Skip to content
GOVERNED AGENT RUNTIMEUPDATED 2026-09-29

What is a governed AI agent runtime?

THE SHORT ANSWER

A governed AI agent runtime is the software layer that runs AI agents inside an organisation’s rules. The agent can read, reason and propose freely, but every action it wants to take — updating a record, sending an email, moving money — is checked against what the person who asked is allowed to do, held for a named approver when it is risky, and written to a record that cannot be quietly changed.

Why an agent needs a runtime, not just a model

A model produces text. Acting on a business system needs much more around it: an identity, permissions, credentials, a way to ask a person, and a record of what happened. Without a runtime, every team wires those pieces by hand — and the usual shortcuts are a bot account with standing access, an API key pasted into a prompt, and a log nobody can trust.

A runtime makes those pieces part of the platform, so every agent gets them the same way and no agent can skip them.

What a governed runtime does

  • Identity first: it knows who asked, for which company and department, before anything runs.
  • Permission before action: a proposed action is only an intent. It runs if the requesting person may do it — the agent inherits no authority of its own.
  • Human approval where it matters: actions your policy marks as consequential wait for a named approver, with quorum and separation of duties.
  • One way to the outside: tools and other agents are reached only through a gateway that checks each call and keeps credentials out of the model’s sight.
  • Isolation: one company’s data and agents cannot see another’s — enforced in the database, not only in code.
  • Evidence: each decision and result is recorded with the change itself, in a tamper-evident chain.
  • Bounds: iteration, time and cost budgets, so a run stops and says why.

Runtime, framework and orchestration are different things

An agent framework is a library for writing agent logic — prompts, tool calling, memory. Orchestration decides the order in which steps or agents run. A runtime is where that logic actually executes, and the only place a rule can be enforced rather than requested. You can bring agent logic from anywhere; the runtime is what decides whether its actions happen.

Who needs one

Any organisation where an agent’s action could move money, reach a customer or patient, change production systems, or create a record a regulator will read: banking and payments, insurance, healthcare payers, mortgage servicing, security operations — and increasingly any enterprise putting agents on real work rather than on drafts.

HOW A2A MATRIX DOES IT
  • Fifteen Rust services keep execution, authority and evidence apart, so no single component can widen its own reach.
  • Self-hosted: it runs beside your own Postgres, Redis, vector store, object storage and identity provider.
  • Multi-tenant by design, with separation enforced by PostgreSQL row-level security.
  • Your choice of models — commercial or self-hosted — tools over MCP, and other agents over the A2A protocol.
See the services that make up the runtime
QUESTIONS

Asked often.
Answered plainly.

Is a governed runtime the same as an AI agent framework?+

No. A framework helps you write agent logic; a runtime is where that logic runs and the only place rules about who may do what can be enforced. They work together.

Does governance slow agents down?+

Reading, reasoning and preparing run at machine speed. Only the actions your policy marks as consequential wait for a person, and that wait is the point.

Can we use our own models?+

Yes. Commercial and self-hosted models are registered as configuration — any endpoint that speaks the OpenAI chat format — and each company can use its own keys from its own vault.

Where does it run?+

In your estate: your cloud account or your datacentre, next to your own databases and identity provider. No data has to leave for the platform to work.