
The layer inside the control plane
“Control plane” has become a broad category: connecting agents, orchestrating them, observing them, securing them. Underneath all of it sits the layer that decides and proves what an agent is actually allowed to do. That layer determines whether an agent can be trusted to act at all, and it has to work across organisations, not only inside one company’s estate. Forrester’s Leslie Joseph set out the frame that makes this legible: a three-plane view of enterprise agentic architecture, build, orchestrate and control, with governance sitting inside the control plane, outside build and orchestration. (Forrester, “Agent Control Planes Still Need A Robust Standards Stack”, March 2026). Within that control plane, authority is a distinct layer. It covers what an agent is allowed to do, not where it can go or how it does its work.Declare, enforce, prove, see
An Authority Control Plane does four things. It declares authority centrally, so grants live in one place instead of scattered across scripts and service accounts. It enforces that authority at the point of action, at the runtime or gateway the agent already passes through, rather than after the fact in a log review. It produces a receipt for every decision, one a partner or a regulator can check without needing access to internal systems. And it lets an organisation see the whole estate: which agents exist, what authority each holds, what they have attempted, and what was allowed or blocked. That last part is governance observability, which is a different job to operational telemetry. OpenTelemetry’s genAI conventions are getting better at describing what happened inside a model call or a tool execution. They do not tell you who authorised an action in governance terms, or under what grant. Instrumentation records behaviour. Declare, enforce, prove and see records authority.Four primitives
Four primitives sit underneath the layer: identity, authority, intent and action. Every governed action has to answer three questions. Who authorised this. On whose behalf. Under what authority. Intent needs a careful line. An Authority Control Plane binds and verifies structured intent, so the action that executes matches the request that was authorised. It does not resolve what an ambiguous instruction meant in the first place. That is an upstream problem for the model and the orchestration layer.Seen, verified, proven
Any organisation can place its own agent estate on a three-rung ladder. Seen means the agent is known and inventoried. It is in a registry somewhere. Nothing about it is proven. Verified means the agent is bound to a real, verified business through a chain of accountability, so you know who stands behind it. Proven means every action it takes is checked against its authority at the point of execution, and leaves behind a receipt anyone can verify. Most agent tooling stops at seen. Some reaches verified. Very little reaches proven, and that is where the market is heading. Enforcement is becoming table stakes. Proof is where the differentiation sits.Why it is distinct
Access control decides which systems an agent can reach. An Authority Control Plane decides what it is allowed to do once it is there. Orchestration decides how an agent does its work, which tools it calls and in what order. An Authority Control Plane decides whether it should be doing that work at all. Observability records what happened, after it happened. An Authority Control Plane decides and proves what was allowed, in real time. Model governance shapes how a model was built and trained. An Authority Control Plane governs the specific authorisations an organisation grants as the agent acts.Enforcement is becoming common. Proof is not.
Plenty of tools can now pause or block an agent’s action at runtime. That is necessary, and it is no longer rare. What is still missing is authority that travels: a verified chain behind the agent that says who it is really acting for, enforcement at the exact moment it acts, and a receipt a customer owns that a partner or regulator can check for themselves, without access to internal systems or logs, because the receipt carries hashes rather than values. A wave of runtime security tooling has grown up around agent development, built into the environment an agent runs in rather than travelling with it. That is a sign the market has caught up to the enforcement half of the problem. What happens once an agent, or its receipt, leaves that environment is the other half: a chain of accountability and a proof a partner or regulator can verify on their own infrastructure, without trusting anyone else’s. The two sit well together in a stack. Only one of them produces proof that travels with the agent.Why now
Agents are moving off pilots and onto real actions with real consequences. DORA is already in force. The EU AI Act is phasing in across 2026 and 2027, and the Commission published guidance on high-risk classification in May 2026. Agent estates are sprawling across clouds and vendors faster than anyone can govern by hand. Forrester’s own polling reflects the pressure: in a February 2026 survey of 47 vendors, 79% already recognise agent control planes as a distinct category. What that poll does not settle is who governs authority within it, and proves it.What good looks like
Authority declared centrally. Enforcement in the path of the action, at the runtime or gateway the agent already uses, rather than bolted on afterwards. Portable proof. A verified chain behind the agent. Service meshes made the shape familiar: a control plane where authority is declared, changed and audited, and an enforcement plane, the actual points in the path of action where that authority gets applied. None of this needs a proprietary format. A layer built to govern AI at the point of execution can sit on open primitives, decentralised identifiers and verifiable credentials, running over MCP and the agent protocols forming around it. Open primitives are what make authority enforcement portable rather than another platform lock-in. A receipt has to outlive whatever vendor issued it, or it is not proof, it is another log.Honest boundaries
An Authority Control Plane is not orchestration, not telemetry, not access control and not model governance. It does not stop a prompt injection. It stops the unauthorised action the injection is trying to cause, so even a compromised agent cannot do what it was never authorised to do. Revocation is enforced live, at the point of action. Making non-revocation status verifiable fully offline, without a live check, is still a frontier the standards have not settled. Authority is the layer that moves an agent estate from seen to proven. As agents take on real actions, it is the layer that decides whether they can be trusted to act at all.Nuggets is the trust infrastructure for AI actions. If your organisation is deploying AI at High or Critical risk tier and needs to close the governance gap, we’re happy to talk.