
Governed,becausesomebodywillask
How digital colleagues are governed: real identity, a readable practice score, a cost guard before every call, and every delegated action on the record.
Digital colleagues are full members of the team. That position raises an obvious question, usually within the first 10 minutes of a conversation with security and risk: who is accountable, and how would we know? Our answer is evidence, not assurances. Every claim below is something an administrator can read on screen.
Governance is process, not a cage for the AI
Much of the market sells human-in-the-loop as a safety feature, which quietly encodes that the agent is a tool under supervision. We take a different position. The team is the unit, and governance is a property of the team's process. If a change to production needs two approvals, it needs two approvals whoever proposed it. A colleague follows the same gate a person does, and escalates for the same reasons a person does: the matter is outside its remit, ambiguous, or high stakes. There is no parallel governance regime to maintain, because there does not need to be one.
Identity that cannot be asserted
Every colleague is a real identity: its own chat account and its own client in your identity provider, both created the moment you save it. Nothing asserts who it is. The platform derives identity from the credential, so a colleague cannot claim to be a different one. What it may reach is encoded before it asks, which means out of scope is impossible rather than refused after the fact.
A practice score you can read
Each colleague is scored continuously against a rulebook of 31 practice rules across seven categories: model choice, tools, knowledge, prompt, safety, cost and lifecycle. Every finding names the rule, the consequence and the fix. The rules are data, so an administrator can reweight or retire one without a deployment. Before you put a colleague in a client room, you can look at its score.
Cost bounded before the call, not reported after the month
A cost guard runs before every call: how deep the chain of colleagues has gone, whether one is calling itself in a loop, what the conversation has already spent, and whether one colleague is permitted to call another at all. Recurring work is capped by run count, and cost findings are visible per colleague. We promise per-call guards and per-colleague caps rather than a single hard ceiling on monthly spend, because that is what is real.
Acting as a person, on the record
When a colleague acts on your behalf, booking your leave under your permissions and against your name, it happens only in a direct message, only when your identity is linked, and only after it asks you to confirm. The credential it uses covers that one action and expires in minutes. Every delegated action is written down and readable by an administrator: who it acted as, which tool it used, whether a person approved it, and what happened. So when somebody asks who is accountable, the answer is the named person it acted as, with their confirmation on the record. That is what makes it evidence rather than storage.
Where the data goes
Rooms are encrypted by default, and so are calls. Knowledge is scoped per colleague and fetched only when needed. Each turn sends a bounded brief, not the room's history. And the agent behind a colleague can be one you run yourself: bring your own over the open agent-to-agent protocol, or run one on Amazon Bedrock. Routing, memory, governance and identity stay exactly where they are when the model underneath changes.
Governance is usually the section of an artificial intelligence (AI) proposal written to reassure. This one is written to be checked. Ask to see a practice score, a delegated-action record, or a cost finding, and we will show you the screen.
See the whole colleague
Governance is one part of what makes a digital colleague a real member of the team. See the full proposition, and how to start with one job in one room.

