Frontier Governancefor AI Agents

Guardrails, scoped identities and audit trails for every agent you run.

Every agent in your company gets a scoped identity, a written policy and a record of what it did. Credentials are brokered per action, so agents never hold standing access. Risky steps wait for a person, and every action lands in a tamper-evident audit trail your auditors can check.

Policy checkheld for approval

Agent requested: scale payments-api to 0 replicas

Identity
Agent identity scoped to the payments namespace
Credential
Brokered for this action only, expires in 15 min
Policy
Production scale-down requires a human approver
Context
Linked investigation, diff and blast radius
Audit
Request, decision and outcome hash-chained to the log

Routed to the on-call approver in Slack

[The work behind every agent]

Teams are adding agents every month.Security still can’t say what they touch.

01The manual work

Review

Security reviews each new agent by hand, hands out long-lived keys and pieces together logs after something goes wrong.

02The agent handoff

Governed by default

Frontier agents run on scoped identities, brokered credentials and written policies, with every action recorded as it happens.

03Your engineers’ role

Set policy

Decide what each agent may do alone, what needs approval and who approves. Change it as trust grows.

[Where CloudThinker fits]

Your stack stays.Agents work inside it.

01Agents in use

Already running

  • AWSAmazon Bedrock agentsModels and agents on AWS
  • AzureAzure AI Foundry agentsAgents built on Azure
  • Google CloudVertex AI Agent BuilderAgents built on Google Cloud
  • GitHubCoding agentsAgents that open pull requests
  • MCPMCP serversTools your agents can call

No change to your agents

02Identity and secrets

Your system of record

  • Okta and Microsoft Entra IDWho owns each agent
  • VaultHashiCorp VaultSecrets and dynamic credentials
  • AWSAWS IAM Identity CenterRoles and permission sets
  • ServiceNowChange and approval records

Source of truth stays put

03Governance

CloudThinkerCloudThinker

  • ScopeOne identity and policy per agent
  • BrokerShort-lived credentials per action
  • GateRisky steps held for a person
  • RecordEvery action in a tamper-evident log

Least privilege by default

04Oversight

Approvals, not surprises

  • SlackSlackApprove or narrow a held action
  • Microsoft TeamsMicrosoft TeamsApprovals inside the thread
  • JiraPolicy exceptions tracked as tickets
  • SplunkAudit log streamed to your SIEM

Every action attributable

Logos show common stacks. CloudThinker governs each agent through the identities and approvals you already run.

[Example scenario]

Wednesday, 15:20. An agent asks for production.Nobody gave it a key. That is the point.

A 150-engineer logistics platform running 6 kinds of agents across AWS and EKS, with Okta, Vault and a CISO who has to sign off on every new one.

  1. 15:20

    Agent requests an actionAgent

    During an incident, an agent proposes scaling payments-api to 0 replicas in prod-eu to stop a retry storm.

  2. 15:20

    Policy check runsAgent

    Policy says scale-to-zero in production needs a human. The request is held. No credential is issued yet.

  3. 15:21

    Context sent to the approverAgent

    The on-call approver gets the action, the evidence behind it, the blast radius and the rollback command.

  4. 15:24

    Approver narrows itYour team

    Rejects scale-to-zero, approves scaling to 2 replicas and pausing the retry queue instead.

  5. 15:24

    Scoped credential, one actionAgent

    A credential scoped to that deployment and that queue is issued for 15 minutes, used once, then expires.

  6. 15:31

    Recorded for the CISOAgent

    Request, policy decision, approval, action and outcome written to the audit log as one hash-linked entry.

#agent-approvals4 messages
  • CloudThinker15:21

    Held for approval: scale payments-api to 0 in prod-eu. Reason: retry storm from queue settlement-retry, 18k msgs/min. Blast radius: EU checkout. Rollback: scale to 6.

  • On-call approver15:24

    Not zero. Scale to 2 and pause settlement-retry.

  • CloudThinker15:26

    Done with a 15-minute credential scoped to payments-api and settlement-retry. Error rate back to 0.3%.

  • CloudThinker15:31

    Audit entry AUD-88412 written: request, policy, approval, action, outcome. Credential expired at 15:39.

from request to a narrower, approved action
4 min
standing keys held by the agent
0
audit entry with the full story
1

An illustrative example. Team, systems and times are representative, not a specific customer.

