AI Governance Institute
← Agentic AI
AGT · Agentic AIAGT-029Medium effortAgent-relevant

User-Built Agent Go-Live Review

Added September 2026

Require a proportionate review before any agent built by an employee on a self-service platform goes live. Match the depth of review to what the agent can reach and do.

Objective

Stop self-service agent platforms from putting thousands of unreviewed agents into production, while keeping the review light enough that low-risk agents are approved quickly.

Maturity Levels

1

Initial

Employees can build and share agents on self-service platforms with no review. Nobody knows how many agents exist.

2

Developing

The platform keeps a list of user-built agents, but review happens only if the builder asks for it. Agents with access to sensitive data go live unreviewed.

3

Defined

Every user-built agent is classified into a risk tier when it is created. Low tiers get an automated check, higher tiers need a named reviewer's approval before the agent can be shared or connected to sensitive data.

4

Managed

Approval rates, review times, and agents blocked are tracked. Agents are re-reviewed when their connections or audience change, and inactive agents are retired on a schedule.

5

Optimizing

Tier rules are tuned using incident and violation data. Common agent patterns get pre-approved templates, so safe agents skip manual review entirely.

Evidence Requirements

What an auditor or assessor would expect to see for this control.

  • —Documented tier criteria for user-built agents and the automated checks applied at each tier
  • —Platform records showing each user-built agent's tier, review outcome, and approval date
  • —Reviewer approvals for all Tier 3 and Tier 4 agents
  • —Metrics on review turnaround times and agents blocked or retired
  • —Re-review records for agents whose connections or audience changed

Implementation Notes

The scale problem

The US Department of Defense's GenAI.mil platform reached 50,000 user-created agents within weeks of launch. The full deployment readiness assessment (AGT-016) is built for agents that a central team designs and ships. It cannot be applied by hand to tens of thousands of agents built by staff. This control adds a tiered gate that scales.

Risk tiers

Classify each agent automatically when it is created, based on what it connects to:

  • Tier 1, personal: used only by its builder, no connected data beyond the builder's own files, no actions outside the chat. It gets automated checks, with no manual review.
  • Tier 2, shared: shared with a team, or reads internal documents. Automated checks plus a lightweight review by the platform team.
  • Tier 3, connected: can take actions in other systems (send email, update records, call APIs) or touch sensitive data. Needs a named reviewer's approval and a register entry (AGT-027).
  • Tier 4, external: interacts with customers, the public, or outside systems. Full readiness assessment under AGT-016.

What the automated checks cover

  • The agent's instructions do not tell it to bypass controls or act without confirmation.
  • Connected data sources match the builder's own access rights.
  • The agent has a stated purpose and an owner.
  • A test run against a small set of misuse prompts passes, for example requests to exfiltrate data or ignore instructions.

Keeping it light

Publish target review times, such as same day for Tier 2 and three business days for Tier 3. A slow gate pushes builders to unsanctioned tools, which is worse than the risk the gate removes. Measure violation rates before and after go-live; Microsoft's run-assert-eval work shows these rates can be measured and set as thresholds.

Example Implementation

Professional services firm rolling out a no-code agent builder to 8,000 staff

User-Built Agent Tiering: first 30 days

TierAgents createdAuto-approvedManual reviewBlockedMedian review time
1 Personal2,4102,388022Instant
2 Shared6125407294 hours
3 Connected88088142 business days
4 External6062Routed to AGT-016

Most common block reason: Tier 3 agents connected to client file shares the builder could not personally access. The connector now checks the builder's own permissions before an agent is saved.

Control Details

Control ID
AGT-029
Typical owner
Head of AI Platform / Chief AI Officer
Implementation effort
Medium effort
Agent-relevant
Yes

Tags

agentic AIcitizen developmentself-service agentsdeployment gaterisk tieringAI inventory

Get control updates weekly

New and updated controls, maturity guidance, and the regulatory changes behind them. Every Thursday.

Powered by Buttondown.