Governance and audit

Control built into every run, not added later.

Decide who each agent is, what it can touch and when it must stop. Every action is logged, so you can always see what happened.

Comparing approaches? Read governed vs ungoverned agents.

Audit and policy Governance console
Live
Controls RBACSkill accessModel policyApproval rules
Audit log

User approved packet

Agent called CRM tool

Knowledge source checked

Six controls, on for every agent.

Set once, enforced every time

Rules are set by your team and enforced by the system on every run, not left to the prompt.

People can step in at any point

Any run can be paused or cancelled, and hard cases go to a person instead of a guess.

Nothing is a black box

Every decision and action can be traced back, from the sources used to the person who signed off.

Identity and access for every agent

Every agent acts under a name, an owner and a scope. It can only use the connectors and data you approve, and nothing is open by default. Role based access decides which people can build, run and review agents.

  • A named owner for every agent
  • Every connector is governed
  • Role based access for people
Governance
Members Roles Approval Rules Audit
Priya ShahProcurement LeadActiveNo Groups
Marcus LeeWorkspace Owner, Workspace AdminActiveCommercial Approvers
Elena TorresApproverActiveFinance Approvers

Policy and model rules

Guardrails are set at the organization level and enforced before work runs. Decide which models each team can use, which actions an agent may take on its own and which must wait for approval.

Bring your own LLM Model policy
Live
Low risk draft Fast model
Legal reasoning Approved advanced model
Sensitive data Private provider
Central policy

Controls cost, quality, latency, privacy, and task complexity.

Supervision and escalation

Any run can be paused or cancelled at any time, not only at the start. When an agent reaches a step it is not allowed to take alone, it stops and hands the decision to the right person. If an approval waits too long, the agent sends reminders and can alert an admin.

  • Pause or cancel any run
  • Hard cases go to the right person
  • Reminders when approvals wait
Live run Refund case 4821
Live
  1. Read the refund request
  2. Check the order history
  3. Refund above team limit
Escalated Needs a decision from Priya, Support lead

The agent paused this step. Reminder sent after 2 hours.

Approve Pause run Cancel

Audit log and output history

Every decision and action can be rebuilt after the fact: the request, the sources, the model, the tool calls and each human sign off. The record sits next to the work and is ready for review or audit.

Evidence and artifacts Run trace
Live
  1. 09:41 Request classified
  2. 09:43 Scope checked
  3. 09:48 Evidence gathered
  4. 10:02 Approval waiting
Artifacts Contract delta.pdf Spend summary.csv Recommendation.md
How it works

From request to recorded result.

  1. Name the agent and its owner

    Every agent gets an identity and a person responsible for it.

  2. Scope its access

    Choose the connectors and data it may use. Nothing else is open.

  3. Set policy and approvals

    Decide what it may do alone and what waits for a person.

  4. Supervise live runs

    Watch, pause or cancel work as it happens.

  5. Review the record

    Every run leaves a full trail for review and audit.

FAQ

Governance and audit: questions and answers

Short answers to what teams ask before they put this part of SoftworkerAI to work.

Contact us directly
What does governance cover in SoftworkerAI?

Six controls: identity, access, approvals, supervision, audit and policy. They apply to every agent and every run, and governance is included on every plan, never sold as an add on.

Are the rules enforced, or only suggested to the model?

Enforced. Policies are applied by the system at runtime, not written into a prompt. An agent cannot use a tool, read data or take an action that its policy does not allow.

Can we stop an agent in the middle of a run?

Yes. Any run can be paused or cancelled at any time by the people allowed to supervise it.

What happens when an agent is not allowed to do something?

It escalates. The agent stops at that step and asks the right person to decide, with the context attached, and the decision joins the record.

Can we use our own model provider?

Yes. You can bring your own LLM provider and set model policies for each team or workflow.

The multiplayer workspace for humans and AI agents is how teams move beyond prompting and safely hand AI real work. It gives people one place to plan, approve, and oversee execution, so they can run work with AI agents they can govern and trust.
The SoftworkerAI Team