Stack layer · Govern, secure, and observe every agent
The AI Agent Control Plane
The control plane sits outside the tools that build agents. It answers which agents exist, who they act as, what they may do, whether they are behaving, and which calls they are allowed to make.
44 current tools in 5 categories · see the whole stack
Categories in this layer
Registry & management
9 toolsAgent inventory, ownership, lifecycle, and fleet-wide policy: the management core of the control plane.
Identity & access
10 toolsIdentities, scoped access, and access reviews for AI agents as non-human principals.
Guardrails & security
10 toolsRuntime guardrails, content safety, and agent security posture controls.
Monitoring & evaluation
7 toolsTracing, evaluation, prompt management, and cost monitoring for LLM apps and agents.
AI & MCP gateways
8 toolsGateways that route and govern LLM calls and agent access to MCP tools.
Suites that span several categories
Each tool is listed under its main function. These also cover two or more other categories in this layer.
- Amazon Bedrock AgentCoreRegistry & management · also Identity & access, Guardrails & security, Monitoring & evaluation, AI & MCP gateways
- Databricks Unity GatewayAI & MCP gateways · also Guardrails & security, Monitoring & evaluation
- Microsoft Agent 365Registry & management · also Identity & access, Guardrails & security, Monitoring & evaluation
- MuleSoft Agent FabricRegistry & management · also AI & MCP gateways, Monitoring & evaluation
- Portkey AI GatewayAI & MCP gateways · also Guardrails & security, Monitoring & evaluation
- ServiceNow AI Control TowerRegistry & management · also Guardrails & security, Monitoring & evaluation
How the industry frames the control plane
There is no single standard yet. These are the framings this grouping follows; gateways are included as the point where policy is enforced on every model and tool call.
- Forrester: Defines an agent control plane that inventories, governs, orchestrates and assures agents across vendors, separate from the planes that build agents and orchestrate processes. Source
- Microsoft: Positions Agent 365 as the control plane for agents, organised as observe, govern and secure. Source
Recent updates in this layer
- 2026-09-18Amazon Bedrock AgentCore
AWS released the new AgentCore Runtime (V2) with consumption-based memory billing and about 2-second P75 cold starts, in five regions.
Source - 2026-09-17MLflow
MLflow 3.16.1 removed the default basic-auth admin password (a security fix for self-hosted servers) and added scorer timeouts.
Source - 2026-09-16NeMo Guardrails
NeMo Guardrails 0.24.1 fixed benchmark concurrency measurement, Nemotron 3.5 response parsing, server overload handling, and combined-config loading.
Source - 2026-08-27agentgateway
agentgateway 1.5.0 added API-key-scoped LLM budgets, native Gemini APIs, and guardrails on tool calls, with breaking JWT and token-count changes.
Source