7 Governance Questions to Ask an AI Agent Vendor

Every AI agent vendor will show you output. Very few will let you inspect the controls, and the controls determine whether the deployment survives a security review and whether you can answer for it afterward. These seven questions are answerable in a working demo. A vendor who needs to follow up on more than one of them has told you something.
1. Does anything execute externally without a person approving it?
Ask it as a yes-or-no and listen for a qualified answer.
“It’s configurable” means yes, autonomous send exists, and someone in your organisation will eventually turn it on under quota pressure. “There is a supervised mode” means the same. What you want is a product where the approval step is structural — where no setting removes it, because the dispatch path runs through the gate by construction.
Governance you can disable is a policy, and policies degrade under pressure. Governance you cannot disable is an architecture.
2. Where does the approval step sit relative to dispatch?
Before or after. There is no third answer, and vendors describe both using the same phrase.
Ask to watch an action move from proposed to sent. If the demo shows the action already dispatched with an approval record generated alongside it, that is post-hoc notification. It satisfies the words “human in the loop” and provides none of the protection, because by the time a person sees it the message is in someone’s inbox and the exposure is real.
3. What is actually in the audit record?
Not whether logging exists. Every product logs. Ask what a single record contains and require the specifics:
- The acting agent and the approving person, both by identity
- The rationale for why the action was proposed
- The sources the agent consulted to reach it
- The state before and the state after
- A timestamp that cannot be rewritten
Then ask the two questions that separate a record from a view: can it be exported raw, and can it be edited? A dashboard that recomputes from current state is not evidence of what happened. An editable log is not evidence of anything.
4. Whose cloud does the ledger live in?
Yours or the vendor's. This determines who can produce your evidence when a regulator, an auditor, or a customer asks, and whether producing it requires a support ticket to a company whose interests may not align with yours at that moment.
For a regulated buyer this is often decisive on its own. For an unregulated buyer it becomes decisive the first time it matters, which is late.
5. When the system blocks an action, does it tell you which rule?
A governed system returns the specific governing clause. An ungoverned one returns a generic policy violation, which means a reviewer cannot resolve the question and has to escalate it.
The difference compounds. A reviewer who receives the clause resolves the exception in seconds and the throughput of the approval gate stays high. A reviewer who receives “blocked by policy” files a ticket, the action stalls, and within a few weeks the organisation’s response is to widen the policy until the blocks stop — which quietly removes the control the product was bought for.
Ask to see a blocked action. Ask what the reviewer sees.
6. What happens when a reviewer rejects something?
This question reveals the product's actual model of the human.
A system that treats approval as the expected outcome handles rejection as an exception: it drops the action, or retries with a variation, and nothing changes. A system that treats the reviewer as a source of signal records the rejection and the reason, and the reason shapes what the agent proposes next.
The second is the only version where the approval burden decreases over time rather than remaining a permanent tax on the team.
7. What identity does each agent hold, and what can it reach?
Ask whether the agents share credentials or hold separate scoped identities, and how each one reaches your CRM and your outbound provider.
The answer you want is a dedicated least-privilege identity per agent, with external access running only through typed, explicitly granted integrations. The answer that should stop the evaluation is a single set of credentials carrying the permissions of whoever installed it. That configuration means the blast radius of any failure is the full scope of those credentials, and it means the audit record cannot attribute an action to a specific agent, because they are all the same actor.
How do you use these in an actual evaluation?
Run all seven in one session, with the vendor operating a live system rather than a slide. Every one is demonstrable in a working product and none require access to anything confidential.
Score the answers on a simple test: could you reproduce the evidence yourself, without the vendor’s help, six months from now? A no on any question marks where the deployment will fail, and it will fail at the moment you most need it not to.
The Revenue Accelerator Stack is built to answer all seven affirmatively in a live demo, which is a design constraint rather than a marketing position. The reasoning behind leading with governance sets out what each buying-committee seat tests, and what the previous generation of pilots taught buyers is the history that produced these questions.
The broader framework is in digital labor.
Frequently asked questions
What should you ask an AI agent vendor first?
Whether anything executes externally without a person approving it, as a yes-or-no. A qualified answer means autonomous send exists and can be enabled.
How do you tell real human-in-the-loop from post-hoc review?
Ask to watch an action move from proposed to sent. If the approval record is generated alongside a message that already dispatched, the review is a notification rather than a gate.
What belongs in an AI agent audit record?
The acting agent and approving person by identity, the rationale for the proposed action, the sources consulted, the before-and-after state, and an unrewritable timestamp. It should export raw and it should not be editable.
Why does data residency matter for AI agents?
Because it determines who can produce your evidence when an auditor or a customer asks. A ledger inside the vendor’s tenant makes your compliance record dependent on their cooperation and their retention policy.
Should each AI agent have its own identity?
Yes. Shared credentials make the blast radius of any failure equal to the full permission scope, and make the audit record unable to attribute an action to a specific agent.
See where your own execution effort is going
The Autonomous Audit Report models where your team's execution capacity is currently spent, what your configuration is actually paying for, and what the governed alternative looks like on your own data — before any commitment.
Get your free AAR benchmark