The business builds the agents. Your IT governs them.

Hans Brattberg
Co-founder, Product & AI Strategy
·4 min read
The business builds the agents. Your IT governs them.

In this article

AI agents feel like an IT project. They shouldn't be. Here's the division of labour that works — and what your IT can actually enforce.

AI agents feel like an IT project. Yet we keep saying the people closest to the work should build them. If you run IT, that sounds like a recipe for chaos.

It's the opposite. Here's the division of labour that works.

The business builds. Your IT governs.

You already run this model. Nobody thinks your IT should build every spreadsheet or every BI dashboard. But everyone agrees your IT should own the security around the data.

AI agents work the same way. The people closest to the work know what the agent should do. Your IT knows what it must never do.

And here's the uncomfortable truth: the business is already building. With ChatGPT, with spreadsheets that quietly became systems, with tools that never crossed your desk for approval. The question is not whether the business builds AI. It's whether it happens somewhere you can see it — and back it.

What “governs” means in practice

Governance is not a policy PDF. It's a grid: how much autonomy the agent has, times how sensitive the data is.

A four-by-four governance matrix. Rows are agent autonomy, Tier 1 to Tier 4. Columns are data sensitivity: Public, Internal, Confidential, Restricted. Green cells mean the business self-serves, amber means team lead sign-off with IT in the loop, red means built together with IT or prohibited.
Green: the business self-serves. Amber: the business decides, with your IT in the loop. Red: built together, or not at all.

Thanks to Johanna Riad at StruSoft, whose original version of this matrix we're building on.

Be honest about the split. The platform enforces the outer edges. Your policy fills the middle. Abundly can hard-block an agent from posting publicly or reaching an unapproved system. It cannot know that a spreadsheet is confidential — that call is yours.

And note what the Confidential column doesn't say. Reading is not automatically safe: even a read-only agent can pass confidential data somewhere it must not go. That's why even Tier 1 needs sign-off there.

Be careful with amber, though. For finance, HR and sales, almost nothing is public, so amber is their real playing field, not green. Make it their own call: the team lead signs off, you see it in the log afterwards. Amber must not become a ticket in your queue.

What your IT can actually block

Your IT sets the limits once, for the whole workspace.

Workspace-wide capability settings in Abundly. Default mode for capabilities is set to Default OFF. Individual capabilities are listed with ON or OFF: Google Drive, HTTP Requests, Twitter/X Post, WhatsApp, Google Chat, Virtual Machine and Endpoint Management are OFF, while Slack, Send Email, Receive Email and Code Execution are ON.
Off means off. Your IT sets the workspace defaults and blocks the capabilities agents must not use.

Agents reach only the systems your IT has registered. Every other endpoint is closed. That holds even when an agent runs code: the sandbox has no network of its own, so every outbound call goes through the same allowlist. Credentials sit in a vault, scoped per team or per agent, and are injected server-side — the model never sees them. People sign in through your existing single sign-on.

An agent that reads inbound email can be told what to do by a stranger. Abundly screens incoming email and SMS for injection attempts before the agent acts on them. The capability policy is the backstop: an agent that cannot post publicly cannot be talked into it.

An agent can use a named person's connection, with that person's permissions, or run on a dedicated service account your IT provisions with least privilege. Use the service account for anything you need to audit clearly: then the agent has its own identity, its own permissions and its own trail.

Model availability settings for a workspace. Vendors are listed with individual models switched on or off. Claude Opus and Claude Sonnet are available only through EU-hosted Bedrock, Mistral through Scaleway, and a preview model is switched off.
Your IT picks the brains — which models, from which vendors, hosted where. Here Claude is allowed only through EU-hosted Bedrock, Mistral only through Scaleway, and the preview model is off. Turn a model off and agents using it stop with a clear error, never a silent fallback to something cheaper or riskier.

And when you want to know what actually happened: every trigger, every tool call and every external request is logged per agent, with the cost attached. Configuration changes have their own append-only history — who changed what, and when.

Nor do agents quietly outlive their owner. Your IT has a fleet view of the workspace: every agent, its owners, last runs and costs by agent or team. Orphans become visible instead of buried on someone’s laptop. And cost is the cheapest early warning there is: an agent nobody uses drops off the bill, one running wild shows up on it immediately.

When agents outgrow the platform

The business prototypes an agent, it proves useful, then it hits a wall: this part needs real code. That's where your IT comes in. Not to take the agent over, but to build the hard parts as services the agent calls. The prototype keeps earning its keep while you build, so nothing stalls in the queue.

You don't design this upfront. The working prototype is the spec.

The bottom line

You don't have to build everything. You get to see everything, govern everything, and step in where it matters.

That's a better job than being the bottleneck.

Read more

AI Agents in Practice -Beyond the Prototype (slides and video from my AI Fokus talk)

AI Agents in Practice - Beyond the Prototype (slides and video from my AI Fokus talk)

Making an impressive prototype is easy. But what about the icky stuff that comes after - real-life deployment, scaling, monitoring, optimization, data architecture, safety?

What does 10x engineering productivity look like in practice?

What does 10x engineering productivity look like in practice?

Concrete and surprising data on how AI agents in Cursor and Abundly affect our productivity and quality.

Henrik Kniberg
May 22, 2026
How to not AI Slop

How to not AI Slop

Illustrated by two extremes: an unedited voice transcript of Henriks sitting on a rock talking, vs an AI-written article

Henrik Kniberg
May 9, 2026
The Trust Ladder: how to onboard AI agents like new colleagues

The Trust Ladder: how to onboard AI agents like new colleagues

What data should we let them access? What if the agent gets it wrong? What holds organisations back is rarely the technology — it's the uncertainty. Think of AI agents as new colleagues and extend their remit one rung at a time, along the Trust Ladder.

Hans Brattberg
April 24, 2026
The First 100 Days as an AI Lead: The Playbook in 5 Minutes

The First 100 Days as an AI Lead: The Playbook in 5 Minutes

You got the role. The mandate is clear: make AI agents work across the organization. Now what? A short teaser of the four conditions, three phases, and the patterns that separate AI initiatives that ship from the ones that stall — with a link to the full 100-day playbook.

Nils Janse
April 24, 2026
Demo: The Human + AI-Agent Dev Team

Demo: The Human + AI-Agent Dev Team

How we use AI agents internally at Abundly - both for coding, backlog management and release management. It's a system of AI agents & human engineers working together, building on each other's strengths. This not only enables us to release a new version of our platform every day, but also makes the work really fun.

Henrik Kniberg
April 23, 2026