Celest Learn · Operating model
What is an AI agent control plane?
An AI agent control plane is the operating layer that makes a collection of AI agents governable as one estate. It discovers agents across platforms, joins identity, ownership, capability, usage, cost, and risk evidence, turns supported evidence into findings, keeps approval authority explicit, and verifies the outcome of every consequential action.
Why an agent estate needs a control plane
Organizations rarely operate every agent in one runtime. An agent's identity may live in an identity provider, its definition in an authoring platform, its tools in APIs or MCP servers, its work in business systems, and its cost and activity in still other sources. Each system can be accurate about its own record while no system answers who owns the whole agent or whether its authority is still justified.
A control plane does not replace those execution systems. It joins their observations into an accountable estate, preserves conflicts and unavailable evidence, and provides one governed path from a supported finding to a verified outcome.
The seven-stage operating loop
A useful control plane keeps observation, judgment, authority, action, and proof separate. Collapsing those states makes a recommendation look like an approval or an accepted API request look like a successful outcome.
| Stage | Question | Durable output |
|---|---|---|
| 1. Discover | What agents and source observations exist? | Evidence snapshot with provenance and source health |
| 2. Diagnose | What does the available evidence support? | Finding with rationale, severity, and unknowns |
| 3. Propose | What bounded work could resolve the finding? | Plan with scope, predicted effect, and rollback conditions |
| 4. Approve | Who or what policy has authority for this exact work? | Authority decision tied to actor, scope, and time |
| 5. Execute | What provider-native action was attempted? | Action record without assuming success |
| 6. Verify | Did fresh observation show the intended effect? | Execution receipt with postcondition evidence |
| 7. Reconcile | Can the finding close, or must it reopen? | Updated estate state and review history |
What belongs in the canonical agent record
The record should be a provenance-preserving join, not a flattened guess. Every material value needs a source, observation time, and confidence or availability state. Contradictory source values should remain visible until a governed rule resolves them.
- Stable identity and aliases across source systems
- Accountable business and technical owners, including an explicit unknown state
- Lifecycle state, publication state, assignments, and last meaningful activity
- Models, tools, connectors, MCP servers, credentials, and delegated permissions
- Data boundaries, environments, regions, and external dependencies
- Usage, cost, quality, safety, and security observations with source health
- Findings, proposed work, authority decisions, actions, receipts, and reconciliation history
Evidence quality is part of the risk model
The NIST AI Risk Management Framework organizes AI risk work around Govern, Map, Measure, and Manage, and describes governance as a cross-cutting function. An agent control plane turns that idea into inspectable operating state: the estate being governed, the evidence available to measure it, the decisions made, and the result of risk treatment. [nist-ai-rmf]
A source outage, stale observation, failed join, or inaccessible permission record changes what the system can responsibly conclude. Source health and collection time therefore belong beside the evidence, not in an internal log that disappears from the decision.
What is not an agent control plane
- A catalog that lists agents but cannot explain ownership, authority, or evidence provenance
- An orchestration framework that runs multi-agent workflows but does not govern the surrounding estate
- A dashboard that converts unavailable observations into reassuring zeros
- A policy document with no connection to live source evidence or execution receipts
- An automation layer that treats approval as a UI click and an HTTP 200 as proof of success
How this applies to a Microsoft agent estate
In a Microsoft-centered estate, relevant evidence can span identity, Microsoft 365, Copilot Studio, Power Platform, Azure, GitHub, Azure DevOps, and the business systems an agent can reach. Celest's current commercial entry point is a fixed-scope, read-only Agent Estate Review that gathers and normalizes available evidence before proposing any action.
Celest currently has bounded development proof for discovery and deterministic diagnosis. Proposal is the next gate. Approval, execution, verification, and reconciliation describe the intended operating model and are not claimed here as current commercial execution capability.
Limitations
- There is no universal industry definition of an AI agent control plane; this page states Celest's definition and design criteria.
- A control plane cannot repair incomplete source data by inference without changing evidence into speculation.
- Cross-platform inventory does not itself grant authority to modify any source system.
- Controls must be adapted to the organization's risk, regulatory, identity, and operating context.
Sources
External claims on this page use the primary sources below. Celest-authored definitions and design criteria are identified as our operating model.
- 1Artificial Intelligence Risk Management Framework (AI RMF 1.0)
National Institute of Standards and Technology · Accessed 2026-07-27. The Govern, Map, Measure, and Manage framing and governance as a cross-cutting function.
- Author
- Celest
- Source revision
sha256:9096d9b3485490f40e5e46ebcac384bbe788f248689a010de0ba271dd2b9f8b1