A substantial share of the usable guidance on governing agentic systems is currently being published by the companies selling agent platforms. This is not a scandal — they have the operational experience, and much of the material is careful. It does mean the guidance should be read with an awareness of where its attention naturally falls.
Autonomy boundaries and the trouble with levels
Most frameworks of this kind define tiers of autonomy: an agent that only recommends, one that acts with approval, one that acts and reports, one that acts within a scope. The tiers are a useful shared vocabulary and a poor risk model, because the tier does not tell you what an action at that tier can cost.
The properties that predict consequence are reversibility and blast radius. An irreversible action affecting one record is a different proposition from a reversible one affecting a million, and neither is captured by an autonomy level. Frameworks that anchor on these two dimensions produce more defensible boundaries than those that anchor on autonomy alone.
Approval controls and their known failure mode
Requiring approval before consequential actions is the most commonly recommended control and the one most commonly hollowed out in practice. The mechanism is volume: an approver seeing many low-information requests approves reflexively, and the control persists as a step in a workflow while having ceased to be a decision.
Frameworks that address this specify what an approval request must contain, and set a budget for how many any one person should receive. Frameworks that do not are describing a control that will be present and non-functional.
Reading a vendor framework for its gaps
The predictable pattern is that a vendor framework is most detailed on the controls its platform implements and least detailed on the ones it does not — commonly the organisational parts: who owns an agent, who is accountable when it causes harm, what happens at the boundary between the platform and everything else the organisation runs.
That is not bad faith; it is where the authors' expertise is. It does mean that an organisation adopting a vendor framework wholesale inherits a shape of coverage determined by a product roadmap. The correction is to read two or three from different vendors alongside a neutral reference such as the NIST framework or ISO/IEC 42001, and to notice what only one of them mentions.
The prerequisite, again
Every framework in this space assumes an agent inventory. Most organisations adopting one do not have it, and the adoption therefore governs a hypothetical estate while the real one continues unobserved. The inventory is the first task, not a later phase.