# Governance and Audit as Product
## Control is what the buyer pays for
An agent that acts on real work needs three controls. It must inherit the access rights of the user. It must stop at set human boundaries. It must leave a full record of what it read, decided and did.
> [!warning] The audit gap is wide
> One 2026 source says only 52 percent of companies can track the data their AI agents access. This is a secondary figure. Verify it.
## Design test
- Does the agent act as a named identity?
- Can the customer stop one action type without stopping all work?
- Can an auditor replay one decision from the log?
- Does the log record actions that the agent took for a user?
## Why it matters
Governance is a sales gate and a possible moat. A gate, because security teams block pilots without it. A moat only if the customer cannot move policy and logs to another vendor. See [[Switching Cost Design]].
## Related
- [[AI Deployment Layer MOC]]
- [[Human-in-the-Loop Systems]]
- [[Connector Layer and MCP]]