Skip to main content
Editorial portrait graphic of Sougata Roy with examiner governance motifs
Practitioner frameworks for AI governance in regulated environments

Sougata Roy

An examiner walks in and asks who authorized your AI agent to act.

Most regulated organizations cannot produce the record. This site is for the practitioner frameworks, authorization artifacts, and field notes that make that answer easier to find before the review starts.

Now published: Who Owns the Agent?

Why the record is the point

Enterprises deploying AI agents accumulate monitoring, logging, and dashboards long before they accumulate a single document naming who authorized the agent to reach the data. The monitoring is real. The authorization record often does not exist.

This site is for that document. Writing one is estimated at under an hour of an owner's time. Reconstructing one after a finding runs at a remediation program's rate, over months, assembled by people who never met the agent.

Both figures are estimates. The gap between them is not.

40

Minutes to write, estimated

4

Months to repair, estimated

Active

Enterprise systems in regulated environments

26+ years enterprise systemsRegulated environmentsThe Governance Gap newsletter

Featured essay

When Microsoft Provisioning Quietly Changes Who Owns Security Copilot

Under the inclusion model for Microsoft 365 E5 and E7, eligible tenants are automatically provisioned for Security Copilot, and a documented set of existing Entra, Purview, and Intune roles inherits owner or contributor access. The entitlement exists. The approval record does not.

Read essay

Operational frameworks

Frameworks for the evidence examiners ask for.

Governance frameworks built from primary-source analysis of platform documentation and regulatory guidance. Each framework answers a question that enterprise AI deployment makes unavoidable.

The book Who Owns the Agent? brings several of these frameworks into a larger accountability and authorization model.

Explore the frameworks

01

Accountability

02

Authorization

03

Evidence

Latest publication

Who Owns the Agent? Enterprise AI Accountability on the Microsoft Stack is now live.

First edition, August 2026

Book

Enterprise AI Accountability on the Microsoft Stack

The August 2026 first edition on enterprise AI accountability and the authorization record every agent needs. Paperback and Kindle.

The book is the argument. The companion annex keeps the source and product record current as platform documentation changes.

Printed formulation

The platform can prove what the agent did. Only you can prove what it was allowed to do.

Front cover of Who Owns the Agent? Enterprise AI Accountability on the Microsoft Stack

The governance question arrives on a Tuesday.So does the field note.

Primary sources only. No product agenda. Written for the technology leaders responsible for governing AI in regulated environments.

Newsletter

Read the latest edition on LinkedIn.

Weekly research on enterprise AI accountability, authorization, and the changing platform context behind the issues explored in Who Owns the Agent?.

Read or join on LinkedIn(opens in new tab)