Celest Learn · Operating model
A practical guide to governing AI agents at work
Start with the questions your team already asks: What agents do we have? Who owns them? What can they reach? Are they being used as expected? Who can approve a change? And how will we know the change worked? For each answer, keep the evidence, the owner, and the next step together.
Start with the questions your team already asks
Your agent estate is simply the agents, tools, and environments your team manages. You do not need a new governance language to get started. Bring the people who know the work, open the sources you already trust, and ask six questions.
- What agents do we have, and where are they?
- Who is responsible for each one?
- What tools, data, and services can each agent reach?
- Is each agent being used and behaving as expected?
- Who is allowed to approve a change?
- How will we know the change happened and worked?
A controls matrix people can actually use
Use this as a conversation guide, not a universal checklist. Start with the rows that matter for the agent in front of you. The short references help people and software return to the same question later.
| Question | What we check | What we can honestly say | Who owns the next step |
|---|---|---|---|
| EST-01 · Can we see the agents in scope? | The environment, review time, and health of each source | Confirmed or unknown. If collection fails, there is no snapshot yet | The estate owner repairs missing access or sources |
| OWN-01 · Does each agent have an owner? | A healthy ownership source and a matching agent record | Confirmed, needs attention, or unknown | The business or platform owner acknowledges the gap or opens a review |
| LIF-01 · Is its status clear and intentional? | Whether it is published, deployed, assigned, active, or quarantined, where those facts are available | Confirmed, needs attention, or unknown | The app and platform owners decide whether to open a separate change |
| CAP-01 · What can it reach? | Its tools, connectors, other integrations, and the policies that apply | Confirmed, needs attention, or unknown | Security and the application owner decide the response |
| USE-01 / OPS-01 · Is it being used and behaving as expected? | Activity, cost, errors, latency, safety events, and incidents over one clear period | Confirmed, needs attention, or unknown | The business and service owners decide whether to keep, investigate, or retire it |
| AUT-01 · Who can approve a proposed change? | The finding, proposed work, impact, reversibility, and alternatives | A named person approves, rejects, defers, requests changes, or asks for more evidence | A non-approval can close the decision. Approval only permits a clearly defined handoff |
| EXE-01 / VER-01 · Did the approved work happen, and did it stick? | A handoff and separate execution record, followed by a fresh read of the estate | Execution failed, succeeded, or is unknown. A fresh check separately confirms the result | The execution owner records what happened; a separate reviewer checks the result. The fresh check is future work in Celest |
Keep the result easy to explain
- Confirmed — the available evidence supports the answer.
- Needs attention — a repeatable check found something worth reviewing.
- Unknown — the source was missing, unhealthy, or unable to answer.
Move from a finding to a trustworthy follow-up
- Review — show the evidence and record the team's response.
- Decide — let the named owner approve, reject, defer, request changes, or ask for more evidence.
- Hand off — if approved, send the exact bounded work to the person or system responsible for it.
- Check — record what happened, then read the estate again before saying the intended result is in place.
Try it with one agent
Pick one agent that matters to the business. Bring its owner, one unanswered question, and the source your team trusts. Work through the relevant rows together, write down what is unknown, and give every next step a name and an owner. NIST treats governance as everyday risk work; this is Celest's practical version. [nist-ai-rmf]
That is enough to start well: make the current picture trustworthy, help the right person decide, and never claim more than the evidence supports.
Limitations
- This guide is an operating model, not legal advice, a certification, or a substitute for your organization's regulatory analysis.
- Choose questions, owners, and thresholds that fit your systems, responsibilities, and appetite for risk.
- A receipt links the records we have; it cannot make weak source data true or replace a fresh check of the estate.
Sources
External claims on this page use the primary sources below. Celest-authored definitions and design criteria are identified as our operating model.
- 1Artificial Intelligence Risk Management Framework (AI RMF 1.0)
National Institute of Standards and Technology · Accessed 2026-07-27. Govern as a cross-cutting risk-management function; used here only to contextualize the guide's operating role.
- Author
- Celest
- Source revision
sha256:cc4f8eb394d71c8298b452312a90676767640595e9ddadc8eae19507959f3334