Five pillars. Thirty components. Built for autonomous AI. Governance at the top, Change Management at the base — because every layer below decides whether the agents above it operate safely, purposefully, and with the trust of the people they work alongside. Security is not a pillar. It runs through all five.
Who decides what an agent is permitted to do — and how far it can act without asking. Six components built for the permission, boundary, and accountability challenges that autonomous systems create. Security starts here.
In Governance, security is set before build — least-privilege scope, credential custody held outside the agent, and data-use boundaries drawn before a single agent is designed.
What: Use cases classified on two axes — risk level (Low/Medium/High) and autonomy level (Supervised/Conditionally Autonomous/Fully Autonomous). Why: These two axes together determine the approval path. A high-risk fully autonomous agent requires a fundamentally different gate than a low-risk supervised one.
What: Every agent has a documented scope — which systems, data, APIs, and actions it may access and execute. Scope is explicit, approved, and enforced before deployment. Why: Ungoverned scope is how agents acquire capabilities beyond their design. Least-privilege by default; no agent holds credentials directly.
What: Rules on what data agents can read, process, and act on — what passes to external APIs and what is off-limits. Why: Agents with read access to sensitive data and write access to external systems create exfiltration risk. Data rules must precede agent design, not follow it.
What: Every agent action classified as reversible or irreversible before deployment. Irreversible actions — sending messages, financial transactions, data deletion — trigger mandatory human approval. Why: Reversibility is the single most important agentic risk variable. Can't govern what you haven't classified.
What: Agents encountering situations outside their defined scope must have a named human escalation path. BU-vs-central conflicts resolve with the Executive Sponsor within 5 business days. Why: Autonomous systems without escalation paths don't stall — they improvise. That's the failure mode.
What: A central AI office sets agent guardrails — approved tools, data standards, scope boundaries, credential policy. BUs deploy agents freely within those guardrails. Why: Hybrid moves fast where it can, applies rigor where it must. Central control of scope; distributed control of deployment.
"An agent without a defined scope isn't a tool — it's a liability with an API key."FOXPATH™ · Pillar 01
Who runs the agentic program — and who owns what each agent does. Three roles, six components, one principle: every autonomous system has a named human accountable for its behavior.
In the Operating Model, security is owned by a name — every agent has an accountable human steward, and the Sponsor chairs a quarterly agent risk review.
What: AI Transformation Lead architects and builds agent systems. AI Champions serve as Agent Stewards — accountable for agent behavior in their BU, not just adoption. Executive Sponsor holds quarterly agent risk reviews. Why: Three crisp roles. Every agent deployment has a clear owner.
What: Chairs quarterly agent risk review and program review. Makes binding escalation decisions on agent scope requests within 5 days. Why: Agentic deployment decisions require authority above the BU level. Without exec accountability, scope creep goes uncontested.
What: High performers recruited centrally for influence, credibility, and functional knowledge — plus baseline agentic literacy: tools, memory, orchestration, failure modes. Why: Agentic Champions must reason about autonomous systems, not just advocate for tools. Enthusiasm isn't enough.
What: Champions serve as Agent Stewards — owning behavior accountability for agents deployed in their BU, running discovery sessions, maintaining pipeline entries, and escalating anomalous agent behavior. Why: Stewardship, not just adoption. A named human owns what each agent does.
What: Weekly Champions sync now includes agent status review — anomalous behavior, scope boundary alerts, and human-in-the-loop escalations surface here first. Dedicated channel for real-time coordination. Why: Agents don't wait for the next meeting. The cadence must match their pace.
What: Turns workflow conversations into scored, risk-tiered AI opportunities — and explicitly identifies which are candidates for agentic deployment vs. AI assist. Why: The instrument Champions use to surface agent opportunities from the people closest to the work. Built first.
"You can't delegate autonomous action without delegating the accountability for it. The operating model is where that line gets drawn."FOXPATH™ · Pillar 02
How agentic use cases move from idea to supervised deployment to autonomous operation. Two gates, three autonomy stages, and a security review that's not optional — the part of the framework that prevents premature autonomy.
In Process, security is a gate you cannot skip — a mandatory review before any agent goes autonomous, caught in shadow mode first.
What: Use cases enter via open intake form, Champion-led discovery sessions, or top-down exec priorities. All three feed one unified pipeline — no shadow backlog. Why: The source of the idea doesn't change the rigor applied to it. One pipeline, same gates, regardless of channel.
What: First gate. Every use case tiered on risk (Low/Medium/High) and autonomy (Supervised/Conditional/Fully Autonomous) before scoring. Why: Autonomy level changes the approval path more than risk level alone. A fully autonomous Medium-risk agent requires a different gate than a supervised High-risk one.
