Executive Summary
Agentic artificial intelligence changes the enterprise control problem. A generative model primarily produces information. An agentic system can be designed to select tools, retrieve data, invoke APIs, modify records, coordinate workflows or initiate actions. The difference is not merely a new interface; it is a shift from output generation toward delegated authority.
As authority expands, organizations need a control plane around the agent. Identity, permissions, data boundaries, tool access, approval thresholds, logging, monitoring, incident response and termination controls become part of the system architecture.
In May 2026, the Canadian Centre for Cyber Security joined international partners in publishing guidance on the careful adoption of agentic AI services. The guidance emphasizes layered defence, strict access controls, secure development and secure operation. That direction reinforces a broader institutional principle: autonomy should increase only when the surrounding control environment can support it.
01 — From model output to action authority
Traditional software generally executes predefined logic under explicit user or system permissions. Generative AI added probabilistic outputs to that environment. Agentic systems can add another layer by deciding how to pursue a goal and which tools to use within a defined environment.
This creates a new risk boundary. A poor model response may be visible to a user and corrected before action. An agent with tool access can potentially turn an incorrect interpretation into an external change: sending a message, updating a customer record, initiating a transaction, modifying code or triggering another system.
The security and governance question therefore becomes: what is this agent allowed to do, under whose authority, with which data, and with what evidence of its activity?
02 — The emerging agent control plane
An enterprise agent control plane can be understood as the set of technical and organizational mechanisms that sit between an agent’s reasoning process and the systems it can affect. It does not need to be one product. In many organizations it will be a collection of identity, security, orchestration, logging, policy and approval services.
A mature control plane should be able to answer several questions continuously: Which agent is acting? Who owns it? Which model and version are involved? What data can it retrieve? Which tools can it call? What action is it attempting? Does that action require human approval? What happened after execution? Can the activity be reconstructed later?
03 — Agent identity becomes a security primitive
Human users already operate inside identity and access management systems. Service accounts and applications also have identities. Agentic AI extends the need for machine identity because an agent may act on behalf of a user, team or business process while making intermediate decisions independently.
Persistent identification makes accountability possible. An enterprise should be able to distinguish one agent from another, connect the identity to an owner and purpose, and revoke its authority without dismantling the entire surrounding application.
The identity record can also carry attributes such as environment, risk tier, permitted tool set, transaction limit, approval requirements and credential expiration. This is analogous to existing identity governance but applied to increasingly autonomous software actors.
04 — Least privilege must include tools and actions
Least privilege is a familiar cyber-security principle, but agents require a more granular interpretation. Access should not be defined only by which database or application the agent can reach. The organization should also consider which operations are permitted inside those systems.
An agent may need to read an account balance without being able to initiate a payment. It may need to create a draft without being able to publish it. It may search a knowledge base without gaining broad access to every underlying repository. Tool design should expose only the minimum functions required for the intended workflow.
05 — Retrieval creates another trust boundary
Many enterprise agents rely on retrieval-augmented generation or other data-access mechanisms. Retrieval improves relevance, but it also introduces questions around authorization, source quality, stale content, prompt injection and data leakage.
The agent should not obtain broader information rights simply because retrieval is technically convenient. Access controls need to follow the underlying user, role or business purpose where appropriate. High-risk actions may also need source provenance: the organization should be able to determine what information materially influenced the action.
06 — Human approval should be engineered, not assumed
“Human in the loop” is often used as a general safeguard, but its effectiveness depends on design. A person cannot provide meaningful oversight if the approval request arrives without context, if the system produces too many alerts, or if the action is difficult to reverse.
Approval thresholds should therefore be tied to consequence and uncertainty. Low-risk reversible actions may operate with broad automation. Material financial, legal, safety, privacy or security consequences can require explicit authorization. The interface should show the proposed action, relevant evidence, affected systems and any material uncertainty.
07 — Auditability requires more than chat history
Conversation logs alone are insufficient for agentic systems. An activity record should capture the agent identity, user or process that initiated the task, model or service involved, tools called, data sources accessed, approvals obtained, actions attempted, outcomes, errors and material policy decisions.
This creates a basis for security investigations, compliance review, performance analysis and operational improvement. It also helps distinguish model error from integration error, permission misuse or downstream system failure.
08 — Agentic systems require continuous operation controls
Agent behaviour can change when the underlying model changes, when system prompts are modified, when tools are added, when retrieval sources change or when business processes evolve. Governance therefore cannot end at deployment.
Organizations need change management, periodic re-evaluation, anomaly monitoring, credential rotation, incident procedures and the ability to reduce or revoke autonomy. The Canadian Cyber Centre’s agentic AI guidance explicitly treats secure operation as a continuing responsibility rather than a one-time design decision.
09 — A practical adoption sequence
- Start with bounded workflows. Choose tasks with clear goals, known systems and reversible outcomes.
- Establish identity and ownership. Every production agent should have a named organizational owner and a distinct technical identity.
- Constrain tools and data. Grant only the access required for the specific workflow.
- Define approval thresholds. Connect human authorization to material consequence, not to arbitrary workflow steps.
- Capture complete activity records. Make actions reconstructable.
- Test failure modes. Evaluate prompt injection, tool misuse, data leakage, incorrect action selection and unexpected downstream effects.
- Increase autonomy gradually. Expand authority only when evidence demonstrates that the surrounding controls are effective.
10 — Research view
The long-term enterprise importance of agentic AI may be less about whether agents can reason like people and more about whether institutions can delegate bounded authority to software safely. That makes agentic AI a convergence point for identity, cybersecurity, application architecture, governance and operational risk.
A useful design principle is therefore: every production agent should have an identity, an owner, an explicit authority boundary and a complete activity record.
11 — Limitations
Agentic AI remains an evolving category. Product capabilities, definitions and levels of autonomy vary widely. This paper describes an enterprise control model and does not imply that every agent requires the same architecture or risk treatment. Sector-specific legal, privacy, security and safety requirements may impose additional controls.