AI Governance
Identity per agent, autonomy tiers, and audit trails your risk and security teams will actually accept.
The two questions an auditor asks first are which agents are running and what each one is allowed to do. Most organisations deploying AI agents cannot answer either, because the agents share a service account, their permissions are whatever that account holds, and the record of what they did is an application log written for debugging.
This is not a documentation problem. An agent that inherits broad credentials is genuinely over-permissioned, and no policy written afterwards changes what it can reach.
Governance means the platform produces the evidence as a by-product of running, rather than the evidence being assembled for the audit.
What the engagement includes
Agent identity model
Every agent as a first-class principal with its own identity and scoped credentials, rather than a shared service account. Workload identity federation and SPIRE where the estate supports it.
Tiered autonomy
Explicit tiers governing what an agent may do unattended, what requires approval, and what is prohibited — with autonomy granted per action rather than assumed from a role.
Policy as code
Authorisation decisions expressed as versioned, testable policy and enforced at runtime, so a permission change is a reviewable pull request.
Audit trail
Every agent action recorded with its identity, inputs, decision, and outcome, in an append-only store the application cannot rewrite.
Framework evidence
Controls mapped to NIST AI RMF and ISO 42001, with the evidence pack a reviewer needs assembled from what the platform already produces.
Who this is for
- Organisations with agents in production and no per-agent identity
- Risk and compliance functions asked to approve autonomous systems
- Teams facing an audit, customer security review, or regulatory question about AI
When this is the wrong engagement: If you have not deployed agents yet, governance is cheaper to design in than to add. Enterprise AI architecture is the better starting point.
How it runs
- Discovery (30 minutes). A working call to map your stack, constraints, and the highest-value first step. No pitch deck.
- Scoped fixed-price proposal. A written statement of work with deliverables, milestones, and a fixed price — not an open-ended time-and-materials meter.
- Delivery. Senior architects execute against milestones, with governance applied to every AI-agent action from day one.
- Operate or hand off. Monitored operation, or a clean handoff with runbooks so your team can run it without us.
Questions we get asked
Is this a policy document or working controls?
Working controls. A governance policy that the platform does not enforce is a description of intentions, and auditors have learned to test the difference. The engagement delivers the identity model, the authorisation policy, and the audit trail as implemented components, with written policy documenting what was built rather than substituting for it.
What is tiered autonomy in practice?
Each agent action is classified by blast radius and reversibility. Low-tier actions — reading, drafting, analysing — run unattended. Middle-tier actions that change state run with an approval gate or within bounded limits. High-tier actions that are irreversible or externally visible require explicit human authorisation every time. The tier is enforced by policy at runtime, not by the agent choosing to comply.
Does governance slow delivery down?
It slows the first agent and speeds up every one after it, because the identity, authorisation, and audit machinery is built once. The alternative pattern — ship agents fast, retrofit governance under audit pressure — is materially slower overall, and the retrofit usually requires re-architecting how agents get credentials, which is the expensive part.
How does this map to NIST AI RMF and ISO 42001?
Controls are mapped to both, and the mapping is delivered as part of the evidence pack. To be explicit about what that means: Citadel delivers against these frameworks and does not represent itself as certified in them. The mapping shows a reviewer which of their expectations each implemented control satisfies, which is what they need to complete their own assessment.
Related services
AI Security Consulting
Threat modeling for LLMs, data pipelines, and model endpoints — plus the controls to close the gaps.
Multi-Agent Systems
Fleets of governed agents coordinated around real workflows — not a demo that stalls after the meeting.
Enterprise AI Strategy
A board-ready roadmap from where you are today to governed AI in production — sequenced by value and risk.
Start with a 30-minute discovery call
No pitch deck. We map your constraints and tell you the highest-value first step — including when that step is not an engagement with us.
Book a discovery call