A governed agent lifecycle starts before execution. Purpose and ownership are declared, risk and policy are evaluated, a scoped passport is issued, the identity is bound to runtime context, activity is observed under policy, and access is revoked or expired with evidence closure. This creates continuity from authorization to audit.
Resource · 2026
The Six Control Moments of an AI Agent
Request, approve, issue, bind, operate and revoke: a lifecycle for keeping agent identity governed from intent to evidence.