Start with the category foundation to define the scope of your governance program. Use the technical reading to examine a specific question about agent behavior or the evidence available from AI applications.
Category foundations
AI Governance for Real-World Enterprise AI Usage
Connect policy to people, applications, agents, data, tools, and actions. The pillar compares model governance with usage governance and uses a hypothetical workflow to explain where controls and evidence fit.
AI Usage Governance: Control How AI Is Used Across the Enterprise
Define permitted uses of approved AI tools, including the conditions for processing information and sharing the result.
Read the AI usage governance pillar
Runtime AI Governance: Apply Policy While AI Is Being Used
Define when a policy decision remains valid, how it can affect execution, and what happens when it cannot be applied.
Read the runtime AI governance pillar
AI Agent Governance: Control What Agents Can Access and Do
Define authority for agent tool calls, approvals, and evidence across an execution path.
Read the AI agent governance pillar
AI Agent Security
Build a threat model around untrusted inputs, available capabilities, and the effects an agent can produce.
Read the AI agent security pillar
Coding Agent Governance
Define the work a coding agent may perform and the execution conditions that apply across workspaces, tools, and runners.
Read the coding agent governance pillar
Enterprise AI Security
Connect human and agent workflows to the resources exposed, the owners who can apply controls, and the evidence needed for security operations.
Read the enterprise AI security pillar
Shadow AI: Discover and Govern Unapproved Enterprise AI Usage
Turn incomplete discovery signals into a scoped policy decision with an owner and a way to verify the result.
Technical guides
AI Agent Governance Architecture: From Prompt to Action
Follow the request across components and trust boundaries, from a proposed tool call to an attempted action and its evidence.
How to Govern Coding Agents in the Enterprise
Plan a bounded coding agent pilot, verify policy behavior with benign cases, and prepare evidence for operational triage.
Read the coding agent governance guide
What Should Be Logged in an AI Agent Audit Trail?
Specify the records that distinguish authority, policy decisions, attempted actions, and observed results.
Read the agent audit trail guide
Pre-Execution Governance for AI Agents
Choose where a concrete operation can still be withheld, and distinguish an evaluated batch from a changed proposal or partial result.
Read the pre-execution governance guide
MCP Security and Governance for Enterprise AI Agents
Review server selection, tool identity, access permissions, and downstream authority across an MCP workflow.
Read the MCP security and governance guide
Frameworks
The KonaSense Runtime AI Governance Framework
Identify which responsibility, information source, control, or evidence relationship must be resolved to support a governance outcome.
Explore the runtime AI governance framework
AI Agent Governance Maturity Model
Assess demonstrated governance capabilities within a defined scope, keep unverified paths visible, and choose the next result to establish.
Explore the AI agent governance maturity model
Research
Original observations with explicit methods, source records, and interpretation limits. Explore KonaSense Research.
The Anatomy of an Enterprise AI Agent Action
Examine a controlled local file-operation experiment in which the same unavailable caller confirmation accompanies different observed destination states.
Read the controlled agent action field note
Points of view
Why AI Governance Must Move From Models to Actions
Examine who can authorize an agent action, enforce its limits, and account for the evidence.
Observing an AI Agent Is Not the Same as Governing It
Distinguish a reported policy decision from evidence that the executor applied it.
Why Prompt-Level Governance Is Not Enough for AI Agents
Examine the facts that emerge as an agent prepares an operation, and keep the initial review within the evidence it actually assessed.
Read the prompt-level governance analysis
The Security Boundary of an AI Agent Is Larger Than the Model
Distinguish findings that remain useful from questions a changed agent configuration has not yet answered.
Read the agent security boundary analysis
Human-in-the-Loop Is a Control, Not a Governance Strategy
Examine what a reviewer can decide, what evidence is missing, and why accepting an exception does not verify an unknown fact.
Read the human-in-the-loop governance analysis
From Discovery to Enforcement: The Eight Layers of Runtime AI Governance
Identify who must establish a policy condition when the agent is known but the decision lacks an accountable source.
Read the discovery-to-enforcement analysis
The Difference Between an AI Incident and an AI Governance Decision
Separate a decision about permission from the evidence and criteria used to investigate a situation or declare an incident.
Read the incident and governance decision analysis
Why AI Agent Audit Evidence Needs More Than a Prompt Log
Trace a copied result and its hashes to their inputs, and distinguish delivery records from observations of an effect.
Read the audit evidence and prompt log analysis
Glossary
AI Governance
Clarify the responsibilities, policies, controls, and evidence that govern AI.
AI Agent Governance
Distinguish delegated authority, permissions, policy decisions, controls, and evidence.
Shadow AI
Distinguish a known application from an approved use of AI.
AI Agent
Understand how an AI agent connects context, decisions, and actions.
Agentic AI
Distinguish delegated choices from decisions retained by people.
AI Control Plane
Separate policy management from where decisions take effect.
AI Usage Governance
Distinguish an approved application from the conditions that authorize a particular use of AI.
Read the AI usage governance definition
Runtime AI Governance
Clarify when a policy decision can affect an interaction and what evaluation alone does not establish.
Read the runtime AI governance definition
Tool Call
Distinguish a request through a tool interface from its dispatch, response, and resulting effects.
MCP
Understand how MCP connects applications to servers and why protocol access does not establish authority over downstream resources.
Human-in-the-Loop
Distinguish supplying information, reviewing work, and authorizing an operation within an AI workflow.
Read the human-in-the-loop definition
Pre-Execution Governance
Identify the operation, decision, and control point while the protected effect can still be withheld.
Read the pre-execution governance definition
Agent Observability
Understand agent activity through telemetry while preserving each observation's source, scope, and limits.
Read the agent observability definition
AI Observability
Distinguish observations of models, applications, and workflows from conclusions that require additional context or evaluation.
Read the AI observability definition
Coding Agent
Distinguish generated development suggestions from the steps an AI system is delegated to select and execute.
Read the coding agent definition
Agent Action
Identify the unit of work and distinguish its proposal, execution attempt, and observed outcome.
Read the agent action definition
Technical reading
What Is an AI Agent, Actually?
Examine how a system's behavior and delegated authority affect the governance question behind the “agent” label.
Observability and Governance for AI Apps on Company Desktops
Explore KonaSense's explanation of the OpenTelemetry path, the context applications export, and the distinction between observing activity and intervening before an action.
Read the OpenTelemetry technical note
For the product connection, explore KonaSense's approach to enterprise AI usage.