Governance

How a governed request works

The canonical path for work under Brightwire Agent Governance — authenticate, meter, check budget and policy, route the model, allow tools, then audit.

Every capability page in Governance assumes the same idea: policy and cost checks sit in the path, not only in a slide deck.

User / agentAuthenticateMeterBudget OK?Policy OK?Route modelTools if allowedAudit + costResult or human gate
StepPurpose
AuthenticateEnterprise identity and environment membership
MeterCount tokens and requests on the governed path
BudgetSoft or hard stop — or require elevation — before spend runs away
Policy / allowlistModel, tool, data, and export rules for this environment
Route modelSimple work to smaller/faster models; high-stakes work to frontier — under policy
ToolsOnly approved skills and tools for that caller
Audit + costReconstructable trail: actor, path, decision, spend attributes
Outcome or human gateReturn a result, or require accept / reject / escalate on Advise- and Act-class work

The same path can apply to a cloud seat, a coding agent, a department Runtime, or another managed path — when that path is in scope. We do not claim this path runs inside every closed vendor UI on day one.

Related: Why Governance · Cost · Policy & human gates · Audit