[Frontier governance]

Every agent has an identity.Every action has a record.

One control plane for every agent you run, so a new agent arrives with the same identity, policy and audit rules as the last one, and autonomy grows one approved step at a time.

Scope every identity
Each agent gets its own non-human identity, limited to the systems and actions its job needs.
Broker every credential
Short-lived credentials issued per action through a broker. No standing keys in prompts, code or config.
Gate risky actions
Policy as code decides what runs alone, what needs approval and what is blocked, per environment.
Record everything
Requests, decisions and outcomes written to a tamper-evident log, ready for your auditors.

[What changes]

Same team. Same tools.Far less of the work by hand.

MomentTodayWith frontier agents
A team adds an agentA one-off security reviewOnboarded on the shared policy
Agent accessLong-lived keys with broad scopeBrokered, short-lived and scoped per action
Risky actionsAllowed or blocked by guessworkDecided by written policy, with approvals
After an incidentLogs pieced together by handA tamper-evident record of every step
AuditScreenshots and spreadsheetsEvidence exported from the log

[Integrations]

Connects to the rest of your stack.Read-only to start.

  • AWS IAM
  • AWS CloudTrail
  • Amazon Bedrock
  • Amazon EKS
  • Okta
  • AWS IAM Identity Center
  • GitHub
  • GitLab
  • Slack
  • Microsoft Teams
  • ServiceNow
  • Jira
  • Splunk
  • Datadog

[Adoption path]

One pilot.Then company-wide.

The rollout follows the four phases of the AWS Cloud Adoption Framework, so it fits the plan your cloud team already runs.

  1. 01Envision

    Map the agents you run

    List every agent, what it can reach and how it authenticates. Start with the one closest to production.

  2. 02Align

    Write the policy

    Agree what agents may do alone, what needs approval and who approves, per environment.

  3. 03Launch

    Move agents onto the control plane

    Replace standing keys with brokered credentials, and run every agent on the same policy and audit trail.

  4. 04Scale

    Make it the default

    New agents can only reach production through the control plane. Autonomy grows as each agent earns it.

[Customer proof]

MSM.Results on the record.

A Vietnamese digital transformation partner moved from AI-assisted delivery to governed AgenticOps, with brokered access, per-environment approvals and tamper-evident audit logs for every agent action.

Read the case study
less production incident noise
95%
lower tooling cost through consolidation
63%

[Trust and control]

Agents do the work.Your team keeps control.

You approve every change
Agents propose. Nothing touches production until someone on your team says yes, and you set that rule per system.
Every action on the record
Each step is logged, attributed and reversible, ready for your auditors.
Certified for enterprise
SOC 2 Type II and ISO 42001, with reports in our trust center.
Runs where you need it
In our cloud, through AWS Marketplace, or inside your own account.

[Questions]

What teams askbefore they start.

Can we start without giving agents write access?
Yes. Most teams start read-only, with every write action held for approval. Autonomy grows one action type at a time, as the record shows it is safe.
Where do credentials live?
In your own secret store or identity provider. The broker issues short-lived credentials per action, so agents never hold long-lived keys.
Who decides what an agent may do?
Your team does, in a written policy per environment. Actions can run alone, wait for an approver, or be blocked outright.
Can auditors check the log?
Yes. Every request, decision and outcome is written to a tamper-evident log, and evidence can be exported for SOC 2 or ISO reviews.

Give every agent an identity.Keep every action on the record.

Start with the agent closest to production. See its access, policy and audit trail in one place before you scale to the rest.

  • A CloudThinker team member holding a card reading "up to $200K active AWS credits"

    Up to $200K in AWS credits

    Applied to your own AWS account.

  • A CloudThinker team member presenting the AWS Partner AI Services Competency badge for Agentic AI Consulting Services

    AWS AI Services Competency

    Validated for Agentic AI Consulting.

  • An engineer approving a request beside a global operations map, an uptime dial, and HIPAA, GDPR and SOC compliance marks

    Covered 24/7, on your approval

    Under HIPAA, GDPR and SOC 2 controls.