Agentic AI governance planning
Know who can say yes before an agent can act.
Agentic AI governance starts with boundaries. Your team wants to use AI, but the boundaries are unclear. Canvas helps you turn broad guardrails into a reviewable plan: what the workflow may do, what evidence it needs and where a person must decide.
On the home page, choose “Setting guardrails” to set your starting point.

Illustrative workflow to plan
A small first version. A clear human decision.
Select a step to follow the handoff. People keep the decisions marked for human review.
Map proposed actions
Separate drafting, recommendations and commitments.
Plan the evidence and ownership for this handoff.
Example: a proposed assistant drafts supplier communications. A named owner reviews the draft and any commercial commitment before sending. Canvas helps describe that approval gate. It does not enforce permissions, intercept requests or operate a runtime gateway.
A policy needs a place in the workflow.
“Keep a human in the loop” leaves important questions unanswered. Which person? At what step? With what evidence? Start with one proposed workflow and make its decision boundaries concrete enough for delivery and governance teams to review.
Research context: the NIST AI Risk Management Framework is voluntary guidance for considering trustworthiness across AI design, development, use and evaluation. Canvas can help organize planning questions; using it is not NIST certification.
NIST: AI Risk Management FrameworkBring the evidence behind the idea.
- One workflow and the actions it proposes to take.
- Decision owners, existing policies and escalation paths.
- Source authority, sensitive-data boundaries and examples of unacceptable outcomes.
Turn discovery into a reviewable plan.
Connect the rules to the operating model in the Agentic Brain. Use readiness gaps and generated planning outputs to prepare a shared review. Prepare evidence and approval gates for reviewers; runtime enforcement requires separate implementation.
Define what would make it worthwhile.
Ask whether reviewers can identify the owner, required evidence and stop conditions at each decision. Track unresolved questions and review effort. Approval of a plan is not proof that an implemented control works.
Your first conversation
Start with a brief like this.
We want to set guardrails for an AI assistant that drafts supplier communications. Help us identify permitted actions, evidence requirements and approval owners. Commercial commitments must remain with a person, and implementation controls still need to be designed.
Adapt this example and bring it to the home-page conversation. Choose “Setting guardrails” in the starting-point options. The link does not select a chip or fill in your brief.
Start planningBefore you start
Does Canvas enforce our policies?
No. It helps describe and review boundaries. Runtime controls, monitoring and enforcement belong to the system your team implements and validates.
Who should join the review?
Bring the workflow owner, someone who performs the work, and the people responsible for technology, data access and governance. Resolve disagreement before treating a gate as agreed.
How do you govern agentic AI?
Decide in advance what the workflow may do alone, what a person must approve and what it must never do. Name the evidence each decision needs and who owns it, then write these limits into the implementation plan before anything is built.
What is human in the loop for AI agents?
A named person reviews or approves the agent’s output before it takes effect, and can stop it. Planning is where you decide which steps need that approval.