human must intervene.

Clear accountability

Named business, technical, security and data owners with defined decision rights and escalation paths.

Explicit authorisation

User, agent, model and tool identities with permissions that can be reviewed, changed and revoked.

Risk-based autonomy

Autonomy matched to impact, reversibility, data sensitivity and the strength of available controls.

Continuous oversight

Monitoring, evaluation, incident response and human intervention throughout the production lifecycle.

Lifecycle governance

Govern the system from use-case assessment to retirement

Controls begin before a model is selected and continue after deployment. Material changes to data, tools, models, autonomy or impact trigger reassessment.
  1. 01

    Assess

    Define purpose, affected people, data, decision impact, autonomy, legal obligations and measurable benefit.

  2. 02

    Design

    Select architecture controls, model policy, identities, tools, approval points and evidence requirements.

  3. 03

    Assure

    Threat model, privacy assessment, security testing, evaluation and business acceptance before release.

  4. 04

    Authorise

    Record accountable decisions, conditions, known limitations, residual risk and operational ownership.

  5. 05

    Operate

    Monitor behaviour, access, cost, quality and incidents while controlling changes to models and tools.

  6. 06

    Review or retire

    Reassess on material change, revoke access, preserve required records and decommission safely.

Threat-informed design

Controls for the failure modes that matter

Agent risk is not limited to inaccurate text. It includes malicious instructions, excessive agency, unsafe tool use, sensitive disclosure, compromised integrations and untraceable actions.

Agent threat-to-control map

DW Data reference pattern

Prompt and indirect injection

Content isolation, source trust, injection detection and tool separation

Excessive agency or permissions

Autonomy classification, least privilege and operation allow-lists

Sensitive data disclosure

Classification, minimisation, security trimming and model routing

Unsafe parameters or actions

Schemas, deterministic validation, transaction limits and approval gates

Compromised tools or supply chain

Tool registry, signed delivery, scanning, monitoring and kill switch

Hallucinated outcomes

Grounding, evaluation datasets, validation and human oversight

Controls are selected using the use case, data classification, autonomy level, threat model and customer risk appetite.

Threat modelling is tailored to the agent's actual data, tools, operating environment and autonomy. Controls are tested with adversarial inputs and realistic end-to-end scenarios rather than prompt checks alone.

Governance artefacts

Registers make control ownership visible

DW Data establishes a connected system of records so governance teams can answer what exists, who owns it, what changed and what evidence supports continued operation.

Agent register

Owner, purpose, status, autonomy, environments, risk rating and review dates for every agent.

Data source register

Classification, custodian, permissions, retention, retrieval method and approved agent uses.

Tool register

Operations, schemas, credentials, transaction limits, approval policy and system owner.

Model register

Provider, version, deployment type, processing boundary, approved use cases and evaluation status.

Instruction register

Versioned system instructions, safety policy, owner, change history and regression evidence.

Evaluation register

Datasets, thresholds, results, known limitations, release decisions and residual risks.

DW Agent Card

A readable control record for each agent

The Agent Card connects policy to a specific production system. It is concise enough for executives and service owners, but precise enough to direct security, engineering and operational controls.
  • Business owner and intended purpose
  • Autonomy level and approval rules
  • Models, data sources and tools
  • Permitted and prohibited actions
  • Evaluation status and known limitations
  • Audit coverage and review dates

DW Agent Card

Procurement Contract Agent

A1 - Drafting
Owner
Procurement Operations
Model
Approved enterprise model
Data
Contract and supplier information
Tools
Fabric Query API, Procurement API, Document Search

Can

  • Search contracts and supplier information
  • Analyse obligations, spend and expiry risk
  • Generate recommendations and sourcing briefs

Cannot

  • Approve purchases
  • Change supplier master data
  • Create or release payments

Human approval: Purchase recommendation release

Audit: 100% tool invocation logging

Human oversight

Approval is an architectural control

A human-in-the-loop design must identify the right decision maker, present enough context for a meaningful decision and preserve the approval as part of the action trace.

A2 - approval required

DW Data reference pattern

Agent

Prepares action

Proposed transaction

Structured and validated

Human review

Approve or reject

ApproveReject

Security Gateway

Revalidates policy

Enterprise system

Executes authorised action

The model proposes; an authorised person decides. Approval context and the final execution result are recorded as part of the same trace.

Authorised reviewer

Approvals are restricted to people with the right role, delegated authority and separation from incompatible duties.

Decision context

The review includes source evidence, proposed parameters, risk flags, model output and downstream effect.

Fresh validation

Approval does not bypass control. Identity, policy and parameters are checked again immediately before execution.

Continuous evaluation

Test quality, safety and control effectiveness

Evaluation datasets become part of the release and operational process. Thresholds are tied to the business outcome and risk rather than a single generic accuracy score.

Task quality

Accuracy, completeness, usefulness and outcome-specific benchmarks

Groundedness

Claim support, citation quality, source currency and unsupported assertions

Retrieval

Precision, recall, permission filtering and malicious-document resistance

Tool use

Tool selection, parameter safety, idempotency and approval enforcement

Security

Prompt injection, indirect injection, data leakage and privilege escalation

Operations

Latency, availability, token use, cost, failure recovery and trace completeness

Operational resilience

Detect, contain, recover and learn

Agent incidents need clear ownership and fast intervention. DW AgentOps incorporates anomaly detection, access revocation, tool disablement, kill switches, rollback and evidence preservation.

Detect

Alert on abnormal tool calls, data access, model behaviour, cost, latency and control failures.

Contain

Pause the agent, revoke credentials, disable a tool route or restrict the model catalogue.

Recover

Roll back agent, prompt, tool or model versions and validate the last known safe configuration.

Learn

Preserve traces, assess impact, update controls and add the scenario to regression evaluation.

Assurance context

Designed around Australian security expectations

Framework mapping is scoped to the customer and workload. Links below point to the authoritative sources used to shape the service.
No implied certification: DW Data does not claim that this service is IRAP certified, ISO certified or government accredited. Architectures can be designed within IRAP-assessed Azure environments and mapped to relevant controls. Customer accreditation, classification and system authorisation remain required.
From concept to controlled production

Put governance around the agent before it reaches production

DW Data can assess the use case, define its autonomy and control model, prepare the governance artefacts and build the evidence needed for an informed authorisation decision.