Guides · Overview
Guides
Plain-language guides for teams starting to govern AI agents: human oversight patterns, governance platforms, and regulatory compliance.
- The Capability Library
Pre-built registration templates for selected vendor capabilities (Stripe, Slack, GitHub, Jira, Postgres, Ramp, Brex, Twilio, SMTP, Salesforce, AWS, Microsoft 365, Okta, ServiceNow, and Workday) with capability counts, risk tiers, per-pack limitations, honest review states (13 library, 2 draft), and dated sources. Registration is not connectivity.
- Comparing AI agent governance approaches
A sourced, dated comparison of Microsoft Agent 365, Google Agent Gateway, AWS Bedrock AgentCore, ServiceNow AI Control Tower, and IBM watsonx.governance, measured on customer-controlled credential custody and offline-verifiable evidence, with our conflicts and limits disclosed.
- Why the native control planes might not fit
Seven structural differences between the hyperscaler control planes (Microsoft Agent 365, Google Agent Gateway, AWS Bedrock AgentCore) and the architecture AAES is designed to offer, stated claim first: credential custody, approval as a precondition, per-action spending ceilings, offline-verifiable evidence, governed capability packs, client-boundary deployment, and capacity pricing.
- Agent governance pricing: seats vs capacity
Per-seat control planes (Microsoft Agent 365 at USD 15 per user per month, or in M365 E7) versus capacity-metered governance: humans never billed, no per-agent license charge or licensed-agent-count limit, governed-decision capacity as the only meter. Arithmetic at 10, 100, and 1,000 users, labelled as arithmetic, not an AAES quote.
- Enterprise AI governance platforms: an honest comparison
Which platforms large organizations evaluate (IBM watsonx.governance, Credo AI, Holistic AI, OneTrust, ServiceNow, AAES), what each layer governs, and the best value for mid-sized companies.
- Human-in-the-loop AI: examples and patterns
What human-in-the-loop AI means in machine learning and in production agents, with examples of approval patterns and when human-out-of-the-loop is acceptable.
- AI governance platform: what to evaluate
How an AI governance platform differs from model governance and AI risk management software, and the capabilities worth testing: agent access control, guardrails, monitoring, and audit trails.
- AI agent spending controls: patterns and tools
Cost observability and LLM gateways (LiteLLM, Portkey, Helicone, Kong) vs budget enforcement at the action layer, and how to stay inside a strict monthly AI budget.
- AI regulatory compliance: a practical guide
What AI regulatory compliance asks of teams running agents, what AI compliance software can and cannot do, and how evidence records support an audit.
Why we publish these guides
Teams adopting AI agents ask the same questions: what human-in-the-loop means in a production workflow, which capabilities an AI governance platform should provide, and what regulators and auditors will ask for when agents act on behalf of the business. Search results for these topics are dominated by vendor marketing and contradictory definitions, so we wrote precise, vendor-neutral guides grounded in how enterprise agent deployments work.
Each guide stands on its own. The human-in-the-loop guide covers oversight patterns and shows when human-on-the-loop or human-out-of-the-loop operation is defensible. The governance platform guide is an evaluation framework: access control for agents, guardrails, monitoring, and audit trails, with the questions to ask any vendor, including us. The regulatory compliance guide maps emerging AI regulation to the evidence records an agent platform should produce, so audits rely on queries rather than manual reconstruction. Read them in any order; each one links to the others where the topics connect.
These guides are educational. They describe general practice and, where relevant, how AAES approaches the topic. They are not legal advice or a certification.
