Operational
Agents touch systems, APIs, and data.
Agents are wired into the CRM, the data warehouse, file storage, and internal APIs. They move real work and affect real records — but there is no way to see or intervene while they do it.
Agents have left the sandbox. They read and write production systems, so their mistakes are now production incidents.
Workflow impact without runtime intervention. When something goes wrong, you find out afterwards, if at all.
Add runtime visibility. Log every tool call, data access, and decision — attributable and in real time.
The six control surfaces
What the controls look like at this stage
Maturity is measured across six control surfaces. Here is where a maturing organisation — one sitting at Stage 03 — typically stands on each.
Inventory
MaturingA partial register — the important agents are tracked, the long tail is not.
Ownership
MaturingOwners assigned to some agents, inconsistently, with gaps at handover.
Runtime visibility
MaturingSome logging, reviewed after the fact when someone goes looking.
Access control
MaturingScopes assigned, but static and hard to change without touching code.
Evaluations
MaturingAd hoc pre-deployment testing, with little visibility once an agent is live.
Governance
MaturingReviews and policy exist, but enforcement drifts behind real behaviour.
The move that matters
Advancing to Stage 04 — Governed
You do not skip stages. You close the gap in front of you, and only one control matters most right now.
Add runtime visibility. Log every tool call, data access, and decision — attributable and in real time.
Stage 03 — Operational, answered.
Short answers for teams placing themselves at the Operational stage of the agent operational maturity curve.
What is Stage 03 (Operational) of the agent maturity model?
Agents are wired into the CRM, the data warehouse, file storage, and internal APIs. They move real work and affect real records — but there is no way to see or intervene while they do it. In short: agents touch systems, apis, and data.
What is the main risk at the Operational stage?
Workflow impact without runtime intervention. When something goes wrong, you find out afterwards, if at all.
How do you move beyond the Operational stage?
Add runtime visibility. Log every tool call, data access, and decision — attributable and in real time. That is what takes an organisation from Stage 03 (Operational) to Stage 04 (Governed).