The Short Answer
Effective AI governance isn't just another layer of approvals; it's a mechanism that quickly answers recurring questions: who decides what an agent can do, what mandatory controls are needed based on risk level, and what's required to change behavior after deployment. Without such a mechanism, every new agent becomes a debate from scratch.
The core principle is tiered classification. An internal agent that only reads information and writes nothing shouldn't go through the same approval process as an agent that interacts with customers and issues refunds. A one-size-fits-all approach either creates bottlenecks or encourages workarounds, and usually both.
Risk Classification: The Foundation for All Other Decisions
| Tier | Characteristics | Approvers | Mandatory Controls |
|---|---|---|---|
| Low | Internal, read-only, no sensitive customer data | Process Owner + Platform Manager | Approved grounding, conversation logs, monthly review |
| Medium | Internal with reversible write actions, or customer-facing information disclosure | + Architect + Data Representative | Test set, Persona testing, weekly monitoring |
| High | Customer interaction, financial transactions, irreversible permissions or data | + Risk, Legal, and CISO | Human approval, full audit trail, rollback plan |
| Forbidden | Decisions with direct legal or regulatory implications without human oversight | - | Use case rejected or split into lower-tier sub-tasks |
Classification is determined by only three questions: Is the action reversible, who is exposed to the outcome, and what type of information is involved in the process? Three questions that can be answered in ten minutes, which is precisely what makes this model practical.
Three Roles to Appoint
The Business Owner is accountable for the outcome, defines what the agent is allowed to do, and resolves conflicts. This is the person who will need to explain to management why the agent answered the way it did, so this role cannot be left vacant or split between two managers.
The Technical Owner is responsible for implementation, monitoring, the change process, and cost. They maintain the agent registry and the runbook for incident management.
An Independent Auditor – typically a representative from Risk or Information Security – is not involved in development and can therefore provide an unbiased review. Their role is to sample conversations, verify that stated controls are actually functioning, and escalate findings to the decision-making forum. Without an impartial party who isn't invested in the project's success, oversight becomes self-reporting.
The responsibility model with Salesforce and model providers is detailed in Agentforce Security and Shared Responsibility.
Agent Registry
This is the one document you absolutely cannot skip. It doesn't need to be a system—a maintained spreadsheet is sufficient—but it must be up-to-date. For every active agent: its purpose in one sentence, Business and Technical Owners, risk tier, active channels, a list of Actions and their permissions, grounding sources, human approval points, last review date, and the three main KPIs.
The registry solves a problem that emerges in the second year: agent sprawl. When every team builds its own agent, you find three agents answering the same question in three different ways, and nobody knows who approved the third one.
Post-Launch Change Process
Distinguishing between routine and material changes is what prevents paralyzing governance. A routine change – wording edits, correcting a response phrasing, adding an existing Knowledge article to the index – goes through the platform's standard change process. A material change requires re-approval at the appropriate tier.
Four changes are always material: adding a new Action, expanding a permission, opening a new channel, and removing or softening a human approval point. These are precisely the changes that are quietly made under pressure to improve performance, so they need to be flagged in advance.
The monitoring mechanisms that feed the change process are detailed in Observability for AI Agents.
What Governance Actually Reviews, Quarterly
The quarterly review isn't a status presentation. It examines five things: whether the agents in the registry are still necessary, whether the stated controls are functioning through sampling, whether the cost relative to the outcome is justified, what recurring escalations indicate a content gap, and whether material changes followed the correct process.
The review's outcome is a list of decisions: expand, reduce, suspend, or decommission an agent. Governance that cannot decommission an agent isn't governance—it's documentation.
Scenario: A Retailer Regained Control Without Halting Development
A retail chain discovered seven concurrent AI initiatives across four departments, without a registry and unknown to Risk. The first proposed response was a blanket freeze until a policy could be established—a move that would have also halted the two initiatives already delivering value.
Instead, a two-week mapping exercise was conducted: each initiative was classified by risk tier. Five were found to be low-tier and continued with expedited approval from a Process Owner and Platform Manager. Two—one involving customer refunds and the other exposing inventory data to suppliers—were moved to the high-tier, received human approval points, and were reviewed by Risk before proceeding.
Six months later, the number of initiatives had grown, but management knew for the first time what existed, who was responsible, and what the cost was. The practical conclusion: governance gained legitimacy precisely because it didn't block the low-tier initiatives.
Governance Risks and Preventative Actions
| Risk | How it Appears | Preventative Action |
|---|---|---|
| Blocking Committee | Teams build outside the approved channels | Fast-track for low-tier with only two approvers |
| Outdated Registry | Auditor discovers an unknown agent | Registry update as a condition for release |
| Ownership only in IT | No one to decide on business behavior | Appoint a named Business Owner for every agent |
| Self-Reporting Controls | Controls exist on paper but not in reality | Conversation sampling by an uninvested party |
| Quiet Material Change | Human approval removed to improve response time | Closed list of changes requiring re-approval |
Governance Metrics
| Metric | What it Reveals | Frequency |
|---|---|---|
| Registry Coverage | Percentage of active agents documented | Monthly |
| Average Approval Time | Whether the process has become a bottleneck | Monthly |
| Sampling Findings | Gap between declared control and actual state | Quarterly |
| Material Changes Following Correct Process | Process discipline | Quarterly |
| Agents Suspended or Decommissioned | Whether governance can say no | Quarterly |
When guidance is needed to establish a governance model tailored to your organization's size and applicable regulations, the Agentforce and AI Services is the practical path forward.
Governance Setup Checklist
- ☐ Risk classification model with three questions approved
- ☐ Approvers set for each tier, including a fast-track for low-tier
- ☐ Business and Technical Owners appointed for every existing agent
- ☐ Independent auditor appointed, not involved in development
- ☐ Agent registry established with all mandatory fields
- ☐ Closed list of material changes defined
- ☐ Quarterly review routine established with authority to decommission an agent
- ☐ Governance metrics defined with reporting frequency to management
