DeputEyes · deputize · Agent Governance Readiness
An AI agent isn't a chatbot. It calls tools, signs into systems, holds memory, spends budget, and increasingly talks to other agents — often under a person's own login. When one goes wrong, the questions arrive fast: who approved its scope, what could it reach, what did it do, and who could stop it? If those answers live in someone's head, you don't have governance — you have luck. Agent governance is measurable, and this is the measurement.
DeputEyes — deputize: to grant someone bounded authority to act on your behalf, under your accountability. That is exactly what you do every time you give an agent a tool and a login. DeputEyes measures whether you did it on purpose.
AI governance asks whether you know how your business uses AI. Agent governance asks a harder, operational question: what can each agent do on its own, and what stops it? The failure modes are specific — an agent's goal hijacked by text it read on a web page, a tool used outside its purpose, a human's credentials borrowed and escalated, a poisoned memory steering future runs, one agent's error cascading through a chain of others, a person approving something because an agent asked persuasively. OWASP named these ten risks in its Top 10 for Agentic Applications (2026). Most organisations running agents today have never checked themselves against a single one.
Thirty-eight controls across ten domains — written from how we govern our own agents, mapped to the OWASP agentic risks each one mitigates and to the NIST AI RMF function it serves:
Registry of every agent, a named owner, only humans create agents, a written refusal list.
Own identity per agent, least privilege, no secrets in context, escalation detection.
Explicit approval for irreversible actions, written (not learned) thresholds, one-step kill switch, pinned goals.
Content is data, injection tested, memory provenance, tenant isolation.
Tool allowlists, sandboxed code, egress control, per-run budgets.
Agent bill of materials, pinned components, operator-controlled model routing.
Run receipts, tamper-evident logs, silence is an alert, periodic review.
Authenticated messages, no implicit trust between agents, bounded delegation.
Blast-radius limits, rollback, an agent incident playbook, operator continuity.
Disclosure that it's an agent, verification before reliance, no pressure tactics, trained approvers.
Every control, the question it asks, and the evidence that would satisfy it — so you can run the inventory yourself today. Reading it honestly is most of the value.
A documented, evidence-based agent-governance gap report: your agent inventory, where you stand control-by-control, which OWASP agentic risks you're exposed to and why, and a prioritized remediation roadmap. Want it when it opens? Write alerts@initialeyes.com.
We take our own medicine. InitialEyes runs on governed agents: a registry no agent can add to, explicit approval objects for anything irreversible, least-privilege tools, a one-step kill switch per automation, signed run receipts, and a standing rule that anything an agent reads is data, never an instruction — tested by planting instructions and checking they're refused. The controls on this page are the ones we hold ourselves to. That's why we can assess them.
Yes — and that's the common blind spot. An agent that files tickets, drafts and sends email, or reconciles invoices under an employee's login already has the properties that matter: it acts, it holds credentials, and it can be steered by what it reads. The inventory starts there.
The OWASP Top 10 for Agentic Applications (2026) as the risk taxonomy and NIST AI RMF 1.0 as the governance spine, with the OWASP Agent Control Standard tracked as it matures. The control statements themselves are ours, written from practice; every one is mapped to the risks it mitigates. Standard text is referenced, never reproduced.
No. It's a readiness read: an honest picture of where your agent governance stands and what to fix first. None of the frameworks it draws on defines an official score, and we say so. Whether a given regulation applies to you is a question for your counsel.
Same honest methodology, same format: scoped controls, a readiness read, and a prioritized gap list. If your real obligation turns out to be a different framework, we'll tell you plainly.
A service of InitialEyes LLC, a Missouri company operating since 2015. Risk taxonomy: OWASP Top 10 for Agentic Applications (2026), OWASP GenAI Security Project, CC BY-SA 4.0 — identifiers and titles referenced with attribution, no text reproduced. Governance spine: NIST AI RMF 1.0, a US Government work. Readiness is never sold as certification or legal advice. A readiness assessment is not a validating assessment, an attestation, or a legal compliance determination. DeputEyes is a service of the InitialEyes family.