Governance
Most AI governance is a document describing what agents are supposed to do. We think governance only counts when it is enforced at the moment an agent acts, because everything else is a statement of intent with no mechanism behind it.
Yaju Team · 15 June 2026
There is a version of AI governance that consists of a policy, a training module and an annual review. It produces a document that can be shown to an auditor and has almost no relationship to what the agents in the organisation actually did last Tuesday.
We are not dismissive of policy. We are dismissive of policy that has no mechanism, because an agent cannot read a PDF and decline.
The principle underneath the Agent Orchestration System is that a rule which is not enforced where the action happens is not a rule.
If an agent should never write to a production database, that constraint lives at the point where the write would occur, not in the prompt that asked it not to. Prompts are instructions to a model, and models are persuadable. Enforcement is a property of the system.
The practical consequence is that the answer to "could this have happened" is determinate rather than probabilistic. Either the boundary permitted it or it did not.
An organisation that can answer these four for every running agent is governed. One that cannot is hoping.
A recurring failure in agent deployments is credential sprawl: keys in configuration files, in repositories, in shell history, shared between agents because it was convenient at the time.
Our position is that an agent should never hold a secret in clear text. Credentials resolve at runtime from an organisation-level vault, scoped to the agent that needs them, so revoking access is a single action rather than an investigation.
This also makes the audit trail meaningful. When every action is tied to a resolved identity, "which agent did this" has an answer.
Some actions should not proceed without a person. Not everything, or the system is pointless, but the ones where being wrong is expensive or irreversible.
Rather than treating this as a blanket review of all output, we treat it as a property of specific actions. Risky actions pause for approval; routine ones do not. That keeps review meaningful, because a person who approves forty things a day stops reading by the tenth.
We do not train on customer data. We do not require data to leave the region you choose, and where it cannot leave your infrastructure at all, the same system runs self-hosted or fully air-gapped with identical governance.
We also do not claim that governance makes agents safe in some absolute sense. It makes them accountable, which is a smaller and more honest claim: when something goes wrong, you can establish what happened, who owned it and what it cost.
The AI Governance pages cover enforcement, and the Trust Center covers compliance, subprocessors and how to raise a security issue. Questions can go to contact@capconsultor.eu.