As agent-based solutions are increasingly deployed across virtually every aspect of the modern operating environment, organizations are facing an exponential growth in operating entities that need oversight. More specifically, as work constructs shift from a human-centric model to an agent-centric one, historical operating models such as RBAC, need to be reconstructed into more discrete atomic elements that can scale to meet the security and governance needs of a growing agentic operating model.
To date, data and system access controls policies have been aligned to specific job responsibilities. This “human-centric” model created context that could then be applied to security and governance controls to determine suspicious, malicious, or unintended system behaviors.
As this human-centered process is deconstructed and AI agents are reconstructed to carry out new machine-scoped units of work, access controls must become more fine-grained and dynamic, based on the intent and context of a specific agent’s usage. Because context continuously changes, agentic security and governance controls will require access to up-to-date, contextual policy and operating guardrails.
The challenge is that this contextual knowledge has not been embedded in systems to date but instead has been owned and managed by the people responsible for individual functions, depending on their roles and responsibilities.
So, while AI models are becoming more capable in problem solving and action planning, without the right level of contextual policy and operating requirements, agents lack the ability to align security and governance properly. As a result, agents can potentially make bad decisions without the proper context around identity, policy, workflow state and decision history.
This security and governance gap becomes increasingly visible as AI agents initially designed and deployed to operate within narrow use cases are then further utilized within additional use cases over time. This dynamic is like a person taking on new responsibilities in a new environment that has its own policies and procedures, requiring a context shift for the person.
Providing AI agents with the necessary context to support security and governance requirements: Where this context comes from
Traditional automation solutions have a long history of providing a static framework for defining workflows, decision trees and ownership models for every workflow and work unit. These systems were designed to support and improve individual and team collaboration, escalation and outcome management.
In the process, workflow automation tools have been tracking usage patterns, contextual dependencies and patterns, resulting in a sizable contextual understanding of policy and operating patterns.
As the world shifts to a more agentic AI operating environment, this rich dataset is ripe for use in providing agents with context around dependencies, data and functional access requirements, regulatory requirements and risk visibility.
This creates an opportunity for organizations to harvest rich, historical context and make it available to new agent-based solutions that are replacing prior human-driven workflows.
It’s worth noting that this context is and will continue to be, continuously changing, requiring ongoing management and stewardship of this important dataset. Moving forward, every AI interaction, resolution, approval and escalation will strengthen a richer understanding of how an organization operates.
Architectural considerations
As agent architecture evolves, inter-agent communications models are becoming core to operating models. Model Context Protocol (MCP) servers; Agent2Agent (A2A); Agent Communication Protocol (ACP) and other emerging mechanisms are paramount to providing access to functions and datasets.
Workflow and automation solution vendors are advancing platforms to enable agents to access critical contextual information.
As AI solutions increasingly replace traditional automation solutions and organizations reengineer systems and workflows, the requirements for oversight, governance and security are changing and increasing. Personnel requirements are changing as well, requiring new operational management skills for working together with agent-based solutions. While what’s needed to support governance and security for agentic solutions is still emerging, human-based governance and security requirements continue to evolve as the machine-human operating model also evolves.
Conclusion
As AI models become increasingly intelligent and continue to commoditize intelligence, the models’ surroundings become scarce resources:
- The enterprise context that grounds AI in reality.
- The security and governance that makes it safe.
- The execution infrastructure that turns insight into action.
Leading model providers increasingly acknowledge that the real breakthrough comes from the context and integration wrapped around the model.
The more capable the agent becomes, the more it depends on identity resolution, entitlements, workflow constraints, integration governance, audit evidence and change management. In addition, context isn’t complete without understanding how an organization operates on a day-to-day basis: Who's connected to whom, who collaborates on what and what skills exist and where?
Context matters.