Skip to contentThe Observability LayerSearch

Enterprise handbook · Section 5 of 30

3. Enterprise governance and the lifecycle

3.1 Integrate agents with existing enterprise decisions

The enterprise needs a business owner for the complete process, a platform owner for the deployed controls, resource owners for the systems changed, and independent challenge appropriate to the risk. Responsible AI, security, privacy, compliance, model validation, procurement, operations, and audit should have clear interfaces. A committee without explicit decision rights cannot substitute for these responsibilities.

NIST AI RMF 1.0 organizes risk work through GOVERN, MAP, MEASURE, and MANAGE. In plain terms, establish ownership and policy; understand the use and impacts; evaluate evidence; and decide how to treat risks. NIST reports that AI RMF 1.0 is being revised. This book refers to the inspected 1.0 baseline and does not imply that a completed replacement has been adopted. [S43, S47]

The following lifecycle is the handbook's proposed operating implementation. Its gates are distinct decisions with named owners, not a claim that a particular standard prescribes these exact stages.

Figure 3. Enterprise lifecycle and evidence renewal

Open figure at full size ↗

Figure 3. Enterprise lifecycle and evidence renewal

Figure 3. Proposed lifecycle. The enterprise approves the use before building, the bounded configuration before production, and the affected evidence again after material change or incident. Retirement includes credentials, memory, queued work, retention, and business continuity.

Evidence table: Gate, Decision, Required evidence, Accountable operating role
GateDecisionRequired evidenceAccountable operating role
IntakeIs an agent appropriate for this purpose?Benefit, simpler baseline, affected people, consequence and legal scope.Business process owner.
DesignWhich actions, data, controls, and oversight will be permitted?Mandate, architecture, effect inventory, impact assessment, test plan.Business owner with platform and resource owners.
ReleaseDoes this configuration earn its requested authority?Tests, failures, utility, rights review, monitoring and recovery evidence, independent challenge.Delegated release authority under enterprise policy.
OperationDoes evidence still support the operating mandate?Reconciled effects, drift, customer outcomes, incidents, review capacity.Business and operations owners.
Change or incidentWhich claims expire, and what can safely continue?Materiality assessment, affected coverage, containment and retest results.Change or incident authority with independent challenge.
RetirementCan the system be withdrawn without leaving active authority or lost obligations?Revoked grants, stopped descendants and queues, data disposition, transition and evidence custody.Process and platform owners.

3.2 Give the governing body a decision pack

the sources cited here should state the permitted mandate, action classes and autonomy; critical dependencies; evidence for the main control claims; unresolved failures and unknowns; customer and workforce impacts; exception owners and expiry; containment capability; and the next decision requested. Distinguish tested mechanisms from vendor assertions and planned work.

An executive should be able to ask who can stop the workflow, whether the stop mechanism was exercised, and what remains active after the agent process stops. An auditor should be able to select a completed case and join its resource effect to authority, approval, deployment configuration, and independent outcome verification.

3.3 Account for people, intellectual property, and resource use

Assess the work transferred to reviewers and service teams, training needs, accessibility, overreliance, and the effect of new performance expectations. Obtain feedback from affected people through permitted channels. Track burden and correction outcomes rather than equating faster automated output with improved service.

Record permissions and restrictions for retrieved content, licensed data, code, and generated deliverables. A citation identifies a source; it does not itself confer a license to reuse the source. Procurement and legal review should determine applicable rights and contractual constraints.

For resource use, measure calls, tool invocations, compute where observable, retries, and cost by workflow. Treat supplier energy or water data as measured or estimated according to its actual provenance; do not convert token counts directly to a claimed carbon footprint without a valid model. NIST's GenAI Profile includes environmental impact and intellectual-property risk, among other concerns. The measurement design here is proposed practice. [S44]

3.4 Govern the change in the work, not only the software

Training should explain the agent's role, common failure mechanisms, review rights, evidence sources, escalation route, and permitted overrides. Reviewers should practice correction rather than only acknowledging a policy. Changes in staffing, task mix, customer channel, or workload can invalidate oversight assumptions even when the software is unchanged.