What: Scored on value, effort, and readiness — plus four agentic dimensions: autonomy level, failure mode severity, reversibility, and integration complexity. Why: An agentic pipeline without agentic scoring criteria will consistently underprice risk and overpromise speed.
What: Human acts with AI assist → Agent acts with human review on every step → Agent acts autonomously within defined scope. Explicit gate criteria required at each transition. Security review mandatory before any agent moves to autonomous. Why: Stage gates prevent premature autonomy — the most common agentic failure mode.
What: Agents run in shadow mode first — acting but with outputs reviewed by a human before any action executes. Shadow phase confirms scope compliance and catches prompt injection before live deployment. Why: Pilot-first applied to agents means shadow before live. Always.
What: Post-deployment learnings include failure mode logs, scope boundary encounters, escalation patterns, and prompt injection attempts — not just ROI outcomes. Why: The agentic framework improves with every deployment cycle, or it accumulates hidden risk with every one.
"No agent moves from supervised to autonomous without a security review — the last line before you lose the ability to correct easily."FOXPATH™ · Pillar 03
What gets built to run the agentic program. Four infrastructure tools, one observability layer, one onboarding program — because autonomous systems without observability are ungoverned by default.
In the System, security is made enforceable — Agent Observability supplies the audit trail, anomaly detection, and scope alerts that make policy visible.
What: Single source of truth for all active use cases — tier, autonomy level, stage, owner, status, baseline metrics, next action. Why: Visible to all stakeholders means no parallel spreadsheets. Autonomy level is a first-class field — not a footnote.
What: Real-time logging of what every agent does and when — action traces, scope boundary alerts, anomaly detection, full audit trail. Why: You cannot govern what you cannot see. Agents acting without observability are autonomous and invisible. This is the biggest gap in most agentic deployments.
What: Tracks productivity, cost reduction, and revenue enablement against documented pre-deployment baselines. Why: Real numbers, not estimates — what makes the program defensible to leadership and credible to the business.
What: Adoption rate, active use cases, Champion engagement, time-to-deploy, BU coverage — plus agentic signals: scope boundary rate, human escalation rate, shadow phase pass rate. Why: A program can ship wins while quietly accumulating agentic risk. These signals separate the two.
What: Onboards Champions and end users to tools, scoring methodology, and discovery techniques — with an agentic literacy track: how agents work, how to oversee them, when to intervene. Why: People cannot trust or oversee what they don't understand.
What: Two-track structured onboarding — standard AI adoption curriculum for all Champions, plus an agentic stewardship track for those overseeing autonomous systems: scope review, failure mode reading, escalation protocols. Why: The on-ramp determines the oversight culture.
"The first version of every tool ships in weeks. But Agent Observability ships before the first agent goes live — not after."FOXPATH™ · Pillar 04
How people trust systems that act on their behalf. Six components for the adoption and trust challenge unique to autonomous AI — because the fear isn't job loss. It's loss of control.
In Change Management, security is a human right — the standing permission to stop, override, and report an agent is the last and most important security layer.
What: Map stakeholders by function, influence, adoption risk, and position on the trust-in-autonomy spectrum — identifying who will struggle with delegating action to an agent before launch. Why: Agentic resistance is harder to surface than tool resistance. Proactive mapping prevents late-stage blockers.
What: Every agentic win documented and socialized with a trust-building frame — not just "AI saved time" but "the agent handled X autonomously, with full audit trail and zero errors." Why: Trust in autonomous systems is built through visible, verifiable wins. Vague wins don't move skeptics.
What: Role-based training with an agentic literacy track — end users learn how to interpret what an agent did, when to intervene, and how to read agent logs. Champions get stewardship methodology. Execs get risk literacy. Why: People can't oversee what they don't understand.
What: For agents, the primary resistance pattern is loss of control — not job displacement. Categories: fear of accountability for agent errors, discomfort with irreversible actions, distrust of autonomy. Each gets a specific response: transparency, scope communication, override controls. Why: Generic reassurance doesn't address agentic anxiety.
What: Early adopters work in shadow mode first — building personal evidence before advocating to peers. The trust ramp runs: shadow observer → supervised user → autonomous delegator. Why: For agents, the adoption curve requires a trust ramp, not just a learning curve. Evidence precedes advocacy.
What: Explicit permission to stop an agent, override its actions, and report concerns without judgment. The crawl stage for agents is shadow mode — observe before trusting. Why: Punishing agent skepticism destroys the oversight culture you need most. The override is a feature, not a failure.
"The four pillars above this one decide what agents get built. Change Management decides whether anyone trusts them enough to let them act."FOXPATH™ · Pillar 05