Skip to content

Resources

AI Governance Resources

Read by the decision you need to make: define the governance scope, understand agent behavior, or examine what telemetry can establish.

Start with the category foundation to define the scope of your governance program. Use the technical reading to examine a specific question about agent behavior or the evidence available from AI applications.

Category foundations

AI Governance for Real-World Enterprise AI Usage

Connect policy to people, applications, agents, data, tools, and actions. The pillar compares model governance with usage governance and uses a hypothetical workflow to explain where controls and evidence fit.

Read the AI governance pillar

AI Usage Governance: Control How AI Is Used Across the Enterprise

Define permitted uses of approved AI tools, including the conditions for processing information and sharing the result.

Read the AI usage governance pillar

Runtime AI Governance: Apply Policy While AI Is Being Used

Define when a policy decision remains valid, how it can affect execution, and what happens when it cannot be applied.

Read the runtime AI governance pillar

AI Agent Governance: Control What Agents Can Access and Do

Define authority for agent tool calls, approvals, and evidence across an execution path.

Read the AI agent governance pillar

AI Agent Security

Build a threat model around untrusted inputs, available capabilities, and the effects an agent can produce.

Read the AI agent security pillar

Coding Agent Governance

Define the work a coding agent may perform and the execution conditions that apply across workspaces, tools, and runners.

Read the coding agent governance pillar

Enterprise AI Security

Connect human and agent workflows to the resources exposed, the owners who can apply controls, and the evidence needed for security operations.

Read the enterprise AI security pillar

Shadow AI: Discover and Govern Unapproved Enterprise AI Usage

Turn incomplete discovery signals into a scoped policy decision with an owner and a way to verify the result.

Read the Shadow AI pillar

Technical guides

AI Agent Governance Architecture: From Prompt to Action

Follow the request across components and trust boundaries, from a proposed tool call to an attempted action and its evidence.

Read the architecture guide

How to Govern Coding Agents in the Enterprise

Plan a bounded coding agent pilot, verify policy behavior with benign cases, and prepare evidence for operational triage.

Read the coding agent governance guide

What Should Be Logged in an AI Agent Audit Trail?

Specify the records that distinguish authority, policy decisions, attempted actions, and observed results.

Read the agent audit trail guide

Pre-Execution Governance for AI Agents

Choose where a concrete operation can still be withheld, and distinguish an evaluated batch from a changed proposal or partial result.

Read the pre-execution governance guide

MCP Security and Governance for Enterprise AI Agents

Review server selection, tool identity, access permissions, and downstream authority across an MCP workflow.

Read the MCP security and governance guide

Frameworks

The KonaSense Runtime AI Governance Framework

Identify which responsibility, information source, control, or evidence relationship must be resolved to support a governance outcome.

Explore the runtime AI governance framework

AI Agent Governance Maturity Model

Assess demonstrated governance capabilities within a defined scope, keep unverified paths visible, and choose the next result to establish.

Explore the AI agent governance maturity model

Research

Original observations with explicit methods, source records, and interpretation limits. Explore KonaSense Research.

The Anatomy of an Enterprise AI Agent Action

Examine a controlled local file-operation experiment in which the same unavailable caller confirmation accompanies different observed destination states.

Read the controlled agent action field note

Points of view

Why AI Governance Must Move From Models to Actions

Examine who can authorize an agent action, enforce its limits, and account for the evidence.

Read the analysis

Observing an AI Agent Is Not the Same as Governing It

Distinguish a reported policy decision from evidence that the executor applied it.

Read the analysis

Why Prompt-Level Governance Is Not Enough for AI Agents

Examine the facts that emerge as an agent prepares an operation, and keep the initial review within the evidence it actually assessed.

Read the prompt-level governance analysis

The Security Boundary of an AI Agent Is Larger Than the Model

Distinguish findings that remain useful from questions a changed agent configuration has not yet answered.

Read the agent security boundary analysis

Human-in-the-Loop Is a Control, Not a Governance Strategy

Examine what a reviewer can decide, what evidence is missing, and why accepting an exception does not verify an unknown fact.

Read the human-in-the-loop governance analysis

From Discovery to Enforcement: The Eight Layers of Runtime AI Governance

Identify who must establish a policy condition when the agent is known but the decision lacks an accountable source.

Read the discovery-to-enforcement analysis

The Difference Between an AI Incident and an AI Governance Decision

Separate a decision about permission from the evidence and criteria used to investigate a situation or declare an incident.

Read the incident and governance decision analysis

Why AI Agent Audit Evidence Needs More Than a Prompt Log

Trace a copied result and its hashes to their inputs, and distinguish delivery records from observations of an effect.

Read the audit evidence and prompt log analysis

Glossary

AI Governance

Clarify the responsibilities, policies, controls, and evidence that govern AI.

Read the definition

AI Agent Governance

Distinguish delegated authority, permissions, policy decisions, controls, and evidence.

Read the definition

Shadow AI

Distinguish a known application from an approved use of AI.

Read the definition

AI Agent

Understand how an AI agent connects context, decisions, and actions.

Read the definition

Agentic AI

Distinguish delegated choices from decisions retained by people.

Read the definition

AI Control Plane

Separate policy management from where decisions take effect.

Read the definition

AI Usage Governance

Distinguish an approved application from the conditions that authorize a particular use of AI.

Read the AI usage governance definition

Runtime AI Governance

Clarify when a policy decision can affect an interaction and what evaluation alone does not establish.

Read the runtime AI governance definition

Tool Call

Distinguish a request through a tool interface from its dispatch, response, and resulting effects.

Read the tool call definition

MCP

Understand how MCP connects applications to servers and why protocol access does not establish authority over downstream resources.

Read the MCP definition

Human-in-the-Loop

Distinguish supplying information, reviewing work, and authorizing an operation within an AI workflow.

Read the human-in-the-loop definition

Pre-Execution Governance

Identify the operation, decision, and control point while the protected effect can still be withheld.

Read the pre-execution governance definition

Agent Observability

Understand agent activity through telemetry while preserving each observation's source, scope, and limits.

Read the agent observability definition

AI Observability

Distinguish observations of models, applications, and workflows from conclusions that require additional context or evaluation.

Read the AI observability definition

Coding Agent

Distinguish generated development suggestions from the steps an AI system is delegated to select and execute.

Read the coding agent definition

Agent Action

Identify the unit of work and distinguish its proposal, execution attempt, and observed outcome.

Read the agent action definition

Technical reading

What Is an AI Agent, Actually?

Examine how a system's behavior and delegated authority affect the governance question behind the “agent” label.

Read about agent behavior

Observability and Governance for AI Apps on Company Desktops

Explore KonaSense's explanation of the OpenTelemetry path, the context applications export, and the distinction between observing activity and intervening before an action.

Read the OpenTelemetry technical note

For the product connection, explore KonaSense's approach to enterprise AI usage.