Celest
Sections
Explore the demo

Celest Learn · Operating model

What is an AI agent control plane?

An AI agent control plane is the operating layer that makes a collection of AI agents governable as one estate. It discovers agents across platforms, joins identity, ownership, capability, usage, cost, and risk evidence, turns supported evidence into findings, keeps approval authority explicit, and verifies the outcome of every consequential action.

Published
Updated
Evidence
Celest operating model, informed by cited standards and primary platform specifications.

Why an agent estate needs a control plane

Organizations rarely operate every agent in one runtime. An agent's identity may live in an identity provider, its definition in an authoring platform, its tools in APIs or MCP servers, its work in business systems, and its cost and activity in still other sources. Each system can be accurate about its own record while no system answers who owns the whole agent or whether its authority is still justified.

A control plane does not replace those execution systems. It joins their observations into an accountable estate, preserves conflicts and unavailable evidence, and provides one governed path from a supported finding to a verified outcome.

The seven-stage operating loop

A useful control plane keeps observation, judgment, authority, action, and proof separate. Collapsing those states makes a recommendation look like an approval or an accepted API request look like a successful outcome.

Seven distinct control-plane stages
StageQuestionDurable output
1. DiscoverWhat agents and source observations exist?Evidence snapshot with provenance and source health
2. DiagnoseWhat does the available evidence support?Finding with rationale, severity, and unknowns
3. ProposeWhat bounded work could resolve the finding?Plan with scope, predicted effect, and rollback conditions
4. ApproveWho or what policy has authority for this exact work?Authority decision tied to actor, scope, and time
5. ExecuteWhat provider-native action was attempted?Action record without assuming success
6. VerifyDid fresh observation show the intended effect?Execution receipt with postcondition evidence
7. ReconcileCan the finding close, or must it reopen?Updated estate state and review history

What belongs in the canonical agent record

The record should be a provenance-preserving join, not a flattened guess. Every material value needs a source, observation time, and confidence or availability state. Contradictory source values should remain visible until a governed rule resolves them.

  • Stable identity and aliases across source systems
  • Accountable business and technical owners, including an explicit unknown state
  • Lifecycle state, publication state, assignments, and last meaningful activity
  • Models, tools, connectors, MCP servers, credentials, and delegated permissions
  • Data boundaries, environments, regions, and external dependencies
  • Usage, cost, quality, safety, and security observations with source health
  • Findings, proposed work, authority decisions, actions, receipts, and reconciliation history

Authority must be data, not an assumption

Agent tools can cross security and organizational boundaries. The Model Context Protocol authorization specification, for example, requires protected MCP servers to verify access tokens and audience rather than accepting tokens intended for another resource. That runtime check is necessary, but an estate control plane must also preserve why a particular actor or policy was allowed to approve a particular change. [mcp-authorization]

An authority decision should bind the approver, proposed work digest, target scope, constraints, expiration, and rationale. Execution must fail closed when the decision is missing, expired, or does not match the requested work.

Evidence quality is part of the risk model

The NIST AI Risk Management Framework organizes AI risk work around Govern, Map, Measure, and Manage, and describes governance as a cross-cutting function. An agent control plane turns that idea into inspectable operating state: the estate being governed, the evidence available to measure it, the decisions made, and the result of risk treatment. [nist-ai-rmf]

A source outage, stale observation, failed join, or inaccessible permission record changes what the system can responsibly conclude. Source health and collection time therefore belong beside the evidence, not in an internal log that disappears from the decision.

What is not an agent control plane

  • A catalog that lists agents but cannot explain ownership, authority, or evidence provenance
  • An orchestration framework that runs multi-agent workflows but does not govern the surrounding estate
  • A dashboard that converts unavailable observations into reassuring zeros
  • A policy document with no connection to live source evidence or execution receipts
  • An automation layer that treats approval as a UI click and an HTTP 200 as proof of success

How this applies to a Microsoft agent estate

In a Microsoft-centered estate, relevant evidence can span identity, Microsoft 365, Copilot Studio, Power Platform, Azure, GitHub, Azure DevOps, and the business systems an agent can reach. Celest's current commercial entry point is a fixed-scope, read-only Agent Estate Review that gathers and normalizes available evidence before proposing any action.

Celest currently has bounded development proof for discovery and deterministic diagnosis. Proposal is the next gate. Approval, execution, verification, and reconciliation describe the intended operating model and are not claimed here as current commercial execution capability.

Limitations

  • There is no universal industry definition of an AI agent control plane; this page states Celest's definition and design criteria.
  • A control plane cannot repair incomplete source data by inference without changing evidence into speculation.
  • Cross-platform inventory does not itself grant authority to modify any source system.
  • Controls must be adapted to the organization's risk, regulatory, identity, and operating context.

Sources

External claims on this page use the primary sources below. Celest-authored definitions and design criteria are identified as our operating model.

  1. 1
    Artificial Intelligence Risk Management Framework (AI RMF 1.0)

    National Institute of Standards and Technology · Accessed 2026-07-27. The Govern, Map, Measure, and Manage framing and governance as a cross-cutting function.

  2. 2
    Model Context Protocol authorization specification

    Model Context Protocol · Accessed 2026-07-27. Resource-server token validation, audience binding, and protected-resource authorization behavior.

Publication record
Author
Celest
Source revision
sha256:9096d9b3485490f40e5e46ebcac384bbe788f248689a010de0ba271dd2b9f8b1